Subprocessors
Every third party that can receive personal data because NeuroPage sends it to them, with what it does, where it holds the data, and which categories of data reach it. Published so that a customer can copy it straight into their own processing register. Read alongside the Privacy Policy and the Data Processing Agreement.
Last updated: 7 September 2026
Notice of changes
We give customers at least 30 days notice before a new subprocessor starts processing their personal data. A customer may object on reasonable data protection grounds within that period, and where we cannot offer a workable alternative the customer may terminate the affected part of the Services without penalty. To receive these notices, write to privacy@neuropage.io.
Infrastructure
| Provider | Purpose | Location | Data | Transfer safeguard |
|---|---|---|---|---|
| Supabase | Primary database and file storage. Holds accounts, leads, generated pages, and generated messages. | European Union (eu-west-1, Ireland) | Account and contact data, professional profile and lead data, generated content, persona analysis output | No transfer outside the EEA for data at rest |
| Cloudflare | Edge compute for page generation and page serving (Workers), object storage for page assets (R2), CDN and network security. | European Union (R2 buckets created with EU jurisdiction; CDN edge serving is global by design) | Generated pages and page assets, visitor IP address and request metadata | EU Standard Contractual Clauses under the provider DPA |
| Vercel | Hosting for the NeuroPage web application and its API routes. | European Union (eu-west deployment region) | Account and contact data, usage data, application logs, request metadata | EU Standard Contractual Clauses under the provider DPA |
AI models
| Provider | Purpose | Location | Data | Transfer safeguard |
|---|---|---|---|---|
| OpenRouter | Routes copy generation requests to the text model used to write page copy and outbound messages. | United States | Professional profile context and the prompt built from it, generated copy | EU Standard Contractual Clauses under the provider DPA |
| Anthropic | Models used for content analysis, output quality checks, and image understanding. | United States | Professional profile context, page and brand content submitted for analysis | EU Standard Contractual Clauses under the provider DPA |
| Groq | Models used for persona analysis and for extracting structured fields from submitted content. | United States | Professional profile data used to derive the persona analysis described in Article 7 of the Privacy Policy | EU Standard Contractual Clauses under the provider DPA |
Research and enrichment
| Provider | Purpose | Location | Data | Transfer safeguard |
|---|---|---|---|---|
| Airscale | Looks up professional profile and company data for a submitted lead. | European Union | Name, employer, job title, LinkedIn URL and other professional profile identifiers | No transfer outside the EEA for data at rest |
| Apollo | Professional profile and company lookup, and contact list synchronisation. | United States | Name, work email address, employer, job title and other professional profile identifiers | EU Standard Contractual Clauses under the provider DPA |
| Exa | Web search used to research a lead and their employer before a page is written. | United States | Search queries containing a name, employer, or job title | EU Standard Contractual Clauses under the provider DPA |
| Linkup | Web search used to research a lead and their employer before a page is written. | European Union (France) | Search queries containing a name, employer, or job title | No transfer outside the EEA for data at rest |
| Firecrawl | Reads the content of public web pages, including a customer website during onboarding and a lead employer website during research. | United States | URLs submitted for extraction and the public page content returned | EU Standard Contractual Clauses under the provider DPA |
| PredictLeads | Company signal data, used as a fallback source for technology and hiring signals. | European Union (Slovenia) | Company identifiers and public company signals | No transfer outside the EEA for data at rest |
Communications
| Provider | Purpose | Location | Data | Transfer safeguard |
|---|---|---|---|---|
| Resend | Sends transactional email from the platform, such as sign-in links, invitations, and service notifications. | United States | Work email address, name, message content | EU Standard Contractual Clauses under the provider DPA |
| Google Workspace | Internal email, documents, and the mailbox that answers privacy and support requests. | European Union and United States | Correspondence with NeuroPage, including anything a sender chooses to include | EU Standard Contractual Clauses under the provider DPA |
Analytics
| Provider | Purpose | Location | Data | Transfer safeguard |
|---|---|---|---|---|
| PostHog | Product analytics for the NeuroPage application. Not loaded on generated pages. | European Union (EU Cloud) | Usage events within the signed-in application | No transfer outside the EEA for data at rest |
| Google (Tag Manager and Analytics) | Tag management and website analytics on the NeuroPage marketing website only. Not loaded on generated pages. | United States | Website usage events, IP address, device and browser data | EU Standard Contractual Clauses under the provider DPA |
| Microsoft (Clarity) | Behaviour analytics on the NeuroPage marketing website only. Not loaded on generated pages. | United States | Website usage events, IP address, device and browser data | EU Standard Contractual Clauses under the provider DPA |
Customer-activated integrations
These are connected by a customer, with the credentials of that customer, and receive data because the customer instructed it. They are the processors of the customer rather than subprocessors of NeuroPage. They are listed here because a customer building its own processing register needs to know that data leaves through these doors.
| Service | What it receives and why |
|---|---|
| HeyReach | LinkedIn outreach: enrols leads and sends connection notes and messages. |
| Smartlead | Email outreach: enrols leads into the customer email sequences. |
| Instantly | Email outreach: enrols leads into the customer email sequences. |
| ReachBoost | Outreach and inbound reply synchronisation. |
| Apollo | Where a customer connects their own Apollo account, contact lists are synchronised into the workspace. |
What is deliberately not on this list
- Payment processing. NeuroPage does not currently process card payments through the platform, so no payment provider receives personal data. This list will be updated before that changes.
- Tools used only for our own sales and marketing, which never receive customer or prospect data from the platform.
- Model training providers, because there are none. We do not train models on customer or prospect data, and our model providers do not train on data submitted through their APIs. See Article 8 of the Privacy Policy.