Sub-processor List
Every organisation that handles personal data in the course of providing ProvenBatch to you, what each one does, and where it is.
Effective 5 September 2026 · Updated 6 September 2026
1. What this page is
This page lists the third-party organisations (“sub-processors”) that Stella Apps, trading as ProvenBatch, engages to help provide the ProvenBatch service, and what each one does. It is referenced from our Terms of Service, Privacy Policy, and Data Processing Agreement, and is the authoritative, kept-current list for all three.
What this page covers, and what it therefore does not. It lists every organisation that handles personal data in the course of providing the Service to you — your Account data, your business content, and the data you enter about your own customers. It is not a list of every supplier Stella Apps buys anything from. Clause 3.4 names what has been considered and left off, so that “this is the list” is a claim you can check rather than one you have to take on trust.
2. The current list
| Sub-processor | For | Note |
|---|---|---|
| Supabase | Database, authentication, file storage, and backend (edge) functions | UK region (eu-west-2, London) — this is what our UK data-residency claim rests on |
| Anthropic | Reading photographed receipts, recipe pages, and food packaging (AI vision), and generating the in-app assistant’s replies | US-based. Transferred under the UK Addendum to the EU SCCs — see clause 4 of this page |
| Groq | Transcribing voice notes to text (speech-to-text) | US-based. The recording is sent for transcription and is not stored — only the returned text is kept, by us in the UK. See Privacy Policy clause 5.6 and clause 4.4 of this page |
| Stripe | Payment processing for subscriptions | Live since 14 August 2026. We never receive or store full card numbers — they are held by Stripe |
| Resend | Transactional email (account, billing, and service notifications), Supabase Auth mail (confirmation, password reset), and the emails sent about a beta or update-list request | See clause 6 for the beta and update-list flow |
| Google Workspace | Hosts our support mailbox, support@provenbatch.co.uk, and holds the contact list of accepted beta testers (name, email address, Business name) that we use to email the group | The tester contact list is #1071; it holds testers, not every applicant. See clause 6 |
| Cloudflare | Hosting, DNS, and content delivery for the Service and our websites; receiving email sent to your private receipt scan-in address | Replaced Netlify as of v0.85.1 (31 July 2026). For scan-in email, see clause 5 — no durable copy of your mail rests with Cloudflare |
| GitHub | Receives in-app feedback you choose to send (your message, Business name, and Account email) into our private issue tracker; its infrastructure also runs our scheduled background jobs (for example, overnight FSA recall-alert matching, subscription lifecycle emails, the beta invitation and any beta email that needs re-sending, and the export of the beta tester contact list), which work on the data in memory — as of 6 September 2026 their own run logs identify a request or account by internal id, never by email address, though the contact-list export still leaves a file of names and addresses on GitHub for a day. See clause 6 | US-based. See Privacy Policy clause 7.2 and clause 4.5 of this page |
3. How we keep this list current, and how we notify you of changes
3.1 This page is the single source of truth for our sub-processor list — it is not duplicated elsewhere with numbers that could drift out of step.
3.2 If we engage a new sub-processor, or change what an existing one does, we will update this page and, for a sub-processor that processes Customer Personal Data under our Data Processing Agreement, notify active subscribers by email or in-app notice before the new sub-processor begins processing, giving a reasonable opportunity to object as described in clause 7.2 of that agreement.
3.3 We remove a sub-processor from this list, rather than leaving a stale entry, as soon as we stop using it. Two entries were removed for that reason on 29 July 2026: Open Food Facts, following the removal of all Open Food Facts querying from the app in v0.75.0, and Netlify, following the migration to Cloudflare described above. Neither is contacted with any customer data today, and neither should appear as a current sub-processor anywhere else in our documents.
3.4 Considered and deliberately not listed, as at 5 September 2026. We buy other services that never touch your data, and we name them here rather than leave “these are all of them” as a claim you have to take on trust. Apify collects publicly posted content from food-business groups on social media as market research. ElevenLabs and Higgsfield generate voice-over and video for our own marketing. Metricool schedules our social posts. Monday.com is our own internal planning tool. None of them receives Account data, business content, or anything belonging to you or to your customers, so none is a sub-processor of the Service and none belongs in the table above. Where our own marketing research or planning involves personal data, Stella Apps is the controller for it in its own right, and it is outside the scope of the Data Processing Agreement.
4. International transfers
4.1 The system of record — the database, file storage, authentication, and backend functions,
and a beta or update-list request too — is with Supabase in the UK (eu-west-2, London). That is
what our residency claim means, and it is deliberately narrower than “everything stays in the UK”,
which would not be true. Anthropic, Groq, and GitHub are US-based, and clauses 4.2–4.5 cover
them; clause 6 sets out a shorter-lived copy that also rests on GitHub in the United States — the
tester-list export file, for one day.
Stripe, Resend, Google Workspace, and Cloudflare are global providers: the data each one handles
for us (payment details, transactional email, the support mailbox, and web traffic respectively)
may transit or be processed on infrastructure outside the UK under that provider’s own standard
UK/EU data-protection terms.
4.2 Anthropic is US-based, and photographs sent to it for automated reading — and the in-app assistant’s conversations — leave the UK to reach its API. See clause 5 of the Privacy Policy for what this means in plain terms and why it happens.
4.3 The UK GDPR international transfer mechanism that legally documents the Anthropic transfer is the UK Addendum to the EU Standard Contractual Clauses (formally, the International Data Transfer Addendum to the EU SCCs, ICO template version B.1.0) — set out in Schedule 3, Part B of Anthropic’s own Data Processing Addendum, and incorporated automatically when Anthropic’s Commercial Terms of Service are accepted, with no separate execution step on our side.
4.4 Groq is US-based, and voice-note recordings sent to it for transcription leave the UK to reach its API — see clause 5.6 of the Privacy Policy. The mechanism is the same class as clause 4.3’s: section 8.3 of Groq’s Data Processing Addendum for GroqCloud Services (effective 15 October 2025, console.groq.com/docs/legal/customer-data-processing-addendum) applies the International Data Transfer Addendum to the EU SCCs (the ICO’s UK Addendum) to transfers subject to the UK GDPR — it “forms part of this DPA and takes precedence”, and both the EU SCCs and the UK Addendum are deemed signed by entering into the Groq Services Agreement, with no separate execution step. In addition, we have enabled Groq’s Zero Data Retention setting for our account (24 August 2026), so Groq stores no inference inputs or outputs — recordings and transcripts included — even for its own system-reliability logging.
4.5 GitHub is US-based. The transfer (feedback items and transient background-job processing — see clause 7.2 of the Privacy Policy) is documented under GitHub’s Data Protection Agreement (version October 2025), section 7.B: GitHub’s self-certification to the EU–US Data Privacy Framework (including the UK Extension) and/or the EU Standard Contractual Clauses, with the UK Addendum applying to personal data protected by the UK GDPR.
5. Email-to-scan (receipt forwarding by email)
The email-to-scan feature — forwarding a receipt to your Account’s private scan-in address — is handled by Cloudflare, already listed above: mail to that address is received by a Cloudflare Email Worker on our own domain. The Worker is deliberately minimal: it keeps no copy of your message — not the body, not the headers, not the sender’s text — and stores only the receipt attachments, which go directly into your Account’s private storage with Supabase in the UK, exactly as a photographed receipt would. No separate inbound-email provider is engaged, and no durable copy of your mail comes to rest on Cloudflare’s systems.
6. Beta places and the update list
Asking for a beta place, or asking to be kept updated, happens before there is any Account, so it sits outside the Service itself — but it is personal data all the same, and four of the organisations above handle it. The request itself is stored with Supabase in the UK, exactly as Account data is, and the emails about it are sent by Resend.
Two parts of this route reach the United States, and clause 4.1’s “at rest in the UK” does not describe them. Both run on GitHub’s infrastructure:
- The email sends. The acknowledgement and the decision on a beta request are sent by our own backend as soon as they are earned. A scheduled job on GitHub re-sends anything that did not go out, and is what sends the invitation itself. As of 6 September 2026 that job’s own run log identifies the request it acted on by internal id, never by email address — running it is still a transfer to the United States, because your details pass through GitHub’s infrastructure in memory to reach Resend, even though nothing beyond the id is written down. Update-list mail does not go through it at all.
- The tester contact list. Applicants who have been invited or have signed up are exported as a file of names, email addresses and Business names, plus a short status note, so the list can be imported into our Google Workspace account and the group emailed. That file is produced by a job on GitHub and rests there for one day before import. Applicants who have not been invited are not included.
No other organisation is involved, and none of this data reaches Anthropic, Groq or Stripe. See clause 12 of the Privacy Policy for what is collected and how to leave the update list.
7. Contact
Questions about this list, or about any sub-processor’s role, can be sent to support@provenbatch.co.uk.