Subprocessors
Version 1 · Last updated 7 October 2026
These are the companies that handle personal information for Sulucent. Some handle information about our own customers and the people who visit sulucent.com. Others also handle information we look after for the businesses whose websites we run, including what their visitors type into their forms.
Each entry says what the company does for us, what it receives and where. When our data processing agreement is published, it will refer to this page as the list of subprocessors our customers authorise.
- Supabase
- Our database, file storage and sign-in.
- Account details: email address, and name and profile picture for Google sign-in
- The IP address and browser details recorded at sign-in
- Assessment answers, enquiries and onboarding drafts
- Business details, site content, uploaded documents and photos
- Leads and form answers collected on customer websites, campaign recipients and unsubscribes
- Coded (hashed) IP addresses used to stop abuse of our forms
- Vercel
- Hosts sulucent.com and every customer website, and runs our scheduled jobs.
- Every request to those sites, including the IP address and browser details
- An approximate city and country worked out from the IP address, which it passes to us
- Whatever is typed into forms on those sites, on its way to our database
- Request logs
- GitHub
- Stores the code and content of each customer’s website in a private repository.
- The content of the website, including anything published on it, such as staff names, testimonials and contact details
- DigitalOcean
- Runs the server that migrates and builds customer websites.
- Pages, screenshots and images of the customer’s existing website
- The website being built from them
- The server’s own logs
- Anthropic
- The Claude AI model. It reads customer websites, runs the onboarding chat, Site Minion and its demo, and helps draft pages, posts, emails and image descriptions.
- Text and images from the customer’s existing website
- What people type into the onboarding chat, Site Minion and the Site Minion demo
- Business details and uploaded documents
- Quotes from the customer’s website used to draft their emails
- Firecrawl
- Reads customer websites when we migrate them.
- The website address, and the public pages on it, including any personal information published there
- TypeSafe
- An AI model that runs yes-or-no checks on page text during a migration.
- Text from the pages of the customer’s existing website, such as testimonials
- “Continue with Google” sign-in; PageSpeed Insights, which measures how fast a website loads; the Gemini model, which generates images; and the email account our team receives alerts in.
- For sign-in, the Google account the person chooses
- For PageSpeed Insights, the website address entered
- For Gemini, what the image should show, the site’s colours, and the descriptions of the business and its customers as written, so any name in them is sent too
- For our alert email account, the details of each new assessment and enquiry, including names and email addresses, and migration alerts
- Resend
- Sends our emails: assessment results, setup reminders and migration updates, alerts to our team about new assessments and enquiries, and the campaign emails customers send to their leads.
- The recipient’s email address and the content of the email
- Bounces and spam complaints, which it reports back to us
- Sentry
- Reports errors in our software.
- Technical details of the error
- For errors in a browser, the IP address, because the report goes straight from the browser to Sentry
- For the Site Minion demo, the last few messages of a conversation when a reply goes wrong, and a hashed IP address
- For blog drafts, any passage a draft copied from the article it was based on
- We remove the email addresses, form answers and credentials we can detect before a report is sent
- Slack
- Alerts our team about the progress of a migration.
- Status messages about a site being migrated, which can include the business’s name
- Questions the migration server asks our team
- Cloudflare
- Runs the sulucent.com domain name and forwards email sent to our addresses.
- Emails sent to hello@, help@ and legal@sulucent.com, as they are forwarded
- Microsoft
- Hosts the mailbox that hello@, help@ and legal@sulucent.com forward to.
- Emails sent to those addresses, including privacy requests, and our replies
A location marked “per the provider” comes from the provider’s published documents and has not yet been checked against our account. “Not yet confirmed” means we are still checking it.
How we tell you about changes
When we add a subprocessor, stop using one, or change what one receives or where, we update this page first. The version number goes up, and the change log below records what changed and when.
Before a new subprocessor starts receiving our customers’ information, we email every customer. Our data processing agreement, when it is published, will set how far ahead and what happens if you object.
If you object, email legal@sulucent.com before the change takes effect.
Change log
Version 1 · 7 October 2026
First published list, checked against our code, our DNS and our account settings.
Added: Supabase, Vercel, GitHub, DigitalOcean, Anthropic, Firecrawl, TypeSafe, Google, Resend, Sentry, Slack, Cloudflare, Microsoft