Sub-processor Register
Register version 1.0 · Last updated 22 September 2026
Every third party that processes personal data on our behalf, what it does, and the contractual safeguard we rely upon. Published so that your vendor assessment does not have to begin with a document request.
This register forms Annex 3 to our Data Processing Agreement and is maintained as a living document.
1. Purpose of this register
This register names every third party that ZeroRisk Labs relies on to process personal data, the role it performs, the categories of data that reach it, and the contractual safeguard we rely upon.
It exists because Article 28(3)(d) of the UK and EU GDPR gives a controller the right to object to a change of sub-processor. That right cannot be exercised against a party that has not been named, so a general authorisation to appoint sub-processors is only meaningful alongside a published list. The register forms Annex 3 to our Data Processing Agreement.
2. What this register deliberately does not contain
We name the entities, their role, and the safeguard. We do not publish cloud region identifiers, project or account identifiers, datastore structure, tooling inventories, or control parameters.
That is a considered decision rather than an omission. Publishing an infrastructure map would give an attacker a target list while adding nothing to a controller's ability to assess our processing chain. Specific processing regions are recorded in the engagement agreement, which is where Article 30(2)(b) of the Digital Operational Resilience Act requires them to appear, and are provided to clients on request under a non-disclosure agreement.
3. Sub-processors
Each entry below processes personal data on our behalf under a written contract imposing data protection obligations equivalent to those we owe our clients. We remain fully liable for each sub-processor's performance of those obligations.
Two entries name the same corporate group for two distinct services. They are listed separately because the processing purposes, the data categories, and the governing addendum differ, and a controller's own register needs that distinction.
Google LLC and its affiliates
Cloud database and application infrastructure
- Purpose of processing
- Durable storage of enquiry and service-request records submitted through our website forms, and of the short-lived records used to prevent automated abuse of those forms.
- Categories of personal data
- Name, business email address, enquiry or project description, selected service, and technical request metadata.
- Safeguard relied upon
- Google Cloud Data Processing Addendum, incorporating the European Commission Standard Contractual Clauses for European Economic Area transfers and the UK International Data Transfer Addendum for United Kingdom transfers.
Google LLC and its affiliates
Business email and productivity services
- Purpose of processing
- Receipt, routing, and storage of correspondence with prospective and existing clients, and with candidates who contact us directly.
- Categories of personal data
- Name, business email address, and the content of correspondence you choose to send us.
- Safeguard relied upon
- Google Workspace Data Processing Amendment, incorporating the European Commission Standard Contractual Clauses for European Economic Area transfers and the UK International Data Transfer Addendum for United Kingdom transfers.
Vercel Inc.
Website hosting, edge delivery, and TLS termination
- Purpose of processing
- Serving this website, terminating encrypted connections, and generating the transient operational logs required to keep the service available and to investigate abuse.
- Categories of personal data
- IP address and request metadata, held transiently for operational and abuse-prevention purposes only.
- Safeguard relied upon
- Vercel Data Processing Addendum, incorporating the European Commission Standard Contractual Clauses for European Economic Area transfers and the UK International Data Transfer Addendum for United Kingdom transfers.
ZOHO Corporation Private Limited
Recruitment applicant tracking
- Purpose of processing
- Receiving and managing applications for advertised roles. Used solely for recruitment; no client engagement data is processed by this sub-processor.
- Categories of personal data
- Candidate name, contact details, curriculum vitae, and application correspondence.
- Safeguard relied upon
- Zoho Data Processing Addendum. Where a candidate applies from the European Economic Area it incorporates the European Commission Standard Contractual Clauses; where a candidate applies from the United Kingdom it is supported by the UK International Data Transfer Addendum, since the EU Clauses are not a valid UK transfer mechanism on their own. Applies to candidate data only and sits outside the client processing chain.
4. Where processing takes place
Our own operations are conducted from India. Our sub-processors are global providers that may process data in more than one jurisdiction in the course of delivering platform-level functions such as content delivery and mail routing. The specific processing regions applicable to an engagement are recorded in the engagement agreement and are available to clients on request.
5. How we notify changes
- We give at least 30 days' notice before a new sub-processor begins processing personal data on our clients' behalf.
- Notice is sent by email to the contact named in the engagement agreement. We do not rely on publication to this page alone, because a controller cannot be expected to poll a webpage to discover a change affecting its own compliance position.
- Clients may subscribe an additional address — a privacy team inbox or a distribution list — by writing to us with the subject line below.
- A controller may object on reasonable data protection grounds within the notice period. The consequences of an objection, including termination without penalty where no accommodation is possible, are set out in clause 8 of our Data Processing Agreement.
- This page shows its own register version and last-updated date at the top, versioned independently of our other legal documents. A register that shared the document-set version could not signal its own changes, which would defeat the control it exists to provide.
6. Services that are not sub-processors
For completeness, and because vendor assessments frequently ask: the following do not appear above because they do not process personal data on our behalf.
- Analytics and advertising platforms — we use none. This website sets no analytics, advertising, or profiling cookies and loads no third-party analytics or advertising scripts.
- Third-party fonts — typefaces are compiled into the site at build time and served from our own origin, so no font request is made to a third party when you visit.
- Content delivery for images — all images on this site are served from our own origin.
- Customer support, chat, and marketing automation tooling — we operate none.
If we introduce any of the above, it will be added to this register and notified in accordance with clause 5 before it begins processing.
7. How we assess a sub-processor before appointing it
- We assess the necessity of the processing first, and do not appoint a sub-processor where the function can reasonably be performed without one.
- We review the provider's data protection terms, including whether it offers a processor addendum incorporating a valid transfer mechanism.
- We review its security posture and assurance position, including any independent certification it holds.
- We confirm that the obligations we owe our clients can be flowed down contractually in equivalent form.
- We record the assessment, so that it can be produced during a client audit under clause 13 of our Data Processing Agreement.
Where a client is an essential or important entity under Directive (EU) 2022/2555 (NIS2), this assessment is the material you need to discharge your own supply chain security obligations under Article 21(2)(d), and we will provide it on request.
Subscribe to change notifications
To add an address to our sub-processor change notification list, or to request the processing regions and detailed assurance material applicable to your engagement, contact us using the subject line below.
ZeroRisk Labs
Ambari, Guwahati, Assam 781001, India
Email: privacy@zerorisklabs.com
Please use the subject line Sub-processor Change Notifications so your message is routed correctly on arrival.