Sub-Processor List
Last updated: June 27, 2026
Table of Contents
1. What Is a Sub-Processor?
A sub-processor is a third-party service provider that processes personal data on behalf of Shurq Ltd ("Shurq," "we," "us," or "our") to help us deliver our Services. Sub-processors may have access to or process certain categories of personal data as part of providing their services to us.
Under data protection laws such as the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018, we are required to maintain transparency about the third parties that process personal data in connection with our Services.
Important: This page should be read alongside our Privacy Policy, which explains how we collect, use, and protect your personal information, and our Cookie Policy, which details our use of tracking technologies. If you use the Chrome extension, its data handling is covered separately in the Extension Privacy Policy.
2. How We Select Sub-Processors
We take the selection of our sub-processors seriously. Before engaging any third-party service provider that will process personal data, we conduct a thorough due diligence process to ensure they meet our standards for data protection and security.
2.1 Due Diligence Process
Our evaluation of potential sub-processors includes:
- Security assessment: We review the sub-processor's security practices, certifications (e.g., SOC 2, ISO 27001), and track record for protecting data.
- Data protection compliance: We verify that the sub-processor complies with applicable data protection laws, including GDPR where relevant.
- Contractual safeguards: We enter into Data Processing Agreements (DPAs) with each sub-processor that include appropriate technical and organizational measures.
- International transfers: Where data is transferred outside the EEA/UK, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs).
2.2 Ongoing Monitoring
We periodically review our sub-processors to ensure they continue to meet our standards. This includes monitoring for security incidents, reviewing updated certifications, and reassessing the necessity of each sub-processor relationship.
3. Current Sub-Processors
The following table lists all third-party sub-processors that currently process personal data on our behalf, along with their purpose, the categories of data they process, and their primary data processing location.
| Service | Purpose | Data Processed | Location |
|---|---|---|---|
| Amazon Web Services (SES / SQS) | Transactional email delivery and message queueing. Shurq does not host customer data on AWS — application data is stored on infrastructure we own and operate (see our Security page). | Recipient email address and name; queued job metadata | US |
| Stripe | Payment processing | Name, email, billing address, payment method | US |
| Google (OAuth) | Authentication | Email, name, profile picture | US |
| Google Analytics 4 | Website analytics | IP address, device info, usage patterns | US |
| Sentry | Error monitoring | Error logs, device info, browser info | US |
| Sanity | Content management (blog/glossary) | Public content only | US |
| MapTiler | Geolocation mapping | IP-derived location data | EU |
| Intercom | Customer support chat | Name, email, chat messages | US |
| SendGrid | Transactional email | Email address, name | US |
| Amazon Advertising API | PPC data sync | Campaign data, keywords, bids | US |
| Cloudflare | CDN, DNS & web application firewall (edge network) | IP address, request metadata (all traffic transits the edge) | Global |
| PostHog | Product analytics | Usage events, pseudonymous user/account identifiers | EU |
| OpenRouter | AI model routing for assistant features (used as a fallback to self-hosted models; routes to model providers such as Anthropic) | Chat messages and ad-performance metrics submitted to AI features | US |
| Anthropic (Claude) | AI inference for assistant safety-review and fallback (Anthropic's commercial terms do not train on business data) | Ad-decision context and chat messages submitted to AI features | US |
| OpenAI | AI image generation (profile / agent avatars) | Avatar generation prompts | US |
3.1 Data Processing Details
Each sub-processor listed above operates under a Data Processing Agreement (DPA) with Shurq that governs the scope, nature, and purpose of data processing, as well as the obligations and rights of each party.
All sub-processors are required to implement appropriate technical and organizational measures to protect personal data, including encryption in transit and at rest, access controls, and regular security assessments.
3.2 International Data Transfers
Most of our sub-processors are based in the United States. For transfers of personal data from the EEA or UK to the US, we rely on one or more of the following safeguards:
- EU-US Data Privacy Framework (where the sub-processor is certified)
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Binding Corporate Rules (where applicable)
4. Changes to This List
We may update this sub-processor list from time to time as we add or remove third-party service providers. We are committed to keeping our customers informed about these changes.
4.1 Notification Process
We will provide at least 30 days' prior written notice before adding any new sub-processor that processes personal data. Notifications will be sent via:
- Email to the account owner's registered email address
- An update to this page with the effective date of the change
- A notice within the Shurq platform dashboard (where applicable)
4.2 Effective Date
Changes to this sub-processor list will take effect 30 days after notification, unless a customer raises a valid objection during the notification period (see Section 5 below).
5. Your Rights
If you are a customer subject to data protection laws (such as the GDPR), you have certain rights regarding our use of sub-processors.
5.1 Right to Object
You may object to the appointment of a new sub-processor by notifying us in writing within 30 days of receiving our notification. Your objection must include specific, reasonable grounds related to data protection concerns.
Upon receiving your objection, we will:
- Make reasonable efforts to address your concerns, which may include providing additional safeguards or using an alternative sub-processor
- Discuss the objection with you in good faith to reach a mutually acceptable resolution
- If we cannot reasonably accommodate your objection, either party may terminate the affected services with reasonable notice
5.2 Additional Rights
Under applicable data protection laws, you may also have the right to:
- Request information about the specific safeguards in place for international data transfers
- Request copies of our Data Processing Agreements with sub-processors (subject to confidentiality obligations)
- Lodge a complaint with your local data protection authority if you believe your rights have been violated
6. Contact Us
If you have questions about our sub-processors, wish to object to a new sub-processor, or need more information about our data processing practices, please contact us:
Postal Address
Shurq Ltd
Privacy Team
London, United Kingdom
We aim to respond to all inquiries within 30 days. For EU/EEA residents, you also have the right to lodge a complaint with your local data protection authority if you believe your rights have been violated.
Have Questions?
Contact our team for any inquiries about our sub-processors

