Sub-processors
This page lists the sub-processors used by Legatum Group Limited to provide VaultHire and AccountRadar. We update this page when sub-processors are added, changed, or removed. Customers are notified by email at least 30 days before any new sub-processor is added.
A "sub-processor" is a third party that processes personal data on our behalf or as part of providing our services to you.
VaultHire sub-processors
| Provider | Purpose | Region | Privacy policy |
|---|---|---|---|
| Cloudflare, Inc. | Hosting, CDN, edge compute, KV storage | UK / EU | https://www.cloudflare.com/privacypolicy/ |
| Stripe, Inc. | Payment processing | UK / EU (with global routing) | https://stripe.com/privacy |
| Resend (Resend Inc.) | Transactional email delivery | EU region selected | https://resend.com/legal/privacy-policy |
| Anthropic PBC | AI inference (query processing, content drafting) | US (data not retained for training under our enterprise terms) | https://www.anthropic.com/legal/privacy |
| Apollo.io, Inc. | Business contact data | US (SCCs in place) | https://www.apollo.io/privacy-policy |
| Lusha Systems Inc. | Business contact data | US / EU (SCCs in place) | https://www.lusha.com/legal/privacy/ |
| ContactOut, Inc. | Business contact data | US (SCCs in place) | https://contactout.com/privacy |
| Companies House (UK Government) | Public company and director data | UK | https://www.gov.uk/government/organisations/companies-house |
AccountRadar sub-processors
| Provider | Purpose | Region | Privacy policy |
|---|---|---|---|
| Cloudflare, Inc. | Hosting, CDN | UK / EU | https://www.cloudflare.com/privacypolicy/ |
| Supabase, Inc. | Database and backend infrastructure | EU region (London or Frankfurt) | https://supabase.com/privacy |
| Stripe, Inc. | Payment processing | UK / EU (with global routing) | https://stripe.com/privacy |
| Resend (Resend Inc.) | Transactional email delivery | EU region selected | https://resend.com/legal/privacy-policy |
| Anthropic PBC | AI inference (signal scoring, briefing generation) | US (data not retained for training under our enterprise terms) | https://www.anthropic.com/legal/privacy |
| Companies House (UK Government) | Public company and director data | UK | https://www.gov.uk/government/organisations/companies-house |
| News and signal APIs | Public business signal aggregation (funding, hiring) | Various — see internal data register | (varies by source) |
Data residency
All production data storage is pinned to UK or EU regions. Stateless compute (e.g. serving page requests) may execute at the global edge nearest the user, but no production personal data is stored outside the UK/EU.
Where personal data is transferred to non-UK/EU jurisdictions (e.g. our US-based contact data providers), we rely on Standard Contractual Clauses (SCCs) and the providers' own UK/EU compliance positions.
How we manage sub-processors
- Every sub-processor is bound by a written data processing agreement
- We assess sub-processors before onboarding, and review annually
- We notify customers in writing at least 30 days before adding a new sub-processor
- Customers may object to new sub-processors; if we cannot reach a workable position, you may terminate without penalty for the relevant period
Get notified of changes
To receive email notifications when this list changes, contact privacy@legatumgroup.uk to be added to our notifications list.
Contact
For sub-processor enquiries: privacy@legatumgroup.uk