Back to BlackReach

Legal

Subprocessor Register

Service providers authorised to process customer personal information for BlackReach Intelligence.

Last updated: 8 August 2026

Authorised providers

netcup GmbH

Purpose
Production virtual-server hosting and network infrastructure
Data
Encrypted and live application, account, workspace, database and technical-log data
Location
Germany
Safeguards
UK adequacy regulations for the EEA; provider data-processing terms

Clerk, Inc.

Purpose
Authentication, account identity, sessions and sign-in email delivery
Data
Name, business email, authentication identifier, session and security metadata
Location
United States and documented service locations
Safeguards
Provider DPA; approved contractual transfer mechanism and transfer assessment where required

OpenAI, L.L.C.

Purpose
AI-assisted evidence structuring, drafting, summarisation and embeddings
Data
Relevant customer-authorised company, procurement and pursuit text; prompts and outputs
Location
United States and documented service locations
Safeguards
Business/API data terms, provider DPA and approved contractual transfer mechanism with transfer assessment

Resend, Inc.

Purpose
Transactional invitations, requested notifications and service email
Data
Business email, message content and delivery metadata
Location
United States and documented service locations
Safeguards
Provider DPA and approved contractual transfer mechanism with transfer assessment

Stripe

Purpose
Subscription checkout, invoices, receipts and billing portal
Data
Billing contact, subscription and payment metadata; Stripe handles card details
Location
United Kingdom, EEA, United States and documented service locations
Safeguards
Stripe data-processing terms and applicable transfer safeguards

Microsoft

Purpose
Encrypted off-site database backup storage and operator identity services
Data
Client-side encrypted backup objects; authorised operator identity metadata
Location
Customer tenant region and documented support locations
Safeguards
Microsoft Products and Services DPA; encryption before backup upload; approved transfer mechanism where required

Changes and objections

BlackReach gives customers reasonable advance notice before appointing a new subprocessor that will process customer workspace personal information. Customers may raise a reasonable data-protection objection by emailing privacy@blackreach.co. We will work in good faith to address the concern or identify a practicable alternative.

Official procurement portals, Companies House and websites a customer asks BlackReach to access are data sources or independent controllers, not subprocessors acting for BlackReach. Self-hosted PostgreSQL, Redis, Caddy, ClamAV, coturn and the portal gateway run within BlackReach’s netcup environment rather than as separate hosted subprocessors.