Sub-processors
Last updated: 2026-06-01. Owner: Cagdas Arda.
Brewyard is operated by Fincard Ltd, registered in England and Wales. We act as data processor on behalf of our customers for project content, agent prompts/responses, and stored API credentials; and as data controller for billing identifiers, account identifiers, and operational telemetry. The third parties below process customer data on our behalf under appropriate Article 28 contracts.
We commit to giving customers at least 14 days' written notice before adding or replacing a sub-processor in a way that materially affects them, in line with UK GDPR Article 28(2). Notice is delivered via email to the account owner and via a changelog entry at the top of this page.
Active sub-processors
| # | Sub-processor | Legal entity | Role (Art 28) | Region | DPA | Certifications |
|---|---|---|---|---|---|---|
| 1 | Microsoft Azure — Container Apps | Microsoft Ireland Operations Ltd (to confirm) | Processor | Azure UK South (London) | Microsoft DPA | ISO 27001, ISO 27017, ISO 27018, SOC 1/2/3 |
| 2 | Microsoft Azure — PostgreSQL Flexible Server | Microsoft Ireland Operations Ltd (to confirm) | Processor | Azure UK South (London) | Microsoft DPA | ISO 27001, ISO 27017, ISO 27018, SOC 1/2/3 |
| 3 | Microsoft Azure — Key Vault | Microsoft Ireland Operations Ltd (to confirm) | Processor | Azure UK South (London) | Microsoft DPA | ISO 27001, ISO 27017, ISO 27018, SOC 1/2/3 |
| 4 | Resend (transactional email) | Plus Five Five, Inc. | Processor | US (with EU-US DPF certification) | Resend DPA | SOC 2, EU-US DPF + UK Extension |
| 5 | Anthropic, PBC (model inference) | Anthropic, PBC (Delaware) | See note below — direct customer relationship. | US | Anthropic Commercial Terms | SOC 2 Type II (per public statements, to re-verify) |
| 6 | PostHog Inc. — PostHog Cloud EU | PostHog Inc. | Processor | EU (AWS eu-central-1, Frankfurt) | PostHog DPA | SOC 2 Type II, HIPAA (where elected), ISO 27001 (to confirm) |
| 7 | Cloudflare (CDN, WAF, DDoS edge) | Cloudflare, Inc. (to confirm) | Processor | Global edge; UK + EU points of presence prioritised | Cloudflare DPA | ISO 27001, SOC 2 Type II, PCI DSS |
Planned but not yet live
These will move to Active when the corresponding feature ships. They're listed here for transparency so the timing of any new processor is never a surprise.
| # | Sub-processor | Legal entity | Role (Art 28) | Region | DPA | Certifications | Status |
|---|---|---|---|---|---|---|---|
| 8 | Stripe Payments UK Ltd | Stripe Payments UK Ltd | Processor (and independent controller for payment-method data) | UK + US | Stripe DPA | PCI DSS Level 1, ISO 27001, SOC 1/2 | Goes live with paid plans at MVP launch. |
| 9 | Sentry (error tracking) | Functional Software, Inc. d/b/a Sentry (to confirm) | Processor | EU residency option to be elected | Sentry DPA | SOC 2 Type II, ISO 27001 | Added in Phase 2 ("Production polish"). |
Note on the Anthropic relationship
Anthropic, PBC is listed above for transparency, but the customer–Anthropic relationship is direct, not via Brewyard:
- You sign up for an Anthropic Console account yourself and create your own API key.
- That key is what runs inference. We never run inference under a Brewyard-owned account "on behalf of" you.
- Your contract for the inference itself is governed by Anthropic's published terms that you accept when you create your Anthropic account.
- Brewyard's role is to take your key, store it in a per-user secret in Azure Key Vault, and inject it into the user-isolated TeamForge runtime that calls Anthropic. We are acting as an operator-agent of you.
For the purposes of the GDPR sub-processor list we still surface Anthropic, because customer prompts and responses transit through Anthropic infrastructure. The architectural data flow is published at /data-flow.
Contact
Questions about this list, sub-processor changes, or our Article 28 DPA? privacy@brewyard.ai.