Back to Brewyard

Sub-processors

Last updated: 2026-06-01. Owner: Cagdas Arda.

Brewyard is operated by Fincard Ltd, registered in England and Wales. We act as data processor on behalf of our customers for project content, agent prompts/responses, and stored API credentials; and as data controller for billing identifiers, account identifiers, and operational telemetry. The third parties below process customer data on our behalf under appropriate Article 28 contracts.

We commit to giving customers at least 14 days' written notice before adding or replacing a sub-processor in a way that materially affects them, in line with UK GDPR Article 28(2). Notice is delivered via email to the account owner and via a changelog entry at the top of this page.

Active sub-processors

#Sub-processorLegal entityRole (Art 28)RegionDPACertifications
1Microsoft Azure — Container AppsMicrosoft Ireland Operations Ltd (to confirm)ProcessorAzure UK South (London)Microsoft DPAISO 27001, ISO 27017, ISO 27018, SOC 1/2/3
2Microsoft Azure — PostgreSQL Flexible ServerMicrosoft Ireland Operations Ltd (to confirm)ProcessorAzure UK South (London)Microsoft DPAISO 27001, ISO 27017, ISO 27018, SOC 1/2/3
3Microsoft Azure — Key VaultMicrosoft Ireland Operations Ltd (to confirm)ProcessorAzure UK South (London)Microsoft DPAISO 27001, ISO 27017, ISO 27018, SOC 1/2/3
4Resend (transactional email)Plus Five Five, Inc.ProcessorUS (with EU-US DPF certification)Resend DPASOC 2, EU-US DPF + UK Extension
5Anthropic, PBC (model inference)Anthropic, PBC (Delaware)See note below — direct customer relationship.USAnthropic Commercial TermsSOC 2 Type II (per public statements, to re-verify)
6PostHog Inc. — PostHog Cloud EUPostHog Inc.ProcessorEU (AWS eu-central-1, Frankfurt)PostHog DPASOC 2 Type II, HIPAA (where elected), ISO 27001 (to confirm)
7Cloudflare (CDN, WAF, DDoS edge)Cloudflare, Inc. (to confirm)ProcessorGlobal edge; UK + EU points of presence prioritisedCloudflare DPAISO 27001, SOC 2 Type II, PCI DSS

Planned but not yet live

These will move to Active when the corresponding feature ships. They're listed here for transparency so the timing of any new processor is never a surprise.

#Sub-processorLegal entityRole (Art 28)RegionDPACertificationsStatus
8Stripe Payments UK LtdStripe Payments UK LtdProcessor (and independent controller for payment-method data)UK + USStripe DPAPCI DSS Level 1, ISO 27001, SOC 1/2Goes live with paid plans at MVP launch.
9Sentry (error tracking)Functional Software, Inc. d/b/a Sentry (to confirm)ProcessorEU residency option to be electedSentry DPASOC 2 Type II, ISO 27001Added in Phase 2 ("Production polish").

Note on the Anthropic relationship

Anthropic, PBC is listed above for transparency, but the customer–Anthropic relationship is direct, not via Brewyard:

  • You sign up for an Anthropic Console account yourself and create your own API key.
  • That key is what runs inference. We never run inference under a Brewyard-owned account "on behalf of" you.
  • Your contract for the inference itself is governed by Anthropic's published terms that you accept when you create your Anthropic account.
  • Brewyard's role is to take your key, store it in a per-user secret in Azure Key Vault, and inject it into the user-isolated TeamForge runtime that calls Anthropic. We are acting as an operator-agent of you.

For the purposes of the GDPR sub-processor list we still surface Anthropic, because customer prompts and responses transit through Anthropic infrastructure. The architectural data flow is published at /data-flow.

Contact

Questions about this list, sub-processor changes, or our Article 28 DPA? privacy@brewyard.ai.