THIRD PARTIES THAT PROCESS DATA

Every third party we use, and what for.

This is the complete list of sub-processors Counsel.day relies on to deliver the product. Each row names the vendor, the data category processed, the location of processing, the legal transfer mechanism used to move data across borders, and the DPA (Data Processing Agreement) status. We publish in advance of using a new vendor; the changes log at the foot of this page records every addition.

Effective14 MAY 2026
Last revised14 MAY 2026
Total vendors7
§ 01 · THE LIST

The seven vendors, in full.

Each vendor below has a signed DPA in place. Where we transfer personal data out of the EU or UK, we rely on the European Commission's Standard Contractual Clauses (SCCs) and the UK Addendum where applicable. Where the destination has an EU adequacy decision, we record that as the transfer mechanism instead.

Vendor
Purpose
Data category
Location
Transfer mechanism
DPA
Stripe, Inc.stripe.com
Payment processing, fraud screening, 3-D Secure, tax collection.
Card token, billing country, last 4 digits, IP, amount, email.
USA · EU
SCCs + UK Addendum; EU Data Processing Annex.
Signed
Brevo SASbrevo.com · formerly Sendinblue
Transactional email · daily-vote prompts, partner invites, verdict delivery, security alerts.
Email address, display name, transactional message body, delivery telemetry.
EU · France
EU adequacy (in-region).
Signed
Anthropic PBCanthropic.com
Verdict synthesis on paid tiers · Claude Opus 4.7 generates the written paragraph and the conversation prompt.
Anonymised vote series, anonymised note text, anonymised theme list. No account identifier; no email.
USA
SCCs + UK Addendum; zero-retention API tier (data not used to train models).
Signed
Cloudflare, Inc.cloudflare.com
Edge CDN, TLS termination, Web Application Firewall, DDoS mitigation, bot management.
IP address, user-agent, request headers, TLS handshake metadata. No request bodies.
Global edge · USA HQ
SCCs + UK Addendum; Cloudflare Data Localisation Suite pins logs to EU.
Signed
Zoho Corporationzoho.com · EU data centre
Business productivity · Zoho Mail, WorkDrive, Meeting, Cliq for internal communications and documents.
Counsel.day staff email, internal documents, support email threads (only when a user emails us directly).
EU · Netherlands
EU adequacy (in-region); Zoho EU DC contractually locked.
Signed
Infisical, Inc.infisical.com · self-hosted
Secrets management · API keys, encryption keys, service tokens. Self-hosted on our own AWS EU infrastructure.
No user data. Application secrets only.
EU · self-hosted
EU adequacy (in-region); no transfer outside EU.
Source-available
Amazon Web Servicesaws.amazon.com · eu-central-1
Compute, storage, managed Postgres, encrypted backups. Production runs in Frankfurt.
All decision data, account data, encrypted backups. Row-level-security enforced.
EU · Frankfurt
EU adequacy (in-region); AWS DPA + EU-pinned regions; SCCs in place for the AWS account itself.
Signed
§ 02 · CHANGES

How we notify on a new sub-processor.

We publish a proposed change to this list at least thirty days before a new sub-processor begins to process user data. The notification is sent by email to every account holder and announced on the marketing site. If you object to a specific sub-processor on reasonable grounds (jurisdiction, audit record, ownership), write to privacy@counsel.day during the notice period; if we cannot accommodate the objection, you have the right to close the account and receive a pro-rata refund of any annual subscription.

Material change history is kept indefinitely; the most recent revisions are summarised below.

  • 14 May 2026: First publication of this page in the Iteration 8 (white + wine) layout. No vendors added or removed since the last revision.
  • 28 Apr 2026: Added Zoho Workspace as the business productivity provider, replacing the previous Microsoft 365 tenancy. EU data centre.
  • 14 Apr 2026: Confirmed Anthropic zero-retention API tier; updated the data category column to reflect the anonymisation pass that runs before any Claude request.
§ 03 · QUESTIONS

If something on this page does not add up.

If you spot a sub-processor we are clearly using and have not listed (a font CDN, a status-page provider, a JavaScript SDK), write to privacy@counsel.day. The omission is either a bug in this page or a vendor we are about to replace; in either case we want to know. Response within five business days.

Top