Trust Center
Sub-processors
Last reviewed: 2026-07-21
A sub-processor is a third party that may process customer data in the course of providing Compliance Care and the Larenta platform. This page lists every such party, the region in which they operate for our account, the role they play, the class of data they may see, and the status of the contract that governs their use of that data. It mirrors the canonical internal register (CC-LEGAL-SUBP-001), which is updated within fourteen (14) days of any change.
Customers under an active engagement or subscription are notified by email of any change that increases the risk profile (for example, a new overseas sub-processor with access to customer personal information) at least fifteen (15) business days before the change takes effect, with an opportunity to object as set out in the Data Processing Addendum — except where a change is required by law or to address a security risk, in which case notice is given as soon as practicable.
Current sub-processors
| Sub-processor | Region | Role | Data class | Status |
|---|---|---|---|---|
| Amazon Web Services | Sydney (ap-southeast-2) | Hosting for the website and the Larenta platform (App Runner, ECR). | Customer data in transit and in working memory during request handling. | AWS DPA on file. Active. |
| Resend | Tokyo (ap-northeast-1) — not an Australian region | Transactional email delivery: sign-in and verification links, contact-form notification and acknowledgement, newsletter and digest email. | Recipient email address and display name; contact-form message content; newsletter subscriber address. No participant records, worker records, evidence documents, or audit events. | Resend Terms + DPA. Active. See note below. |
| Vercel | Sydney (syd1) | Supplementary hosting, edge CDN, and scheduled-job execution for the website. | Visitor IP, device, and request logs. No participant content. | Vercel DPA on file. Active. |
| Supabase | Sydney | Primary database (Postgres), authentication, file storage, Row-Level Security. | All customer data. | Production DPA on file. Active. |
| Stripe | Australia | Subscription billing and GST invoicing. | Tenant billing contact, card details (held by Stripe — PCI scope reduction), GST invoice data. No participant data. | Stripe Services Agreement (Australia). Active — billing flows only. |
| Anthropic (Claude API) | United States | AI inference for draft production. | Minimised, non-identifying excerpts of customer documents, per the AI handling summary. | Constrained: no customer personal information is submitted until the Anthropic DPA and the conditions in our AI Handling Memo are in place. Internal drafting that involves no customer personal information is permitted. |
| Cloudflare (Turnstile) | United States / global edge | Bot protection on public forms. | Visitor connection and browser signals only; no form content. | Cloudflare terms + DPA. Active — public forms only. |
| Microsoft (Microsoft 365) | Australia (tenant region) | Business email; receives enquiries submitted through the contact form. | Enquirer name, email, phone (optional), organisation, message content. | Microsoft Products and Services DPA. Active. |
| Google (Analytics 4) | United States | Audience measurement on the public marketing website only. Not present on the Larenta platform. | Visitor IP (truncated by Google before storage), device and browser characteristics, pages viewed. No participant records, worker records, evidence documents, or audit events. | Google Analytics Terms + Ads Data Processing Terms. Active — loaded only if you accept analytics cookies. |
| Meta (Pixel) | United States | Measurement of our own advertising, and advertising-audience building, on the public marketing website only. Not present on the Larenta platform. | Visitor IP, device and browser characteristics, pages viewed. No participant records, worker records, evidence documents, or audit events. | Meta Business Tools Terms. Active — loaded only if you accept analytics cookies. |
How we choose a sub-processor
Every prospective sub-processor is assessed against, at minimum: the region of processing (AU preferred; exceptions named in this document); the published data-handling policy; whether they will sign a DPA acceptable to us; their security posture (ISO 27001 or SOC 2 reports requested); and breach-notification SLA.
A sub-processor is not enabled in production until the DPA is executed and the row above is updated.
Planned sub-processors
- E-signature provider (DocuSign or Adobe Acrobat Sign) — planned for engagement-letter signing. The selection will be recorded here, with a DPA executed and AU residency confirmed, before any signature request carries personal information. Until then, engagement letters are exchanged by email.
Removed sub-processors
| Date | Sub-processor | Reason |
|---|---|---|
| 2026-07-14 | Fly.io | Never engaged — application hosting shipped on AWS App Runner (Sydney) instead. |
| 2026-07-14 | AWS Textract | Never engaged — no OCR ingest path shipped. Will be re-listed before any such feature launches. |
| 2026-07-14 | Twilio | Never engaged — no SMS/voice surface shipped. |
| 2026-07-14 | Resend / Postmark (candidate row) | Superseded — Amazon SES (Sydney) selected as the transactional email vendor. |
| 2026-07-21 | Amazon SES (transactional email) | Reversed. AWS declined production access for our SES account twice (case 178399382300285). An SES account without production access can only deliver to addresses verified inside that account, so it cannot send a sign-in link to a new customer. Resend engaged instead — see the note below on the residency consequence. |
| 2026-07-14 | Sentry (candidate row) | Never engaged — no third-party error-monitoring service is in use. |
Change log
| Date | Change |
|---|---|
| 2026-05-25 | Initial publication. |
| 2026-07-14 | Aligned to the live operating stack: added AWS (App Runner + SES), Cloudflare Turnstile, and Microsoft 365; Supabase and Vercel confirmed Active in Sydney; removed never-engaged candidate rows (Fly.io, Textract, Twilio, Resend/Postmark, Sentry); e-signature provider moved to "Planned". |
| 2026-07-21 | Transactional email vendor changed from Amazon SES (Sydney) to Resend (Tokyo). AWS declined SES production access twice, leaving that account unable to email unverified recipients. The Amazon Web Services row is now hosting-only; Resend added as an Active sub-processor with a non-Australian processing region, scoped to email addresses, display names, and message content. |
Note: transactional email is not Australian-resident
Every other sub-processor above operates in an Australian region. Resend is the exception — it has no Australian region, and our sending domain is provisioned in Tokyo (ap-northeast-1).
We changed vendors because Amazon SES became unusable: AWS declined production access for our account twice, and an SES account without it can only email addresses verified inside that account — which cannot deliver a sign-in link to a new customer.
What this does and does not mean:
- What leaves Australia: the recipient's email address and display name, and the content of the message we send (for example, a sign-in link, or the acknowledgement of a contact-form enquiry).
- What does not: participant records, worker records, evidence documents, policies, and audit events never pass through email delivery. The Sydney Supabase project remains the record of every contact-form enquiry; email is a notification on top of that record.
- The disclosure is made to individuals under APP 8 in our Privacy Policy §7.
- If a comparable provider offering an Australian region becomes available, this is re-evaluated at the next scheduled review.
