top of page

ANNEX A - PUBLIC SUB-PROCESSOR REGISTER

Version: 1.2
Last Updated: 29/07/2026
Maintained By: Data Protection Lead
Email: privacy@channel-chaser.com
Operator: Channel Chaser (operated by Cairncom Communications Ltd)

 

1. Introduction

This Sub-Processor Register lists all third-party service providers (“Sub-Processors”) engaged by Cairncom Communications Ltd (“Channel Chaser”, “we”, “us”) to support the delivery of the Channel Chaser SaaS platform.

​

A “Sub-Processor” is a third party that processes personal data on behalf of Channel Chaser for the purpose of providing services to our customers, in accordance with:

  • UK GDPR

  • EU GDPR

  • Data Protection Act 2018

  • CCPA/CPRA (Service Provider provisions)

​

We perform due diligence and maintain Data Processing Agreements (“DPAs”) with all Sub-Processors.

 

2. Current Sub-Processors

Below is the complete and up-to-date list of Sub-Processors used by Channel Chaser.

 

2.1 Platform Hosting & Infrastructure
Microsoft Corporation (Microsoft Azure App Service & Azure SQL Database)

Purpose:
Application hosting, workflow processing, database services, platform infrastructure, user authentication support and storage of customer workflow data.

 

Data Processed:

• User account information
• Business contact information
• Reseller and partner information
• Deal and opportunity data
• CRM synchronisation data
• Workflow submissions
• System logs and platform metadata

 

Location of Processing:
UK / EU / US (depending on Microsoft regional infrastructure and customer configuration)

 

Protections:
Microsoft Data Protection Addendum, SCCs, UK Addendum, ISO 27001, SOC 1, SOC 2

 
2.2 Website Hosting & Membership Services
Wix.com Ltd

Purpose:
Marketing website hosting, membership management, user authentication, cookie banner functionality, web security controls and marketing-site infrastructure.

 

Data Processed:

• User account information
• Login credentials and authentication metadata
• IP addresses
• Device/browser metadata
• Website usage information
• Form submissions

 

Location of Processing:
EU / US (Region determined by Wix infrastructure routing)

 

Protections:
SCCs, GDPR-compliant DPA, ISO 27001

 
2.3 Email, Communication & Productivity Services
Microsoft Corporation (Office 365 / Outlook / SharePoint / OneDrive)

Purpose: Email communication, file storage for support attachments, internal documentation and ticket handling.

 

Data Processed:

  • User emails

  • Names

  • Support files and attachments

  • Metadata included in support emails

  • Internal notes

​

Location of Processing: EU / UK / US (per Microsoft regional routing)

 

Protections: Microsoft Data Protection Addendum, SCCs, UK Addendum, ISO 27001

​

Microsoft Corporation (Azure Communication Services)

Purpose:
Transactional email delivery, account notifications, workflow communications, platform-generated service messages and system alerts.

 

Data Processed:

• Names
• Email addresses
• Email delivery metadata
• Communication preferences
• Message event logs

 

Location of Processing:
UK / EU / US (depending on Microsoft regional routing)

 

Protections:
Microsoft Data Protection Addendum, SCCs, UK Addendum, ISO 27001

 
2.4 Payments & Subscription Management
Stripe, Inc.

Purpose:
Subscription billing, payment processing, fraud prevention, invoicing and payment-related customer communications.

Data Processed:

• Customer name
• Business email address
• Billing information
• Payment metadata
• Subscription status information

 

Location of Processing:
US / EU (depending on Stripe regional processing)

 

Protections:
Stripe DPA, SCCs, PCI DSS Level 1, SOC 1, SOC 2

 
2.5 CRM Integrations (Optional)
HubSpot, Inc.

Purpose:CRM synchronisation, deal pipeline updates, contact record management (when enabled by customer).

 

Data Processed:

  • Contact names

  • Email addresses

  • Reseller and partner records

  • Deal notes & updates

​

Location of Processing: US / EU (depending on customer’s HubSpot region)

 

Protections: SCCs, HubSpot DPA, SOC 2, ISO 27001

 

​​
2.6 Analytics, Consent & Performance Monitoring
Usercentrics GmbH

Purpose:
Cookie consent management, privacy preference storage and consent record management.

Data Processed:

• Consent preferences
• Device/browser metadata
• IP address
• Consent audit records

 

Location of Processing:
EU

 

Protections:
GDPR-compliant DPA, ISO 27001

 

Wix Analytics

Purpose: Website usage analytics, performance monitoring.


Data Processed:

  • Device identifiers

  • Page views

  • User session metrics

​

Location: EU / US


Protections: Wix DPA, SCCs

​

Optional Third-Party Analytics Tools

(e.g., Google Analytics — only if/when activated)


Purpose: Site and platform analytics.


Data Processed:

  • IP address

  • Device/browser data

  • Usage metrics

 

Location: Global

Protections: SCCs, consent-based activation (UK/EU)

 
2.7 Support Services
Zoho Corporation (Zoho Desk)

Purpose:
Customer support, ticket management, customer communications and support request tracking.

Data Processed:

• Names
• Email addresses
• Support enquiries
• Support attachments
• Ticket history and communications

Location of Processing:
US / EU / India (depending on service configuration)

Protections:
Zoho DPA, SCCs, ISO 27001

 
2.8 Security & File Validation Services
OpenAI, LLC

Purpose:
Automated validation and security screening of uploaded company logo image files to assist in detecting invalid, malicious or inappropriate uploads.

 

Data Processed:

• Uploaded image files submitted for validation

 

Location of Processing:
US

 

Protections:
OpenAI business terms, contractual confidentiality obligations and industry-standard security controls.

 

Additional Notes:

• OpenAI is used solely for uploaded image validation and security screening.
• Customer CRM data, Deal Sheet data, workflow submissions and responder account information are not submitted to OpenAI.
• Uploaded images are not used by Channel Chaser to train OpenAI foundation models.


Support is managed via Microsoft Office 365 (already listed).

 

3. International Data Transfers

Where Sub-Processors transfer data outside the UK/EU:

  • Standard Contractual Clauses (SCCs)

  • The UK International Data Transfer Addendum

  • Transfer Impact Assessments

  • Appropriate organisational and technical controls

​

…are all used to ensure lawful transfers.

 

4. Customer Notifications About Changes

We maintain this register to ensure transparency. Customers will be notified:

  • 30 days in advance of any new Sub-Processor being added, except where:

    • The Sub-Processor is optional and only activated by the customer

    • The Sub-Processor performs a strictly necessary function (e.g., security)

​

Notifications may be sent by email or posted on our website.

 

5. How Customers Can Object

If you object to a new Sub-Processor:

  1. Contact us at privacy@channel-chaser.com within the notice period.

  2. We will work with you to find a reasonable alternative.

  3. If no alternative is available, you may suspend use of the relevant integration or terminate affected services as permitted by the Terms of Service.

 

6. Contact Information

For privacy or data protection queries:

privacy@channel-chaser.com

 

​

READY TO END THE CHASE?

The pipeline admin stops here.

Spreadsheet-native from day one. Set up in under 10 minutes. No portal rollout required.

bottom of page