ANNEX A - PUBLIC SUB-PROCESSOR REGISTER
Version: 1.2
Last Updated: 29/07/2026
Maintained By: Data Protection Lead
Email: privacy@channel-chaser.com
Operator: Channel Chaser (operated by Cairncom Communications Ltd)
1. Introduction
This Sub-Processor Register lists all third-party service providers (“Sub-Processors”) engaged by Cairncom Communications Ltd (“Channel Chaser”, “we”, “us”) to support the delivery of the Channel Chaser SaaS platform.
​
A “Sub-Processor” is a third party that processes personal data on behalf of Channel Chaser for the purpose of providing services to our customers, in accordance with:
-
UK GDPR
-
EU GDPR
-
Data Protection Act 2018
-
CCPA/CPRA (Service Provider provisions)
​
We perform due diligence and maintain Data Processing Agreements (“DPAs”) with all Sub-Processors.
2. Current Sub-Processors
Below is the complete and up-to-date list of Sub-Processors used by Channel Chaser.
2.1 Platform Hosting & Infrastructure
Microsoft Corporation (Microsoft Azure App Service & Azure SQL Database)
Purpose:
Application hosting, workflow processing, database services, platform infrastructure, user authentication support and storage of customer workflow data.
Data Processed:
• User account information
• Business contact information
• Reseller and partner information
• Deal and opportunity data
• CRM synchronisation data
• Workflow submissions
• System logs and platform metadata
Location of Processing:
UK / EU / US (depending on Microsoft regional infrastructure and customer configuration)
Protections:
Microsoft Data Protection Addendum, SCCs, UK Addendum, ISO 27001, SOC 1, SOC 2
2.2 Website Hosting & Membership Services
Wix.com Ltd
Purpose:
Marketing website hosting, membership management, user authentication, cookie banner functionality, web security controls and marketing-site infrastructure.
Data Processed:
• User account information
• Login credentials and authentication metadata
• IP addresses
• Device/browser metadata
• Website usage information
• Form submissions
Location of Processing:
EU / US (Region determined by Wix infrastructure routing)
Protections:
SCCs, GDPR-compliant DPA, ISO 27001
2.3 Email, Communication & Productivity Services
Microsoft Corporation (Office 365 / Outlook / SharePoint / OneDrive)
Purpose: Email communication, file storage for support attachments, internal documentation and ticket handling.
Data Processed:
-
User emails
-
Names
-
Support files and attachments
-
Metadata included in support emails
-
Internal notes
​
Location of Processing: EU / UK / US (per Microsoft regional routing)
Protections: Microsoft Data Protection Addendum, SCCs, UK Addendum, ISO 27001
​
Microsoft Corporation (Azure Communication Services)
Purpose:
Transactional email delivery, account notifications, workflow communications, platform-generated service messages and system alerts.
Data Processed:
• Names
• Email addresses
• Email delivery metadata
• Communication preferences
• Message event logs
Location of Processing:
UK / EU / US (depending on Microsoft regional routing)
Protections:
Microsoft Data Protection Addendum, SCCs, UK Addendum, ISO 27001
2.4 Payments & Subscription Management
Stripe, Inc.
Purpose:
Subscription billing, payment processing, fraud prevention, invoicing and payment-related customer communications.
Data Processed:
• Customer name
• Business email address
• Billing information
• Payment metadata
• Subscription status information
Location of Processing:
US / EU (depending on Stripe regional processing)
Protections:
Stripe DPA, SCCs, PCI DSS Level 1, SOC 1, SOC 2
2.5 CRM Integrations (Optional)
HubSpot, Inc.
Purpose:CRM synchronisation, deal pipeline updates, contact record management (when enabled by customer).
Data Processed:
-
Contact names
-
Email addresses
-
Reseller and partner records
-
Deal notes & updates
​
Location of Processing: US / EU (depending on customer’s HubSpot region)
Protections: SCCs, HubSpot DPA, SOC 2, ISO 27001
​​
2.6 Analytics, Consent & Performance Monitoring
Usercentrics GmbH
Purpose:
Cookie consent management, privacy preference storage and consent record management.
Data Processed:
• Consent preferences
• Device/browser metadata
• IP address
• Consent audit records
Location of Processing:
EU
Protections:
GDPR-compliant DPA, ISO 27001
Wix Analytics
Purpose: Website usage analytics, performance monitoring.
Data Processed:
-
Device identifiers
-
Page views
-
User session metrics
​
Location: EU / US
Protections: Wix DPA, SCCs
​
Optional Third-Party Analytics Tools
(e.g., Google Analytics — only if/when activated)
Purpose: Site and platform analytics.
Data Processed:
-
IP address
-
Device/browser data
-
Usage metrics
Location: Global
Protections: SCCs, consent-based activation (UK/EU)
2.7 Support Services
Zoho Corporation (Zoho Desk)
Purpose:
Customer support, ticket management, customer communications and support request tracking.
Data Processed:
• Names
• Email addresses
• Support enquiries
• Support attachments
• Ticket history and communications
Location of Processing:
US / EU / India (depending on service configuration)
Protections:
Zoho DPA, SCCs, ISO 27001
2.8 Security & File Validation Services
OpenAI, LLC
Purpose:
Automated validation and security screening of uploaded company logo image files to assist in detecting invalid, malicious or inappropriate uploads.
Data Processed:
• Uploaded image files submitted for validation
Location of Processing:
US
Protections:
OpenAI business terms, contractual confidentiality obligations and industry-standard security controls.
Additional Notes:
• OpenAI is used solely for uploaded image validation and security screening.
• Customer CRM data, Deal Sheet data, workflow submissions and responder account information are not submitted to OpenAI.
• Uploaded images are not used by Channel Chaser to train OpenAI foundation models.
Support is managed via Microsoft Office 365 (already listed).
3. International Data Transfers
Where Sub-Processors transfer data outside the UK/EU:
-
Standard Contractual Clauses (SCCs)
-
The UK International Data Transfer Addendum
-
Transfer Impact Assessments
-
Appropriate organisational and technical controls
​
…are all used to ensure lawful transfers.
4. Customer Notifications About Changes
We maintain this register to ensure transparency. Customers will be notified:
-
30 days in advance of any new Sub-Processor being added, except where:
-
The Sub-Processor is optional and only activated by the customer
-
The Sub-Processor performs a strictly necessary function (e.g., security)
-
​
Notifications may be sent by email or posted on our website.
5. How Customers Can Object
If you object to a new Sub-Processor:
-
Contact us at privacy@channel-chaser.com within the notice period.
-
We will work with you to find a reasonable alternative.
-
If no alternative is available, you may suspend use of the relevant integration or terminate affected services as permitted by the Terms of Service.
6. Contact Information
For privacy or data protection queries:
​