Referenced by the SafeRedact Data Processing Agreements. Controllers receive at least 30 days’ notice before a sub-processor is added or replaced, and may object within 14 days.
Last updated 10 July 2026
Documents are opened, parsed, redacted and exported inside the Controller’s browser. Document files are never transmitted to or stored on SafeRedact systems. Text extracted from those documents is transmitted to the AI sub-processor for classification and is not stored at rest by SafeRedact. Account, authentication, billing and audit records are stored as set out below. Data-subject reference records the Controller chooses to save are held in the Controller’s browser and are never transmitted to SafeRedact.
| Sub-processor | Role | Data processed | Location |
|---|---|---|---|
| Anthropic PBC | AI classification (Claude API) | Text extracted from documents, transiently | United States |
| Supabase Inc. | Authentication and database | Account records, audit logs (including IP address and user agent) | AWS us-east-1 (United States) |
| Vercel Inc. | Application and API hosting | Request metadata; extracted text in transit only | AWS us-east-1 (United States) |
| Stripe, Inc. | Payment processing | Billing contact and payment records | United States |
SafeRedact does not store document content or extracted text at rest. Extracted text sent to Anthropic is retained by Anthropic for no longer than 30 days for abuse monitoring and is never used to train models, under Anthropic’s Commercial Terms and Data Processing Addendum. Account, authentication, billing and audit records are retained for the life of the account and deleted within 30 days of termination or on written request. Saved data-subject reference records never reach SafeRedact systems: they are stored in the Controller’s browser and removed when the Controller deletes them or clears site data.
All sub-processors process personal data in the United States. Transfers from the EEA are made under the Standard Contractual Clauses (Commission Decision 2021/914, Module Two) annexed to the EU DPA; transfers from the United Kingdom are made under the ICO’s International Data Transfer Agreement. Each sub-processor is engaged under a written data processing agreement incorporating the Standard Contractual Clauses where applicable. A transfer impact assessment is available on request.
Anthropic PBC: ISO 27001:2022, ISO 42001, SOC 2 Type II. Supabase Inc.: SOC 2 Type II. Vercel Inc.: SOC 2 Type II. Stripe, Inc.: PCI DSS Level 1, SOC 2 Type II. Evidence is available to Controllers on request.
Questions about this schedule, or a notification preference for sub-processor changes?
Contact us Back to legal