Last updated: 18 June 2026
SafeGuard Workers engages the following third-party sub-processors as required by UK GDPR Article 28. Where a DPA is marked pending, the relevant agreement is in the process of being executed and will be updated here once complete.
DPA action required: Resend and Sentry and PostHog DPAs have not yet been executed. Processing continues under the providers' standard terms while DPAs are finalised.
Database and authentication — stores all user data, incident reports, and files
DPA accepted as part of Supabase Terms of Service
Transactional email — welcome emails, report confirmations, legal case notifications
Action required: sign DPA at resend.com → Settings → Legal → DPA
Payment processing for organisation subscriptions
DPA auto-accepted on Stripe account creation per Stripe terms
Error monitoring (session replay only with explicit analytics consent)
Action required: sign DPA at sentry.io → Settings → Legal → DPA
Product analytics — only active after the user accepts analytics in the consent banner
Action required: execute DPA in PostHog organization settings
Frontend hosting and serverless compute
DPA accepted as part of Vercel Terms of Service
Police station lookup for generating police report guidance
Data Processing Addendum applies automatically under Google Cloud Terms
Data residency
Primary data is stored by Supabase in EU data centres where possible. For specific residency requirements contact privacy@safeguardworkers.co.uk.
To exercise your GDPR rights, visit Account Settings or email privacy@safeguardworkers.co.uk.