SIGBOT
Legal & Trust

Subprocessors

Last updated: 30 September 2026

The companies that process customer data for Sigbot, what each one does, what data it receives, where it processes it, and the safeguard for data leaving the UK or EEA.

About this list

This page repeats the subprocessor list in section 5 of our Data Processing Addendum (DPA), with the data each one receives set out in its own column. If the two ever differ, the DPA wins. Section 6 of the DPA explains our international transfers, and its Annex D sets out our technical and organisational measures.

Customer data is stored in the European Union (Google Cloud Firestore, multi-region eur3) and processed by Sigbot's backend in the United Kingdom (Google Cloud europe-west2, London).

How you hear about changes

We give at least 14 days' notice before we add or replace a subprocessor. During those 14 days you can object on reasonable data-protection grounds by writing to legal@sigbot.co. Each notice is posted on this page and in section 5 of the DPA.

Current notice

New subprocessor — notice given 30 September 2026

PostHog, Inc. (product analytics, PostHog EU Cloud) is added to the list with effect from 14 October 2026. PostHog receives usage events from the Sigbot web app — for example, that a scan finished and how many contacts it filed — keyed by a pseudonymous account id. It receives no contact records, email content or email addresses, and is set to discard IP addresses. To object, write to legal@sigbot.co before 14 October 2026.

The list

Subprocessor list last modified: 30 September 2026. Ten entries.

SubprocessorPurposeData it receivesLocationTransfer mechanism
Google Cloud PlatformGoogle LLC Cloud hosting and infrastructure: the database (Cloud Firestore), Cloud Functions, secrets management, logging and monitoring. Customer data — the contact records built from email signatures (name, job title, company, email, phone, business address). Mailbox access tokens, which Sigbot also encrypts itself. Application and security logs, which can hold IP addresses, account ids and email addresses shortened to the first character and the domain. Customer data stored in the EU (Firestore eur3) and processed in the UK (europe-west2, London). Application logs in europe-west2. Google's mandatory audit logs of changes to Sigbot's cloud project are not pinned to a region. SCCs and UK Addendum for data from the UK or EEA.
FirebaseGoogle LLC Application backend and sign-in (Firebase Authentication). Account sign-in data: email address, password hash and sign-in providers. A request log of sign-ins, sign-ups and account changes (the email address used, the IP address and the outcome), kept 30 days. Not pinned to a region. Google states that Firebase Authentication runs from data centres in the United States. SCCs and UK Addendum for data from the UK or EEA.
Google Cloud VisionGoogle LLC Reading the text on a business card photo (optical character recognition). Business-card images. They are processed in memory and are not kept by Google or by Sigbot. European Union (Cloud Vision EU endpoint, which processes data only in the EU). None needed: no restricted transfer for data from the UK or EEA.
Anthropic PBC AI-assisted parsing of an email signature block into contact fields, and classifying a company's sector from its public website. Only while AI parsing is switched on for the account and, for a team scan, for the team. The text of an email signature block, at most 4,000 characters per message, and the text of a company's public website. Under Anthropic's commercial terms it does not train its models on these inputs or outputs and deletes them within 30 days, unless its safety systems flag them (then kept up to 2 years) or the law requires longer. United States. Anthropic's data processing addendum, with SCCs and UK Addendum for data from the UK or EEA.
Vercel Inc. Hosting and content delivery for the web app. Request metadata, such as IP addresses, and request logs. United States, with a global edge network. SCCs and UK IDTA addendum for data from the UK or EEA.
Paddle.com Market Ltd Payment processing, billing and tax, as merchant of record. Payment data. Paddle is an independent controller for it. UK, EU and US. Paddle's SCCs for data from the UK or EEA.
Resend, Inc. Transactional email: email verification, password reset, team invitations, team notices, and order and service emails. The recipient's email address and the message content. United States. SCCs and UK Addendum for data from the UK or EEA.
PostHog, Inc.From 14 October 2026 Product analytics for the web app. Usage events keyed by a pseudonymous account id. No contact records, email content or email addresses. IP addresses are discarded. EU (PostHog EU Cloud, Frankfurt, Germany). PostHog's staff and some of its own subprocessors may access data from outside the UK and EEA. PostHog's DPA, with SCCs, the UK Addendum and the EU-US Data Privacy Framework.
OpenStreetMap FoundationNominatim Turning contact postal addresses into map positions for the map view (geocoding). The request goes straight from the user's browser or phone. The address text and that device's IP address. UK and EU. None needed: no restricted transfer for data from the UK or EEA.
komoot GmbHPhoton Fallback geocoding of contact postal addresses for the map view. The request goes straight from the user's browser or phone. The address text and that device's IP address. Germany (EU). None needed: no restricted transfer for data from the UK or EEA.

Each subprocessor above works under a data protection agreement with Sigbot, except the two public geocoding services (Nominatim and Photon). They receive an address lookup directly from the user's device and handle it under their own published privacy policies.

SCCs are the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914). The UK Addendum is the ICO's International Data Transfer Addendum to them.

Questions

Privacy and contract questions: legal@sigbot.co. Security questions: security@sigbot.co.