Legal
Sub-processors
1. About this page
This page lists the third-party service providers (“sub-processors”) that Schemia uses to deliver the Schemia Service. It forms part of our Data Processing Agreement (Annex 3) and is incorporated by reference into the Privacy Policy §5.
We publish this list because it is a contractual commitment to our customers, because our customers (as controllers of personal data they entrust to us) need it to discharge their own UK GDPR Article 28 obligations, and because we believe you have a right to know who else touches your data.
Want to be told when this list changes? Jump to §5 below — we commit to at least 30 days’ written notice before any new sub-processor is engaged, and you can subscribe to a low-traffic notice channel.
2. How we choose sub-processors
Before we engage any sub-processor that processes personal data on a customer’s behalf, we:
- Assess data protection posture. We review the sub-processor’s privacy policy, security documentation, and (where available) independent certifications (SOC 2, ISO 27001, Cyber Essentials).
- Verify a lawful transfer mechanism. Where the sub-processor processes outside the UK or EEA, we require either (a) certification under the UK Extension to the EU-US Data Privacy Framework where applicable, (b) the UK International Data Transfer Agreement, or (c) the UK Addendum to the EU Standard Contractual Clauses. We complete a transfer risk assessment (the “data protection test” under Schedule 7 of the Data (Use and Access) Act 2025) before relying on (b) or (c).
- Flow down obligations. Our contract with each sub-processor imposes data protection obligations no less protective than those we owe our customers under our DPA, including a prohibition on the sub-processor onward-engaging another sub-processor without equivalent commitments.
- Prohibit training on Customer Content. Where the sub-processor is an AI provider, we require that Customer Content is not used to train, fine-tune, or improve the provider’s models. We verify this against the provider’s then-current default API terms before onboarding and on each annual review.
3. Current sub-processors
As of the date at the top of this page.
| Sub-processor | Role | Processing activity | Location of processing | Transfer mechanism (from UK/EEA) |
|---|---|---|---|---|
| Supabase, Inc. | Hosted database, authentication, storage, edge functions | Stores customer schema graphs, account-holder credentials, audit logs; runs customer-triggered edge functions | EU (Frankfurt, primary) and/or US (per project region) | UK Extension to EU-US DPF (US transfers) / UK IDTA where DPF does not apply |
| Cloudflare, Inc. | CDN, edge compute, WAF, DDoS protection, R2 object storage | Caches and serves public-facing pages (including bot sites); protects all customer-facing endpoints; stores published static assets | Global edge network; metadata in US | UK Extension to EU-US DPF (DPF-certified) |
| Google Ireland Limited | Email (Google Workspace), inbound and transactional |
Receives messages sent to Schemia operational addresses
(hello@, privacy@,
legal@, abuse@,
security@) and delivers
Schemia’s transactional service emails during beta
(account, billing, security). Does not process Customer
Content stored in the authoring app.
| EU (Google Ireland Limited tenant, EU data region) | Within UK/EEA — no transfer mechanism required |
| Plausible Analytics OÜ | Privacy-respecting web analytics (marketing site only) |
Counts page views and referrers in aggregate on
schemia.com. Cookieless. No
individual tracking. Script does not load unless a visitor
has opted in to the Analytics cookie category — see
Cookie Policy §4. Not active
on the authoring app or on customer bot sites.
| EU (Estonia) | Within UK/EEA — no transfer mechanism required |
| OpenAI, L.L.C. | AI inference (where customer uses AI-assisted features) | Processes prompts and content the customer submits to AI features; does not train on Customer Content (per OpenAI default API terms) | US | UK Extension to EU-US DPF / SCCs |
| Anthropic, PBC | AI inference (where customer uses AI-assisted features) | Processes prompts and content the customer submits to AI features; does not train on Customer Content (per Anthropic default API terms) | US | UK Extension to EU-US DPF / SCCs |
Notes.
- Operational observability — we will engage an error-monitoring / observability provider (configured to scrub Customer Content from payloads) before broader rollout. It is not currently active. When selected, it will be added to the table above and the 30-day notice mechanism in §4 applies.
- No third-party advertising and no cross-context behavioural tracking — Schemia does not run third-party advertising cookies, does not share data with advertising networks, and does not engage marketing-analytics sub-processors that build cross-site profiles. The Plausible Analytics row above is an aggregate-only, cookieless first-party measurement consumer; it is listed here for transparency, not because it builds tracking profiles. (See Cookie Policy.)
- Customer-introduced integrations. When a customer connects an external integration of their own (e.g. their own CMS, their own search console, a Zapier connection they configure), that integration is the customer’s data processor under the customer’s own contract — not a Schemia sub-processor. Such integrations are not listed here.
4. Change notifications
Before we add, replace, or remove a sub-processor on this list, we will give customers at least 30 days’ prior written notice by:
- updating this page;
- emailing the account-holder email address on file, or notifying you in-product; and
- where you have subscribed to the sub-processor change feed (see §5 below), sending you the change through that channel.
During the 30-day period, you may object on reasonable data-protection grounds by writing to legal@schemia.com setting out the grounds. We will discuss the objection in good faith. If we cannot resolve it, you may terminate the affected portion of the Service and receive a pro-rata refund of any fees paid for the unexpired subscription term, as set out in DPA Clause 5.4.
Routine operational variations within an existing sub-processor’s footprint that do not involve a new legal entity (e.g. a sub-processor moving the customer’s data between its own data centres at the customer’s region selection) are not sub-processor changes and will be reflected here without a notice period.
5. How to be notified of changes
The most reliable way to be notified of sub-processor changes is to subscribe to a low-traffic notice channel. We use this channel only to send sub-processor change notifications and a one-line confirmation when you subscribe or unsubscribe. It is not a marketing list.
Manual subscribe (current). Email
privacy@schemia.com with the subject line subscribe sub-processors
and we will add you to the change-notice channel. We will reply once
to confirm. To stop receiving notices, reply
unsubscribe to any change-notice email
or write to the same address.
We hold subscription records under the lawful basis of consent (UK
GDPR Art 6(1)(a)) and retain them for 3 years from your most
recent confirmed subscription event so we can demonstrate the
accountability requirement under Art 7. You can withdraw consent
at any time by replying unsubscribe;
withdrawal does not affect the lawfulness of processing carried out
before withdrawal.
[Forward-looking — a one-click inline subscribe form with double opt-in is being built; until it ships, the manual email above does the same thing.]
6. Change history
We publish the most recent 12 months of changes to this page (additions, replacements, removals) at /sub-processors/history, with the effective date and the corresponding notice date of each change. This audit trail is provided to help customers discharge their own Article 28 record-keeping obligations and to make any audit under DPA Clause 9 frictionless.
7. Contact
- Sub-processor list questions: privacy@schemia.com
- Legal notices (including objections under DPA Clause 5.4): legal@schemia.com
- Security disclosure: security@schemia.com