Legal · Sub-processor register
Sub-processors
This register is the standing, customer-facing list required by clause 5.1 of the Data Processing Agreement. It is reproduced at Annex 3 of the DPA as at the date of signature, and this page is the authoritative version kept current.
1. What a sub-processor is, and what this list is for
Enforza processes personal data on its customers' behalf when it operates the platform. Where Enforza uses another company to help do that, and that company handles customer personal data, it is a sub-processor and it appears below.
Under clause 5.2 of the DPA, Enforza gives 30 days' notice by email before a new sub-processor starts processing, and customers may object on reasonable data-protection grounds. Updating this page alone is not sufficient notice.
What is not on this list: companies that receive no customer personal data. Section 3 explains each exclusion, because an unexplained absence looks like an omission.
2. Current sub-processors
Current as at 26 August 2026.
Notes on entry 1 — AWS
- Enforza operates one production region. There is no multi-region replication, no failover region holding a copy, and no plan to add one without customer agreement (DPA clause 6.1).
- Development and production are separate AWS accounts with zero cross-account dependencies. Production personal data is not used in development.
- The availability monitor runs in
eu-west-1(Ireland) — deliberately outside the region it observes, so a regional failure does not disable the observer. It holds availability telemetry, not customer personal data.
Notes on entry 2 — Stripe
- Most of what Stripe processes is Account Data for which Enforza is a controller in its own right, not a processor for the customer (DPA clause 2.4). It is listed anyway rather than argued about — a customer reading a register should not have to follow a role distinction to find out that Enforza uses Stripe.
- Enforza never holds card data. Card details go to Stripe directly.
Notes on entry 3 — Google Workspace
- Support email is customer personal data. A ticket routinely contains the sender's name and address, and often an IP address, hostname or policy extract pasted in to explain the problem. That makes the mailbox provider a sub-processor, which is why Google appears here rather than being treated as ordinary back-office software.
- The tenant processes in the United States, making this a restricted transfer (DPA Annex 4 route T4).
- Google's Cloud Data Processing Addendum governs this processing. It covers Google Workspace expressly and incorporates the Standard Contractual Clauses, which provide the Article 46 safeguard for the United States transfer.
3. Not sub-processors, and why
Listed because a diligence reviewer will look for each of these and an unexplained absence reads as concealment.
The architectural point behind most of this list being short
Customer network traffic never transits Enforza's infrastructure. Filtering happens on the customer's own machine in the customer's own cloud account. Traffic log entries reach Enforza only when a customer opens the live-log viewer, and then only as a relay held in memory — they are never written to an Enforza database (DPA clause 3.5). Enforza performs no TLS decryption at any point. The set of third parties who could touch customer traffic is therefore empty, not merely small.
4. Change history
Every future addition, removal or change of purpose is recorded here with its date, and notified by email under DPA clause 5.2 thirty days before it takes effect.
Enforza is a product and trading name of Synvu Limited, a company registered in England & Wales (Company No. 15761962), with its registered office at 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Questions about this register can be sent to contact@enforza.io.
← Back to home Data Processing Agreement Privacy Policy Terms of Service