Sub-processors
Pocket Docket Ltd · company number NI742827 · registered in Northern Ireland · registered office 137 York Road, Belfast, BT15 3GZ Page: app.pocketdocket.co.uk/legal/sub-processors · Last updated: 20 August 2026
What this page is
To run Pocket Docket we use a small number of third-party providers. Where one of them handles personal data on our behalf, it is a sub-processor, and UK data protection law says you are entitled to know who they are, what they get and where they are.
This page is that list. It does three jobs:
- It is how you give the general authorisation for sub-processors that Article 28(2) UK GDPR requires, and how you exercise your right to be told when the list changes.
- It is the list your own privacy notice can point to.
- It is what makes the consent you give Xero meaningful. Xero requires your consent before data from its API goes to a third party. A consent to unnamed third parties is not worth much, so we name them.
Every sub-processor on this list is under a written contract that imposes data protection obligations materially equivalent to the ones we owe you, including the restrictions on AI training and on cross-customer pooling. We remain fully liable to you for what they do.
We keep this list short on purpose. Every name added is another company holding your customers' details. The list below is the whole of it.
The list
| Provider | What it does for us | What it receives | Where | Transfer basis |
|---|---|---|---|---|
| Vercel Inc. | Hosting and application runtime — the servers Pocket Docket runs on | All application traffic while it is in transit through the platform, and our environment configuration. Vercel does not hold a copy of your ledger; it runs the code that reads it | United States | Data Privacy Framework certification, with the UK Extension. Fallback: the standard contractual clauses in Vercel's data processing addendum, with the UK Addendum |
| Supabase | Managed Postgres — our database | Customer records; your encrypted Xero token set; accounting snapshots and computed figures; trial and referral enquiries; the contact addresses registered to receive dashboard links; device bindings; your assistant conversations with Kipp; hashed security logs | Region-dependent — see note 1 | Standard contractual clauses with the UK Addendum |
| Anthropic PBC | The Claude API — the engine behind Kipp and the signals layer | Per request: the financial figures we have already computed, the question being asked, and the last few questions and answers in the same conversation, so the assistant can follow it. Not your ledger, not your contact list, not your customers' names unless a question is about a named contact. Anthropic does not train models on data submitted through its API | United States | Standard contractual clauses, automatically incorporated into Anthropic's data processing addendum. UK Addendum position to be confirmed; transfer risk assessment required — see note 2 |
| Resend | Transactional email — the emails the Service sends on your instruction | The recipient's email address and the content of the message | EU (Ireland) infrastructure; US company | The EU infrastructure is not the whole answer. Remote access by US staff is still a restricted transfer and we treat it as one: standard contractual clauses with the UK Addendum — see note 3 |
| Stripe | Payments and subscription billing | Your name, email address, card details, billing address, and your subscription and payment history. This is your data as the subscriber, not your customers' data | United States | Data Privacy Framework certification, and the UK IDTA Addendum incorporated into Stripe's Data Transfers Addendum. Stripe is partly an independent controller — see note 4 |
| GitHub, Inc. | Source code hosting | No customer personal data. Our application code and configuration only. Listed here for completeness, because people ask — see note 5 | United States | Not applicable to customer personal data |
| Plaid | Bank account connections | Bank institution, account names and account number masks, transaction history, and the dates you gave consent | Plaid Inc. (United States) / Plaid Financial Ltd (United Kingdom) | INTEGRATED BUT NOT ACTIVE IN PRODUCTION — see note 6 |
Xero is not on this list, and here is why
Your data is already in Xero, under your own agreement with Xero. Xero is not processing it on our behalf — it is the source, and we read from it only because you authorised the connection.
Two things follow, and both are in your favour:
- You can cut us off yourself, instantly. Xero → Settings → Connected Apps → disconnect Pocket Docket. It takes effect immediately, it does not need our co-operation, and it does not need a support ticket.
- Your relationship with Xero is unaffected by ours. Nothing in our terms changes what Xero may do with your data under Xero's own terms.
Notes
1 — Supabase region. Our database region determines where your accounting data sits at rest. We are stating the configured region on this page, and we are also confirming separately whether backups, logs and Edge Functions stay in that region, because they do not always follow the primary.
2 — What Anthropic actually receives, and what it does not. This is the question people ask most, so here is the detail.
Financial figures in Pocket Docket are calculated in our own code, not by the AI model. The model is given figures that have already been worked out, plus your question, and it explains them. That design exists for accuracy — a language model should not be doing arithmetic on your VAT — but it has a privacy benefit too: what leaves our systems is a small set of computed numbers and a question, per request. Not the ledger. Not a contact list.
Anthropic's commercial terms state that it does not train models on data submitted through the API. That restriction is also in our contract with you, at clause 4.2 of the Data Processing Terms, and it binds us regardless of what any provider's terms say in future. If a provider changed its position, we would change provider or turn the feature off. We would not ask you to accept it.
3 — Resend and the "EU infrastructure" trap. Resend's sending infrastructure is in Ireland. That is genuinely useful — your emails are processed in the EU. But Resend is a US company and its staff can access systems remotely for support and operations. Remote access from the US is a restricted transfer under UK GDPR whether or not the servers move. We say so here rather than describing Resend as "EU-hosted" and leaving it at that.
4 — Stripe is not a normal sub-processor, and calling it one would be inaccurate. For most of what Stripe does with your billing data — processing the payment, preventing fraud, meeting its own anti-money-laundering and financial regulatory duties, and complying with card network rules — Stripe decides the purposes itself and acts as an independent controller. For that processing it is not acting on our instructions and our contract cannot bind it. Stripe's own privacy policy applies.
We could have quietly listed Stripe as a processor like everyone else. It would have been simpler and it would have been wrong.
What this means for you in practice: your card details never touch Pocket Docket's systems at all. Payment is taken by Stripe's hosted checkout page. We see that a payment succeeded, the last four digits, the card brand and the expiry — enough to show you your billing history and chase a failed payment, and nothing more.
5 — GitHub holds no customer personal data. Our source code lives on GitHub. Your accounting data does not, and it is not intended to. We list GitHub because a reviewer will find it and ask, and because "we host our code somewhere" is not a secret worth keeping.
The one way customer data could reach GitHub is if it were written into an automation log. Our standing engineering rule is that payloads are never logged and secrets are masked. If that ever changed, GitHub would move up this page into the main table with a proper description, and we would tell you under the change process below.
6 — Plaid is built but switched off. We have integrated Plaid so that a future version of Pocket Docket can read bank transactions directly rather than only through Xero. The feature is disabled in production — the flag that enables it (LEDGER_ROUTE_ENABLED) is not set, no route is live, and no customer data has been or is being sent to Plaid.
It is on this page anyway, for two reasons. First, listing a provider before it is live is the only way to give you a real opportunity to object before your data moves, rather than after. Second, telling you about it only when we switch it on would look like we had been hiding it.
When the feature goes live we will update this page before it does, notify subscribers under the process below, and it will only ever apply to a customer who separately authorises a bank connection. If you never connect a bank account, Plaid never receives anything about you.
Onward providers
Our sub-processors use their own suppliers — cloud infrastructure, monitoring, delivery networks. We do not control those relationships and we cannot warrant a list we do not maintain. Each of our providers publishes its own sub-processor list, and we will point you at the current one for any provider on request.
We say this rather than reproducing their lists, because a copied list goes stale silently and a stale list is worse than a pointer to a live one.
When this list changes
We update this page before a new sub-processor touches customer data, not after. That is a commitment, and it is the one to hold us to.
To be notified: email privacy@pocketdocket.co.uk with the subject line "sub-processor notifications". We will email you at least 14 days before any addition or replacement takes effect, and we will give 30 days wherever our own supplier gives us enough warning to do so.
Why 14 and not 30. Some of our providers give us less notice of their own changes than we would like to give you. Promising a flat 30 days would mean promising something we would eventually have to break. Fourteen days, honestly kept, is worth more than thirty days, occasionally missed.
To object. If you object on reasonable data protection grounds within 14 days of being notified, tell us your grounds and we will discuss it properly. If we cannot offer you a workable alternative — a different provider, a configuration that keeps your data out of scope, or the feature disabled for your account — you can terminate the affected part of the service, or the whole service if it cannot be sensibly separated, and we will refund what you have paid for the period after termination.
Not objecting is not consent to anything else. Silence is not agreement; it just means that particular change goes ahead.
Urgent replacements. If a provider has to be replaced quickly for security, legal or continuity reasons, we will give as much notice as we practically can and tell you as soon as possible with our reasons. Your right to object still applies, just after the event rather than before it.
Change log
| Date | Change |
|---|---|
| 20 August 2026 | Draft published. Stripe and Plaid added — both were missing from the previous version of this page. Stripe's independent-controller role stated. Plaid marked as integrated but not active in production. Resend's US remote-access position stated rather than described as EU-hosted. Onward-provider chains replaced with a standing offer to supply current links. |
We keep this log permanently. It is the evidence of when each authorisation was given, and it is the first thing a regulator or an acquirer's advisers will ask for.
Questions
privacy@pocketdocket.co.uk · Pocket Docket Ltd, 137 York Road, Belfast, BT15 3GZ
Version 1.0 · in force from 21 August 2026
© 2026 Pocket Docket Ltd · Registered in Northern Ireland, company number NI742827 · Registered office: 137 York Road, Belfast, BT15 3GZ · ICO registration ZC223982