CivilQuants — Sub-Processors
Effective date: 2026-05-31
Version: v1 (vault-drafted 2026-05-17; aligned with ToS v1.2 + Privacy Policy v1.2 + Customer DPA v1)
Last updated: 2026-05-17
What this page is
This page lists the third-party service providers (each a "Sub-Processor") that Ember Forge Pte Ltd uses to deliver CivilQuants. We publish the full list, including each provider's role, the region in which they process your data, the data-transfer mechanism we rely on, and the date we signed our Data Processing Agreement (DPA) with that provider.
We publish this page so that:
- Our Privacy Policy §4 statement that "each commercial provider is bound by a Data Processing Agreement" is verifiable at a glance.
- Our Customer DPA §6 (Sub-Processors) general-authorisation model is operationally transparent.
- Our business customers (Studio / Practice) can run this list through their own data-protection-procurement processes without raising support tickets.
- Anyone evaluating CivilQuants for procurement purposes can see exactly where the data flows and under what safeguards.
We update this page whenever a Sub-Processor is added, removed, or materially changes its role, region of processing, or transfer mechanism. We commit to at least 30 days' prior written notice to active business customers before any such change becomes effective, in line with Customer DPA §6.2.
The list
| Sub-Processor | Role | Categories of data processed | Region of processing | Transfer mechanism (for UK / EU personal data) | DPA signed |
|---|---|---|---|---|---|
| Stripe Payments Europe / Stripe Inc. | Merchant of Record; payment processing, billing data, tax calculation and reporting, fraud screening | Card payment data (handled by Stripe directly — we never see card numbers), billing address, VAT/GST registration number, transaction outcomes | Global (Stripe has UK/EU/SG entities; routing depends on Stripe's configuration) | Stripe's own SCC framework + adequacy where available | Pending — to be confirmed |
| Resend | Sending transactional email (receipts, security alerts, billing notifications) and — with your explicit consent — marketing email (product updates, QS productivity tips) | Email address, send/open/click events, unsubscribe state | United States (EU region pending Resend GA) | UK ICO IDTA + EU SCCs + supplementary measures (encryption in transit and at rest) | Pending — to be confirmed |
| Clerk | Authentication (account email, password hash if applicable, magic-link tokens, MFA factors, session tokens) | Email address, password hash, auth session, MFA factors | United States | UK ICO IDTA + EU SCCs + supplementary measures | Pending — to be confirmed |
| Cloudflare, Inc. | DNS, CDN, DDoS protection, edge logs (short retention), R2 object storage for generated artefacts | IP address, request metadata, edge logs; R2 stores artefacts derived from your project inputs | Global edge network; R2 storage region configured at deployment | UK ICO IDTA + EU SCCs (for any data egress to US backbones) + supplementary measures | Pending — to be confirmed |
| Sentry | Error monitoring (error events, stack traces, hashed user identifier, strict-error capture per our Cookie Policy §4.2) | Error events, stack traces, hashed user identifier; project content redacted from error payloads | EU region (configured + verified at deployment per Privacy Policy §4) | None required for EU-to-UK and EU-to-EU; SCC fallback if any Sentry sub-processor is outside EU | Pending — to be confirmed |
| PostHog | Optional product analytics (page views, feature usage, funnels; consent-gated via our Cookie Policy) | Usage events, page views, session metadata, IP address, anonymised user identifier — only when you have given consent via our cookie banner | EU region (configured + verified at deployment per Privacy Policy §4) | None required for EU-to-UK and EU-to-EU; SCC fallback if any PostHog sub-processor is outside EU | Pending — to be confirmed |
| Google Ireland Limited ("Google Ads") | Advertising-conversion measurement — confirming whether an ad click led to a purchase (consent-gated via the Marketing category of our Cookie Policy; fires only on post-purchase confirmation pages) | Conversion event, advertising click identifier, IP address — only when you have given Marketing consent via our cookie banner | Global (Google has EU/US entities; routing depends on Google's configuration) | Google's own SCC framework + adequacy where available | Pending — to be confirmed |
| Fly.io | Hosting infrastructure (application servers + Postgres database) | All application data + project inputs and outputs you save | London (LHR) region for v1 | None required for LHR-to-UK and LHR-to-EU; SCC fallback if Fly's US control-plane processes any data | Pending — to be confirmed |
Tax authorities and professional advisors (not Sub-Processors, but listed for completeness)
The following parties also receive personal data from us in specific, narrow circumstances. They are not Sub-Processors in the data-protection sense — they act as independent controllers under statutory or professional duty, not as processors on our behalf.
| Recipient | What they receive | Basis |
|---|---|---|
| HMRC (UK), IRAS (Singapore), EU Non-Union OSS scheme via to be confirmed at EU OSS registration; see [[wiki/spin-outs/civilquants-privacy-policy-v1]] for the current version, ATO (Australia), IRD (New Zealand), CRA (Canada), LHDN (Malaysia) | Tax records as required by applicable law | Statutory legal obligation |
| Our accountant (Singapore-based) | Books and records as required for accounting and tax | Professional accounting services |
| Our legal counsel (Singapore + UK) | Contracts and correspondence as required for legal advice (engaged on a case-by-case basis post-launch) | Professional legal services |
How to stay informed of changes
We notify changes in two channels:
- Active business-customer email notifications. If you have a Studio or Practice subscription, you will receive an email to your account-administrator address at least 30 days before any material change to a Sub-Processor (additions, region changes that materially affect data protection, role changes affecting categories of data processed). Customer DPA §6.2 sets out the operational mechanic; §6.3 explains your right to object.
- This page. This page itself is the canonical source. The "Last updated" date at the top reflects the most recent change. The change-log below records material changes.
If you would like to receive an email whenever this page changes (regardless of whether you are an active subscriber), email dpo@emberforge.sg and we will add you to a Sub-Processor change-notification list.
Change log
| Date | Change |
|---|---|
| 2026-05-31 | Page first published. List as above at first launch. |
| 2026-06-01 | Added Google Ireland Limited ("Google Ads") as a Sub-Processor for consent-gated advertising-conversion measurement (Marketing cookie category, Cookie Policy v1.3). Data flows only for users who opt into Marketing consent. |
(Future entries appended below as Sub-Processors are added, removed, or materially changed.)
Why we use Sub-Processors
We are a small team building a focused product. Rather than re-implement payment processing, email infrastructure, authentication, hosting, error monitoring, and product analytics ourselves (and likely do them worse than specialists do), we use established providers with strong security and data-protection postures. This lets us focus our own engineering on what we do best — the parametric civils estimating engine.
Each Sub-Processor is bound by a written Data Processing Agreement (DPA) that imposes equivalent data-protection obligations to those we owe you. We remain liable to you for the performance of each Sub-Processor's data-protection obligations as if they were our own.
We pick Sub-Processors based on (in priority order): (1) data-protection posture (region of processing, certifications, contractual safeguards); (2) operational reliability; (3) cost. We will swap a Sub-Processor if a better-positioned alternative emerges and the switch can be done without materially disrupting the Service.
Questions
Email dpo@emberforge.sg with any question about this page or about how we work with the Sub-Processors listed above.
Related documents
- Privacy Policy §4 (sub-processor table — this page is the customer-facing live version of that table) — Privacy v1.2
- Customer DPA §6 (Sub-Processors clause governing change-notice and your right to object) — DPA v1, available on request to
dpo@emberforge.sg - Terms of Service — ToS v1.2