Security & legal
Subprocessors
Where we rely on a third party to help deliver our services, that party is engaged as a subprocessor under our data processing agreement.
The current list is issued with the DPA
We publish the subprocessor list alongside the data processing agreement it belongs to, so the version you receive is the one that applies to your contract. We would rather send you an accurate list on request than keep a public table that drifts out of date.
Last updated 27 August 2026
How we engage subprocessors
- Only where there is a reason. A subprocessor is engaged when it is genuinely needed to deliver the service, not by default.
- Under written terms. Each one is bound by data protection obligations no weaker than those we owe you.
- Scoped to a purpose. Access is limited to what the subprocessor needs for the function it performs.
- Reviewed before onboarding. Security posture, data location, and transfer mechanism are assessed before any data flows.
Notice of changes
Customers are notified before a new subprocessor begins processing their data, with an opportunity to object as set out in the data processing agreement. The specific notice period and objection process are stated in that agreement.
Data location and transfers
Where processing or a transfer crosses a border, the mechanism relied on is recorded in the DPA. Data-residency requirements are discussed during evaluation, because they usually shape the deployment option that fits.
This website
The website itself sets no cookies and runs no analytics or advertising trackers, so no subprocessor receives data about your visit here beyond the hosting infrastructure that serves the pages. See the privacy notice for detail.
Questions
Write to dev@bytesurgelabs.com, or raise it with us during a sales conversation if it affects your evaluation.