Sub-processors
Last updated: 17 May 2026
BundleRight is operated by Nimble Tech Ltd. To deliver the service, we use a small number of carefully chosen sub-processors. This page lists every third party that may process personal data on our behalf, the purpose for which they are engaged, and the region in which the processing takes place.
We do not use sub-processors to retain or train on customer document content. AI processing is performed via AWS Bedrock under the AWS Data Processing Addendum, which prohibits retention and training use of prompts and completions. See our Privacy Policy for full detail.
Current sub-processors
| Sub-processor | Purpose | Data | Region |
|---|---|---|---|
| Amazon Web Services EMEA SARL (AWS) | Application hosting, temporary file storage during a session, licence key database, operational logs | Document content (transient, session-only), licence and account data, operational logs | United Kingdom (London region, eu-west-2) |
| AWS Bedrock (Claude Sonnet) | Document classification and metadata extraction (text in, JSON out) | Extracted document text only — sent in-prompt and not retained by AWS or Anthropic | United Kingdom (Bedrock London region) |
| AWS Bedrock (Claude Haiku) | OCR recovery for image-only PDFs and multi-document PDF splitting | Rendered page images and extracted text — not retained by AWS or Anthropic | European Union (Bedrock EU geo profile — London, Dublin, Frankfurt, Stockholm, Milan, Madrid, or Paris) |
| Stripe Payments Europe Ltd | Processing one-off credit top-ups via Stripe Checkout | Billing email, firm name, payment information (we never see or store card details) | European Union, with international transfers under Stripe's own DPA and safeguards |
| Amazon Simple Email Service (SES) | Sending transactional email (licence-key delivery, top-up receipts, service notifications) | Email address, firm name, transactional message content | European Union (Ireland, eu-west-1) |
| Cloudflare, Inc. | Edge DNS, TLS termination, and DDoS protection for bundleright.co.uk and app.bundleright.com | IP address and basic request metadata; no document content traverses Cloudflare | Global edge network with EU/UK presence; processing governed by Cloudflare's DPA |
Changes to this list
We will update this page when we add, replace, or remove a sub-processor. Where the change is material — for example, adding a new provider that processes document content or changing the region in which processing takes place — we will notify customers by email and update the "Last updated" date above.
If you have a contractual right under a signed Data Processing Agreement to object to new sub-processors, the notice period and objection mechanism set out in that DPA apply.
How we choose and oversee sub-processors
Before engaging a sub-processor, we:
- Confirm the provider offers contractual data protection terms at least as strong as our own commitments to customers, including UK GDPR Article 28 obligations
- Confirm the location and region of processing, and the safeguards in place for any international transfer
- Limit the data shared with the provider to what is necessary for the specific purpose
- Review the relationship periodically and at any material change to the service
Contact
Questions about this list, or to request our Data Processing Agreement, can be sent through our contact form.