Articles on: Compliance & Legal

Sub-Processors

At Prospectus Plus, we are committed to protecting the privacy of our users and clients.


We work with trusted third-party service providers (sub-processors) to deliver our services.


Each sub-processor below may process personal data on our behalf, and where required, we maintain appropriate Data Processing Agreements (DPAs).


Sub-processor

Purpose

Data Processed

Location

Notes

Further Information

Kinsta

Hosting (backend infrastructure)

All user and client data stored in app

EU (with Google Cloud as sub-processor)

Hosted on Google Cloud infrastructure via Kinsta.

Kinsta Trust Center - Kinsta DPA

Google Cloud Platform (via Kinsta)

Infrastructure (storage and compute)

All user and client data stored in app

EU

Underlying cloud infrastructure for Kinsta services.

Google Cloud DPA

Amazon Web Services (AWS) Amplify

Hosting (frontend delivery)

Limited user data (IP addresses via CDN logs)

EU/US

Frontend hosting for Prospectus Plus platform.

AWS Compliance Program - AWS Subprocessors - AWS DPA

AWS Simple Email Service (SES)

Email delivery service

User and client email addresses

EU/US

Transactional emails only.

AWS Compliance Program - AWS Subprocessors - AWS DPA

HubSpot

CRM and marketing communications

Client contact information (names, emails, job roles)

EU/US

CRM for university client management.

Hubspot DPA - Hubspot Data Transfer

Crisp

Live chat support

Visitor data (IP addresses, optional names/emails if entered)

EU

Website and platform support chat.

Crisp DPA Template (we have signed and returned this)

Google Analytics

Website and app analytics

Pseudonymised user behaviour data

US

Used for platform analytics. IP anonymisation enabled.

Google Analytics DPA - Google Cloud DPA

DocuSign

Electronic signature services

Client staff names, emails, and signed documents

US

Used for contract management and approvals.

Docusign DPA

Xero

Accounting software

Client billing contacts (names, emails)

US

Financial and billing information.

Xero Data Processing Statement

Google Workspace

Document storage and communications

Client communications (emails, docs)

EU

Internal email and document management.

Google Cloud DPA

Tidycal

Appointment scheduling

Client staff names and emails

US

Used to book demos and client meetings.

Tidycal DPA

Asana

Project management

Internal notes and project data (may include client names/emails)

US

Internal task management.

Asana Data Processing Statement

Grain

Meeting recording and transcription

University staff (recorded demos or meetings)

US

Used to record and transcribe client meetings.

Grain Sub-processors - Grain Trust Center

We review and update our list of sub-processors regularly to ensure that appropriate levels of data protection are maintained.


Where material changes are made, clients will be notified in advance wherever feasible.


If you have any questions about how your data is handled, please contact us.

Updated on: 13/06/2025

Was this article helpful?

Share your feedback

Cancel

Thank you!