These documents are being prepared for launch. Our Stairwell Ltd has not yet been incorporated. Customer subscriptions will open only after incorporation and completion of the supplier details and launch terms. This draft does not offer a subscription from an existing limited company.
This list forms part of the Data Processing Agreement. A provider processes Customer Personal Data only when its relevant Service or optional feature is enabled. Listing a conditional provider does not mean it receives every customer's data.
Authorised subprocessors
| Provider | Purpose and data | Processing location / transfer | Use |
|---|---|---|---|
| IONOS group | Production compute and network hosting for application, database, authentication, search, support and object-storage components. | United Kingdom hosting region; limited provider support access may occur elsewhere under contractual safeguards. | Core hosting |
| Cloudflare, Inc. | DNS, content delivery, TLS edge, tunnel, web-application protection, rate limiting and bot protection. Processes network identifiers, requests and limited cached content. | Global network. Restricted transfers are covered by Cloudflare's DPA and applicable UK transfer safeguard. | Core edge and security |
| Plus Five Five, Inc. (Resend) | Transactional email, inbound support email and delivery events. Processes sender/recipient details, message content, attachments and delivery metadata. | United States and provider subprocessor locations, using the UK Extension to the EU-US Data Privacy Framework or UK transfer clauses as applicable. | Email and support messaging |
| Amazon Web Services EMEA SARL | Encrypted restricted compliance archive after live-data deletion. | AWS London region (eu-west-2), with provider support and resilience processing subject to AWS contractual safeguards. | Lifecycle archive |
| Better Stack | Availability monitoring, operational logs, error diagnostics and status communications. Data is minimised and may include request identifiers, network identifiers and diagnostic context. | Selected EU region where available; provider support and subprocessors may involve restricted transfers under contractual safeguards. | Conditional observability |
| Ideal Postcodes Ltd | UK address and postcode lookup during workspace and record setup. Processes lookup terms and technical request metadata. | United Kingdom, subject to provider terms. | Address lookup |
| Google Ireland Limited / Google LLC | Calendar synchronisation chosen by an authorised user. Processes selected event details, account identifiers and OAuth tokens. | Global Google infrastructure under Google's applicable UK data-transfer safeguards. | Optional integration |
| OpenAI, L.L.C. | Generation of suggested support replies where Supplier enables that feature. Processes the support content selected for a draft; privacy and security queues are excluded from AI drafting. | United States and other documented provider locations under applicable UK transfer safeguards. | Optional support assistance |
| Backblaze, Inc. | Encrypted off-site database, object-store and infrastructure recovery backups. | EU Central storage region in Amsterdam, Netherlands, with applicable UK international-transfer safeguards. | Conditional backup storage |
Payment and customer-directed providers
GoCardless Ltd receives subscription payer and bank information directly through its hosted mandate flow. It acts under its own payment-services and privacy terms for regulated payment activity, rather than solely as Supplier's subprocessor. Our Stairwell stores provider identifiers, limited account descriptors, payment status and billing contact information needed to administer the subscription.
Customer may also direct data to integrations such as FreeAgent or Google Calendar. Where a provider acts as an independent controller, its terms and privacy notice apply in addition to the Agreement. Self-hosted Keycloak, PostgreSQL, MinIO, Meilisearch and the support application components run inside Supplier's hosting environment and are not separate third-party subprocessors.
Change notices and objections
Supplier will email the current Customer administrator or billing contact at least 30 days before a new or replacement subprocessor begins processing Customer Personal Data. The notice will identify the provider, purpose and expected processing location. Customer can object on reasonable data-protection grounds by emailing privacy@ourstairwell.uk within the notice period. The process and remedies in section 8 of the DPA then apply.
Questions
Requests for relevant provider safeguards or transfer information can be sent to privacy@ourstairwell.uk. Confidential provider documents may require a non-disclosure agreement or be supplied as summaries or independent assurance reports.