Skip to main content
Skip to content
Legal Documents

Sub-Processor List

Last updated: June 27, 2026

Table of Contents

1. What Is a Sub-Processor?

A sub-processor is a third-party service provider that processes personal data on behalf of Shurq Ltd ("Shurq," "we," "us," or "our") to help us deliver our Services. Sub-processors may have access to or process certain categories of personal data as part of providing their services to us.

Under data protection laws such as the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018, we are required to maintain transparency about the third parties that process personal data in connection with our Services.

Important: This page should be read alongside our Privacy Policy, which explains how we collect, use, and protect your personal information, and our Cookie Policy, which details our use of tracking technologies. If you use the Chrome extension, its data handling is covered separately in the Extension Privacy Policy.

2. How We Select Sub-Processors

We take the selection of our sub-processors seriously. Before engaging any third-party service provider that will process personal data, we conduct a thorough due diligence process to ensure they meet our standards for data protection and security.

2.1 Due Diligence Process

Our evaluation of potential sub-processors includes:

  • Security assessment: We review the sub-processor's security practices, certifications (e.g., SOC 2, ISO 27001), and track record for protecting data.
  • Data protection compliance: We verify that the sub-processor complies with applicable data protection laws, including GDPR where relevant.
  • Contractual safeguards: We enter into Data Processing Agreements (DPAs) with each sub-processor that include appropriate technical and organizational measures.
  • International transfers: Where data is transferred outside the EEA/UK, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs).

2.2 Ongoing Monitoring

We periodically review our sub-processors to ensure they continue to meet our standards. This includes monitoring for security incidents, reviewing updated certifications, and reassessing the necessity of each sub-processor relationship.

3. Current Sub-Processors

The following table lists all third-party sub-processors that currently process personal data on our behalf, along with their purpose, the categories of data they process, and their primary data processing location.

3.1 Data Processing Details

Each sub-processor listed above operates under a Data Processing Agreement (DPA) with Shurq that governs the scope, nature, and purpose of data processing, as well as the obligations and rights of each party.

All sub-processors are required to implement appropriate technical and organizational measures to protect personal data, including encryption in transit and at rest, access controls, and regular security assessments.

3.2 International Data Transfers

Most of our sub-processors are based in the United States. For transfers of personal data from the EEA or UK to the US, we rely on one or more of the following safeguards:

  • EU-US Data Privacy Framework (where the sub-processor is certified)
  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Binding Corporate Rules (where applicable)

4. Changes to This List

We may update this sub-processor list from time to time as we add or remove third-party service providers. We are committed to keeping our customers informed about these changes.

4.1 Notification Process

We will provide at least 30 days' prior written notice before adding any new sub-processor that processes personal data. Notifications will be sent via:

  • Email to the account owner's registered email address
  • An update to this page with the effective date of the change
  • A notice within the Shurq platform dashboard (where applicable)

4.2 Effective Date

Changes to this sub-processor list will take effect 30 days after notification, unless a customer raises a valid objection during the notification period (see Section 5 below).

5. Your Rights

If you are a customer subject to data protection laws (such as the GDPR), you have certain rights regarding our use of sub-processors.

5.1 Right to Object

You may object to the appointment of a new sub-processor by notifying us in writing within 30 days of receiving our notification. Your objection must include specific, reasonable grounds related to data protection concerns.

Upon receiving your objection, we will:

  • Make reasonable efforts to address your concerns, which may include providing additional safeguards or using an alternative sub-processor
  • Discuss the objection with you in good faith to reach a mutually acceptable resolution
  • If we cannot reasonably accommodate your objection, either party may terminate the affected services with reasonable notice

5.2 Additional Rights

Under applicable data protection laws, you may also have the right to:

  • Request information about the specific safeguards in place for international data transfers
  • Request copies of our Data Processing Agreements with sub-processors (subject to confidentiality obligations)
  • Lodge a complaint with your local data protection authority if you believe your rights have been violated

6. Contact Us

If you have questions about our sub-processors, wish to object to a new sub-processor, or need more information about our data processing practices, please contact us:

Privacy Inquiries

Email: [email protected]

Subject Line: Sub-Processor Inquiry

Data Protection Officer

Email: [email protected]

For: GDPR-related requests

Postal Address

Shurq Ltd
Privacy Team
London, United Kingdom

We aim to respond to all inquiries within 30 days. For EU/EEA residents, you also have the right to lodge a complaint with your local data protection authority if you believe your rights have been violated.

Have Questions?

Contact our team for any inquiries about our sub-processors