Cloudflare
Provider: Cloudflare group entity applicable to the Eselram/customer account.
Purpose: hosting, security, provisioning, routing and customer-controlled deployment infrastructure.
Data: technical identifiers, traffic/security information and, where applicable, customer operational data stored or transmitted through Cloudflare resources.
Role: core infrastructure and a subprocessor where Eselram engages Cloudflare to process Controller Personal Data on Eselram's behalf. Resources created in a customer's own Cloudflare account may instead be directly contracted and controlled by that customer.
Stripe
Provider: Stripe group entity applicable to the relevant account.
Purpose: Eselram subscription billing and optional customer payment integration.
Data: business/contact details, billing information and payment or transaction references.
Role: Stripe processes Eselram's own subscription payments under Stripe's applicable terms. A customer's connected Stripe account is a customer-selected integration and may involve Stripe acting directly for that customer rather than as an Eselram subprocessor.
Google / Gmail
Provider: Google group entity applicable to the connected account.
Purpose: optional outbound email sending through Gmail.
Data: OAuth identity/authorisation information, recipient details and outbound message content needed to send the customer's configured email.
Role: customer-selected integration. Eselram processes connection information needed to establish and maintain the integration. Eselram requests gmail.send and does not require inbox-reading permission for this feature.
Resend and other supported email providers
Purpose: optional outbound operational email where that provider is enabled.
Data: recipient address, delivery metadata and message content.
Role: where the customer selects and directly configures its own provider account, that relationship is customer-controlled. If Eselram centrally contracts a provider to send customer communications on Eselram's behalf, that provider is treated as a subprocessor and is subject to the DPA's subprocessor requirements.
Professional and operational service providers
Eselram may also use professional advisers, fraud/security services or support tooling for its own controller-side business information. Those providers are not automatically subprocessors of Controller Personal Data. If a provider is given routine access to Controller Personal Data to perform processing for Eselram, this notice will be updated as appropriate.
Changes to subprocessors
Where Eselram relies on the Controller's general authorisation under the DPA, Eselram will provide reasonable advance notice of a material new subprocessor where required and allow the Controller to raise a reasonable, documented objection on data-protection grounds.
International transfers
Provider locations and support access can change. Where Eselram initiates a restricted transfer, it will use an applicable UK adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another lawful mechanism as appropriate. Customers should separately assess transfers created by accounts and providers they independently select or control.
Contact
Questions about subprocessors, provider roles or applicable transfer safeguards can be sent to [email protected].