GuardVett

GuardVett Subprocessor Register

Version 1 · Approved for implementation on 21 September 2026

Website preview. The wording has been approved for implementation. Factual publication checks remain in progress; this preview does not change existing agreements.

On this page
  1. 1 Scope and responsibility
  2. 2 Location and transfer information
  3. 3 Supabase
  4. 4 Microsoft Azure AI Document Intelligence
  5. 5 Fly io
  6. 6 Vercel
  7. 7 Resend
  8. 8 Anthropic
  9. 9 Sentry when enabled
  10. 10 Stripe and other business services
  11. 11 Changes and further information

1 Scope and responsibility

GuardVett is provided by ISO Consultants U.K. Limited, company number 10766230, Lewis Building, 35 Bull Street, Birmingham, England, B4 6AF. Questions, requests for transfer information and subprocessor objections should be sent to sales@guardvett.com, marked “Data protection”.

A subprocessor handles screening personal data on ICUK’s behalf when ICUK acts as a processor for the customer. Some services also handle ICUK’s own business information, and some providers act as independent controllers for particular purposes. Those roles depend on the processing, not just the supplier’s name.

The existing DPA, reference ICUK-GV-DPA-001 Issue 1 Rev C, governs customer authorisation. Its clause 7 requires at least 30 days’ prior notice of an intended addition or replacement and permits objections on reasonable data-protection grounds during that period. Publication of this draft does not replace that notice or amend Schedule 3. ICUK remains responsible for subprocessor performance as the DPA requires.

2 Location and transfer information

A selected hosting region identifies where a particular workload is placed. It does not by itself establish where every backup, log, email route, support action or onward supplier operates. For each restricted transfer, ICUK must confirm the recipient, countries, applicable mechanism and assessment before approving the route. Possible mechanisms include UK adequacy regulations or suitable contractual safeguards with the required UK provisions. This register does not assert blanket UK-only or EEA-only processing.

3 Supabase

Function and role: database, authentication and private file storage; a screening-data subprocessor and a processor for relevant account information.

Information involved: screening records and uploaded evidence, account and authentication records, permissions, audit events, application and reference workflow data, and stored correspondence. Access to particular information depends on the service and support activity.

Location evidence: the GuardVett production project has been identified as the London region. Supabase’s contracting entity in its published DPA is Supabase Pte. Ltd. Its terms distinguish selected-region primary processing from wider supplier operations.

Confirmation required: preserve the applicable executed or accepted DPA, identify the account contracting entity, and verify backups, support access, log locations, retention and onward transfers. Do not describe the provider’s legal entity as UK-based solely because the database is in London.

Reference: Supabase Data Processing Addendum.

4 Microsoft Azure AI Document Intelligence

Function and role: optical character recognition and document layout extraction; screening-data subprocessor. The Microsoft contracting entity depends on ICUK’s Azure agreement and must be confirmed from it.

Information involved: submitted document or page bytes, including the personal and potentially sensitive information they contain, and extracted text, layout and recognition results.

Location evidence: GuardVett’s reader is designed to require a UK South response region and uses prebuilt recognition models. Source review supports that design; a response-region check is not independently proof of every deployed resource and access route.

Retention: Microsoft’s published service guidance describes temporary input and result storage for 24 hours after completion, with an API for earlier deletion. GuardVett requests result deletion after processing and reports failure. Early deletion is an attempted control, not an unconditional guarantee that every result is immediately erased.

Confirmation required: verify the deployed resource region, applicable Microsoft DPA and transfer terms, support arrangements and evidence of successful deletion handling.

Reference: Microsoft Document Intelligence data privacy and security.

5 Fly io

Function and role: background worker hosting for document processing, scheduled jobs, reference workflows and retention; screening-data subprocessor. The provider is Fly.io; confirm the legal contracting entity from the account agreement.

Information involved: records and files accessed by workers, job payloads, correspondence content and operational logs. An absence of a public worker website does not mean the worker processes no personal information.

Location evidence: the checked worker configuration specifies London. The inspected configuration names the staging application; production machine placement, storage and support access must be confirmed separately.

Confirmation required: current production region and volumes, log retention, supplier access, accepted DPA and international-transfer arrangements. Fly.io makes a DPA available through its compliance resources; public availability does not prove customer execution.

Reference: Fly.io compliance documents.

6 Vercel

Function and role: hosting and serving the GuardVett application and website, including application requests and server processing; screening-data subprocessor where those requests contain screening information.

Information involved: account and session information, request metadata and IP addresses, application forms, records handled by server routes, and relevant logs. Some upload flows send files directly to Storage, but that does not establish that every file or personal-data request bypasses Vercel.

Location evidence: the signed-in Vercel dashboard was checked on 21 September 2026. Both the live production deployment and function settings show London (lhr1). Edge routing, logs, support and onward processing still require separate verification. Vercel Inc. is a US entity under its published DPA; confirm the contracting account terms.

Confirmation required: deployed function regions, log settings, applicable DPA, UK transfer provisions and any processing outside the selected function region.

Reference: Vercel Data Processing Addendum.

7 Resend

Function and role: transactional emails, reference and candidate communications, and inbound reply handling; screening-data subprocessor. Confirm the legal contracting entity from ICUK’s Resend agreement.

Information involved: sender and recipient names and addresses, message bodies, headers, delivery events and attachments, including screening information included in a message or reply.

Location and retention evidence: no account-specific EU-only handling or retention period has been verified. Resend’s published DPA covers sending, receiving and storage of message content; its supplier list includes US providers. A sending-region selection does not establish the location of inbound content, logs, dashboard data or support processing.

Confirmation required: outbound and inbound processing regions, message and attachment retention, deletion capabilities, applicable DPA and UK transfer arrangements. Do not state that Resend merely passes messages through or that it keeps no copies.

References: Resend Data Processing Addendum and Resend subprocessors.

8 Anthropic

Function and role: commercial API for AI-assisted document and screening-file analysis; screening-data subprocessor. Confirm the applicable Anthropic contracting entity in the commercial account agreement.

Information involved: prompts, relevant screening context, document text and, where a workflow uses those paths, images or PDF content; generated analysis and structured output. The code supports image and PDF inputs, so “document text only” is not a safe universal description.

Location and retention evidence: the existing DPA identifies US processing. Anthropic’s commercial guidance says inputs and outputs are not used for model training by default. Its standard API retention guidance describes deletion within 30 days with stated exceptions, including agreed arrangements, policy enforcement and legal requirements. Zero data retention has not been verified for this account or every enabled feature.

Confirmation required: account-specific retention and feature eligibility, processing countries, applicable commercial DPA and UK transfer provisions, and no opt-in use of customer content for provider training or feedback. No-training and zero-retention are different claims.

References: Anthropic DPA, commercial training policy and retention guidance.

9 Sentry when enabled

Function and role: server error reporting. The published DPA identifies Functional Software, Inc., trading as Sentry. This is a conditional provider entry, not confirmation that production reporting is enabled.

Information involved: diagnostic events, error messages and request context. The inspected code disables default personal-information collection and applies scrubbing, but that is not proof that every event is anonymous. Sentry is a screening-data subprocessor if such events include screening personal data; it may also process ICUK account or security information.

Location evidence: reporting initialises only when SENTRY_DSN is configured. On 21 September 2026, searches of the current production Project and Shared environment-variable lists in Vercel returned no Sentry configuration. Historical deployments and the background worker have not been checked; this is not a blanket assurance that Sentry has never received data.

Confirmation required: determine whether production uses Sentry; if it does, verify event contents, region, retention, contract and transfer safeguards and reconcile its authorisation with the customer DPA. Sentry is mentioned in the help material but is not listed in the active DPA Schedule 3. Listing it here does not retrospectively authorise use.

Reference: Sentry Data Processing Addendum.

10 Stripe and other business services

Stripe: used for subscription billing, payment collection and subscription status. GuardVett’s intended billing data includes customer and billing contacts, payment references, invoices, plan and subscription information. Screening documents and candidate evidence are not required for that purpose and must not be put in payment metadata.

Stripe may act as processor for some services and as an independent controller for payment, fraud-prevention or regulatory purposes. The applicable entity, countries and roles depend on ICUK’s agreement and selected services. It is included for transparency rather than represented as a screening-record storage provider. Verify metadata, applicable privacy/DPA terms and transfer routes.

Reference: Stripe Privacy Center.

Microsoft 365 business email: Matt has confirmed that Microsoft 365 hosts sales@guardvett.com. It processes business enquiries, privacy requests, support correspondence, sender and recipient details, message contents, attachments and associated email metadata. Microsoft acts as a provider for ICUK's business correspondence; where messages include screening personal data handled on a customer's behalf, the relevant processing must also be covered by the customer DPA and subprocessor authorisation. This is separate from Azure Document Intelligence and from Resend's application email delivery.

Account-specific checks: confirm the Microsoft 365 contracting entity, tenant data location, retention and backup settings, support access and applicable transfer arrangements. Confirmation of the mailbox provider does not establish those settings.

Any separate support, accountancy, DNS and analytics services must also be inventoried. Their operators have not been established from the materials reviewed.

11 Changes and further information

Before publishing this register, ICUK will resolve the confirmation items, identify the effective version and align it with the customer DPA. A new or replacement screening-data subprocessor requires the notice and objection process in that DPA. Material changes to locations or processing must also be assessed under the agreed instructions and applicable law.

Customers may request information about supplier safeguards by emailing sales@guardvett.com. Requests will be answered subject to proportionate confidentiality and security protections. Supplier websites are evidence sources, not substitutes for ICUK’s own obligations or the terms accepted by a customer.