Legal
Sub-processor List
Last updated: 30 June 2026
1. Purpose
This Sub-processor List explains the third-party providers that may process personal data in connection with SyftOS, together with customer-enabled integrations that may receive or return data when configured by a customer.
SyftOS is operated by Techshift Digital Ltd, company number 15218025, registered office 1 The Briars, Waterberry Drive, Waterlooville, England, PO7 7YH.
This document supports the SyftOS Data Processing Agreement and Privacy Notice. It is intended to help customers understand where personal data may be processed when using SyftOS.
2. Sub-processors vs customer-enabled integrations
Not every third-party system connected to SyftOS is a SyftOS sub-processor.
- Core sub-processors are third-party providers engaged by Techshift Digital Ltd to help provide, operate, secure, monitor, bill for or support SyftOS.
- Customer-enabled integration providers are third-party services that a customer chooses to connect to SyftOS, such as Slack, Google Workspace, Microsoft 365, GitHub, Jira, HubSpot, Stripe, Xero or Teamwork.
- Where a customer connects an integration, the customer is responsible for ensuring it has authority to connect that service and to send, receive, read, write or process data through it.
- Customer-enabled integration providers may process data under their own terms, contracts, privacy notices and security arrangements with the customer.
Stripe appears in both categories intentionally: it is a core sub-processor for SyftOS’s own subscription billing, and it may separately be a customer-enabled integration where a customer connects its own Stripe account to a workflow. The two roles are distinct.
3. Core sub-processors
SyftOS’s core application, database, cache and file storage are hosted in the United Kingdom. Some operational providers (AI model providers, monitoring and the website CDN) process data outside the UK, primarily in the United States; those transfers are covered by appropriate safeguards as described in section 5.
| Provider | Purpose | Data processed | Location & transfer safeguard |
|---|---|---|---|
| Laravel Cloud (Laravel Holdings, Inc.) | Application hosting and compute, managed MySQL database, Redis cache/queues, and realtime messaging. | Account, workspace, workflow, integration metadata, audit records, logs and operational data. | Hosted in the UK (London). Operator is US-based; covered by the provider’s data processing terms (UK Addendum to the EU SCCs). |
| Amazon Web Services (Amazon Web Services EMEA SARL) | Object storage of uploaded documents and files (stored per-tenant). | Uploaded documents, workspace files and related metadata. | Stored in the UK (London region), under the AWS data processing terms (UK Addendum to the EU SCCs where applicable). |
| Anthropic, PBC | Default AI model provider — processing prompts, workflow context and content to generate AI outputs where AI features are used. | Prompts, workflow inputs, selected connected data, document excerpts, outputs and metadata needed to provide AI functionality. | United States, under Anthropic’s data processing terms (UK Addendum to the EU SCCs). Processed under Anthropic’s standard API terms, which do not use API data to train its models. |
| OpenAI, L.L.C. (OpenAI Ireland Ltd for UK/EEA contracting) | AI model provider for optional models, embeddings (retrieval), web search and voice (speech-to-text / text-to-speech) where enabled. | Prompts, workflow inputs, document excerpts, outputs and metadata needed to provide the relevant AI functionality. | United States, under OpenAI’s data processing terms (UK Addendum to the EU SCCs). Processed under OpenAI’s standard API terms, which do not use API data to train its models. |
| Stripe (Stripe Payments UK Ltd) | Subscription billing, payments, invoices, payment methods and checkout. Card details are handled entirely by Stripe and are not stored by SyftOS. | Billing contact details, payment metadata, subscription information, transaction and invoice data. | UK / US, under the Stripe data processing terms (UK Addendum to the EU SCCs). Stripe also acts as an independent controller for certain payment-processing activities. |
| Postmark (ActiveCampaign, LLC) | Transactional email — account emails, invitations, notifications, password resets and service messages. | Email addresses, names, workspace identifiers and the content of service emails. | United States, under Postmark’s standard data processing terms (UK Addendum to the EU SCCs). |
| Laravel Nightwatch (Laravel Holdings, Inc.) | Application performance and error monitoring, incident investigation and reliability. | System logs, error traces, request metadata, and user and workspace identifiers. | United States, under the provider’s data processing terms (UK Addendum to the EU SCCs). |
| Cloudflare, Inc. | DNS, content delivery, edge security and hosting for the SyftOS marketing website (syftos.com) and its contact form. | IP addresses, request metadata and security events of website visitors. | Global edge / US, under the Cloudflare data processing terms (UK Addendum to the EU SCCs). |
| Google (Google Ireland Limited) | Website analytics (Google Analytics 4, loaded only with consent) and contact-form email delivery (Gmail API) for the SyftOS marketing website. | Website-visitor analytics data (with consent) and enquiry contact details submitted through the contact form. | EU / US, under Google’s data processing terms (UK Addendum to the EU SCCs). |
| Bunny Fonts (BunnyWay d.o.o.) | Web font delivery for the SyftOS application interface. | The IP address of the user’s browser when fonts are requested. No cookies are set. | European Economic Area (Slovenia); UK adequacy applies. |
A documentation-hosting provider (for docs.syftos.com) and a status-page provider (for status.syftos.com) are not yet engaged. They will be added to this list when selected. Customer support is currently handled by email rather than a separate helpdesk product.
4. Customer-enabled integration providers
SyftOS may connect to third-party services at the customer’s direction. These integrations are enabled, authorised or configured by the customer or an authorised user. The exact data processed depends on the integration, the permissions granted, the workflows configured and the actions approved by the customer.
| Integration provider | Typical use in SyftOS | Data that may be accessed or processed |
|---|---|---|
| Slack | Communications, approvals, workflow notifications, message reading or posting where configured. | Slack messages, channel data, user identifiers, workspace metadata and workflow outputs. |
| Google Workspace / Gmail | Email reading, drafting and sending where approved; Drive/Sheets access and document workflows where configured. | Emails, attachments, files, spreadsheet data, user identifiers and metadata selected or authorised by the customer. |
| Microsoft 365 / Outlook | Email, calendar or Microsoft workspace workflows where configured. | Emails, calendar data, attachments, user identifiers and metadata selected or authorised by the customer. |
| GitHub | Repository, issue, pull request, code governance and approval workflows. | Repository metadata, pull request data, issue data, commit metadata, comments and governance attestations. |
| Atlassian Jira | Issue, project, task, workflow and reporting integrations. | Issue data, project data, comments, user identifiers, workflow outputs and metadata. |
| Teamwork | Project management, task, time, reporting or operational workflow integrations. | Project data, task data, comments, user identifiers, time/reporting data and metadata. |
| HubSpot | CRM, contact, company, deal, pipeline and sales workflow integrations. | CRM records, contact details, company details, deal records, activity data and metadata. |
| Stripe | Billing, customer, subscription, payment and finance-related workflows where configured. | Customer billing records, subscription metadata, invoice data, transaction metadata and related finance data. |
| Xero | Accounting, invoicing, finance review or finance workflow integrations where configured. | Contacts, invoices, accounts data, transaction metadata and related finance information. |
5. AI model processing and international transfers
SyftOS may use third-party AI model providers to generate, analyse, summarise, classify, draft, reason over or transform data as part of digital worker, workflow, department or assistant functionality.
The data sent to an AI model provider depends on the feature used, the workflow configuration, the connected integrations, the customer’s permissions and the amount of context required to perform the task. SyftOS sends only the data reasonably required for the relevant workflow or agent run. Customers should avoid using SyftOS for sensitive, high-risk or regulated processing unless this has been assessed and agreed appropriately.
Techshift Digital Ltd does not use customer workspace content to train Techshift-owned models. The AI model providers process data under their standard API terms, which do not use data submitted through their APIs to train their models. Where a provider offers it, SyftOS can be configured to request zero data retention for a tenant.
Where personal data is processed outside the United Kingdom, Techshift Digital Ltd relies on appropriate transfer safeguards, such as the UK International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum, as set out in the provider’s data processing terms.
6. Changes to this list
Techshift Digital Ltd may update this Sub-processor List as SyftOS evolves, as providers change, or as integrations are added or removed.
In accordance with the SyftOS Data Processing Agreement, Techshift Digital Ltd will give at least 30 days’ advance notice before adding or replacing a sub-processor that processes Customer Data, and will give customers the opportunity to object on reasonable data protection grounds, except where an urgent change is required for security, legal or service-continuity reasons.
Customers are responsible for reviewing updates to this list and ensuring that their use of SyftOS remains suitable for their own compliance, security and procurement requirements.
7. Customer responsibilities
Customers are responsible for:
- ensuring they have permission to connect third-party systems to SyftOS;
- configuring integration permissions appropriately;
- reviewing and approving proposed actions before execution where approval is required;
- ensuring their own contracts and privacy notices cover the systems they connect;
- avoiding unnecessary disclosure of sensitive or high-risk data;
- checking whether specific integrations, providers or data transfers are suitable for their organisation.
8. Contact
Questions about this Sub-processor List can be sent to privacy@syftos.com (interim fallback: mathew@techshift.digital).
9. Legal entity details
| Item | Details |
|---|---|
| Product | SyftOS |
| Operator | Techshift Digital Ltd |
| Company number | 15218025 |
| Registered office | 1 The Briars, Waterberry Drive, Waterlooville, England, PO7 7YH |
| Registered in | England and Wales |
| Website | https://syftos.com |