What this page is
A sub-processor is a third party that Sizmic Limited engages to process personal data in connection with Kirak Studio. Under our Data Processing Addendum, customers give general authorisation for us to use the sub-processors listed here.
Notice of changes. We will give at least 30 days’ notice before adding or replacing a sub-processor that processes personal data inside customer backends, by updating this page and notifying subscribers.
To be notified of changes, email legal@kirak.io with the subject “Subscribe to sub-processor changes”.
If you have a reasonable data-protection objection to a new sub-processor, contact legal@kirak.io within the notice period — see DPA §7.3.
Section A — Platform sub-processors
Always involved in operating Kirak Studio.
| Provider | Purpose | Processing location(s) | Transfer safeguard (if outside UK/EEA) |
|---|---|---|---|
| Cloud / instance host — EU | Hosts the platform and customer Instances in EU regions; hosts Sizmic’s own platform data (accounts, billing DB, logs) | EU (region) | — (UK adequacy) |
| Cloud / instance host — US | Hosts customer Instances in US regions, where the customer selects a US region | US (region) | UK IDTA / EU SCCs + UK Addendum |
| Google LLC (Gemini API) | AI model provider for the AI Build Agent | US | UK IDTA / EU SCCs + UK Addendum |
| OpenAI, L.L.C. | AI model provider for the AI Build Agent | US | UK IDTA / EU SCCs + UK Addendum |
| Anthropic, PBC | AI model provider for the AI Build Agent | US | UK IDTA / EU SCCs + UK Addendum |
| Error / performance monitoring | Captures error traces and performance data from the platform (may incidentally include personal data in stack traces) | location | if applicable |
Section B — Module sub-processors
Involved only when a customer enables the relevant module and uses Sizmic-managed credentials (not when the customer brings their own provider keys / BYOK). The specific providers depend on the customer’s configuration.
| Module | Provider(s) | Purpose | Location(s) | Transfer safeguard |
|---|---|---|---|---|
| Payments | Stripe / Razorpay / Square | Process payments and webhooks for the customer’s application | location | if applicable |
| Email / SMS / push | SES / SendGrid / SMTP / SNS / Firebase | Deliver notifications the customer’s application sends | location | if applicable |
| Object storage | Amazon S3 / Wasabi | Store files the customer’s application uploads | location | if applicable |
| Cache / queue | Redis / RabbitMQ provider | Caching and background jobs for the customer’s application | location | if applicable |
(If a module is only ever used with customer-provided credentials, that provider is the customer’s own processor, not our sub-processor, and does not belong here.)
Section C — Service providers for Sizmic’s own data
These process personal data for which Sizmic is the controller — your account, billing, support, and marketing data — not data inside your backend. Listed here for transparency; the authoritative description is in our Privacy Policy §6.
| Provider | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Payment processor — Stripe | Processes card payments for Studio subscriptions; stores card details | US/EU | if applicable |
| Transactional email | Sends receipts, security, and service emails | location | if applicable |
| Marketing email / waitlist | Sends marketing and waitlist emails | location | if applicable |
| Support tool | Manages support requests | location | if applicable |
| Marketing site host | Hosts kirak.io | location | if applicable |
| Google (Analytics, Tag Manager) | Website analytics (consent-based) | US | UK IDTA / EU SCCs + UK Addendum |
| Microsoft (Clarity) | Website session analytics (consent-based) | US | UK IDTA / EU SCCs + UK Addendum |
Contact
Questions: legal@kirak.io