closrr

Sub-Processors

Last updated: February 23, 2026

Under the UK GDPR and the Data Protection Act 2018, we are transparent about the third-party data processors ("sub-processors") we engage to deliver our services. Each sub-processor is bound by a Data Processing Agreement (DPA) that requires them to protect your data to the same standard we uphold.

Where data is transferred outside the United Kingdom, we ensure appropriate safeguards are in place through UK International Data Transfer Agreements (UK IDTAs) or transfers to countries with UK adequacy status.

Sub-ProcessorPurposeData ProcessedLocation
Amazon Web Services (AWS)Cloud infrastructure and hostingAll platform data (encrypted)EU (Ireland / Frankfurt)
StripePayment processingBilling and payment card informationUnited States (UK IDTA in place)
OpenAIAI model provider for coaching and scoringPractice session transcripts, anonymised performance dataUnited States (UK IDTA in place)
Google Cloud (Gemini)AI model provider for coaching and analysisPractice session transcripts, anonymised performance dataUnited States (UK IDTA in place)
ElevenLabsText-to-speech voice synthesisAI-generated text for voice output (no personal data)United States (UK IDTA in place)
PostHogProduct analyticsAnonymised usage events, device metadataEU (Frankfurt)
ResendTransactional email deliveryEmail address, nameUnited States (UK IDTA in place)
SentryError monitoring and performanceError logs, anonymised session dataUnited States (UK IDTA in place)

Changes to Sub-Processors

We will notify customers of any new sub-processors or material changes to existing sub-processors at least 30 days before the change takes effect. If you have concerns about a new sub-processor, you may object by contacting us at privacy@closrr.io.

Questions

For questions about our sub-processors or data processing arrangements, contact our Data Protection Officer at privacy@closrr.io.