Sub-processor List
Version 2026-08-v3. Last updated 25 August 2026. Effective from 25 August 2026.
Some clauses below fill in with your own workspace details (your plan, your domain, the features you have switched on). On this public page there is no workspace to fill them in from, so they are shown as “to be completed”. Your own copy, filled in, is in your workspace under Settings, and you can download it as a PDF.
Sub-processors
Version 2026-08-v3. In force from 25 August 2026.
This page lists the third parties that Siege One Limited trading as OtisIO engages to process personal data on behalf of our customers. It forms Annex 3 to the Data Processing Agreement.
How we use this list. Under the Data Processing Agreement we give you at least 30 days' prior notice before we add a new sub-processor or replace an existing one, and you have 30 days to object on reasonable data protection grounds. The current list is always published at https://otisio.com/subprocessors.
What "sub-processor" means here. A sub-processor is a third party that processes personal data from your workspace on our instructions. A supplier we buy from that never touches your workspace data is not a sub-processor and is not in the tables below. Where such a supplier is nonetheless relevant to your assessment of us, it is disclosed separately in Section E.
Section A: Core sub-processors
These apply to every workspace, whatever features you use.
| Sub-processor | What they do | Where the data is processed | Transfer safeguard |
|---|---|---|---|
| Hetzner Online GmbH, a German company | Hosts the application servers and the databases. Your workspace database lives here. | Helsinki, Finland | Within the EEA, covered by the UK adequacy regulations. No additional safeguard needed. |
| Hetzner Online GmbH, Storage Box | Holds the off-site backup copy, encrypted by us before it leaves our server. | Falkenstein, Germany | Within the EEA, covered by the UK adequacy regulations. |
| Cloudflare, Inc. (United States, with EU and UK entities) | DNS only, plus the Turnstile bot check on our sign-in, sign-up and contact forms. Sees the visitor's IP address when a Turnstile challenge runs. Cloudflare does not proxy our traffic: the service is served directly from our own infrastructure, Cloudflare does not terminate TLS, and it is not a content delivery network or a web application firewall for this service. | DNS resolution and the Turnstile endpoint, on Cloudflare's global network. | UK International Data Transfer Addendum to the EU Standard Contractual Clauses, incorporated into Cloudflare's data processing addendum. |
| Stripe Payments Europe Limited (Ireland) and Stripe, Inc. (United States) | Processes subscription payments and stores payment method details. | Ireland, with support and fraud processing in the United States. | Standard Contractual Clauses with the UK Addendum. We do not send workforce personal data to Stripe. The only individual data that reaches Stripe is the billing contact and payment details. |
| Brevo (Sendinblue SAS, France) | Sends transactional email: invitations, password resets, notifications, alerts. Sees recipient name, email address and message content. | France (EEA). | Within the EEA, covered by the UK adequacy regulations. |
| OpenStreetMap Foundation (United Kingdom) | Serves the map background and the address search used when an administrator sets or edits a site, and when a manager opens a recorded location trail. Map tiles are requested directly by that person's browser, so the Foundation sees their IP address and the map area being viewed, which for a trail is the area a worker's recorded route covers. The address search (Nominatim) additionally receives the text typed into the address box. No worker record, and no coordinate we hold, is uploaded: the browser asks for pictures of map squares. | United Kingdom, with community-run mirrors. | The Foundation is established in the United Kingdom, so no transfer safeguard is required. Its tile and Nominatim services are used under their public usage policies. |
| Microsoft Corporation (Clarity) | Session replay and product analytics. This is switched on. It runs on our public marketing pages and inside the signed-in application. In the application every text node, image and input is masked in code before recording, so the recording carries the shape of a session (pages visited, clicks, scrolling and the masked layout) and not its content. The tag is not loaded at all on the facial recognition screens, the kiosk screens, the sign-in screen, the operator console, or on staging, and it is not loaded anywhere unless the Clarity project identifier is configured. On the marketing pages it additionally waits for the visitor to accept analytics cookies. | United States. | Standard Contractual Clauses with the UK Addendum. See the note below this table. |
| Google LLC (Analytics 4) | Analytics on our public marketing pages only, subject to consent, using Consent Mode. It does not load inside the signed-in application and it receives no workspace data. We are the controller for that processing rather than your processor, so it is deliberately absent from Annex 3 of the data processing agreement and is listed here because customers ask and because this page is the broader of the two documents. | United States. | Standard Contractual Clauses with the UK Addendum. |
Note on Microsoft Clarity. This is disclosed plainly because it is running, not as a capability that might be used one day. The masking is applied at source, so the content of a workspace is not transmitted, and the tag is fenced off the face, kiosk, sign-in, operator and staging surfaces by code that an automated security test checks on every change.
Two questions about it are open and are recorded here rather than hidden. Inside the signed-in application the tag does not wait for a cookie banner, so the PECR consent position for a signed-in employee needs to be settled. And behavioural recording of people at work is employee monitoring, whoever masks it, which is a matter your own privacy notice to your workers should cover. If you would rather it did not run for your workspace, tell us at privacy@otisio.com and we will exclude you.
Note on backups. Backups are taken in two ways and they are not the same thing. A plain compressed database dump is written daily to the production server's own disk and kept for 14 days; it is the fast restore path and it stays on that machine. Separately, twice a day, the databases and the uploaded file store are shipped to the Hetzner Storage Box using restic, which encrypts the data on our server before any of it leaves the machine. A weekly drill restores a real workspace from that off-site copy and verifies it.
In addition to those copies, a scheduled job mirrors the off-site repository daily to a machine in the United Kingdom with full disk encryption, under the sole control of a director of the company. Because it is a mirror of the repository rather than a separate copy, it is encrypted in the same way and it follows the same retention ladder: anything the off-site retention prunes is deleted locally at the next run. That copy is held by us, not by a third party, so it is not a sub-processor arrangement and there is no transfer outside the UK. It is mentioned here because customers ask where every copy of their data is, and the honest answer includes it.
Section B: Application distribution and push notifications
These apply if your workers use the mobile app, the desktop app, or browser notifications.
| Sub-processor | What they do | Where the data is processed | Transfer safeguard |
|---|---|---|---|
| 650 Industries, Inc. trading as Expo (United States) | Builds the mobile application, delivers over-the-air updates, and, where mobile push notifications are enabled, delivers those notifications. Receives the device push token and the notification content, being its title, body and link, which can include a worker's name, shift times and a message preview. Expo is the only notification party that receives the content in the clear. | United States. | Standard Contractual Clauses with the UK Addendum. |
| Apple Inc. (United States and Ireland) | Distributes the iOS application through the App Store and TestFlight. Delivers notifications to Apple devices: as the final carrier when Expo sends to an iPhone, and directly from our own servers for the live clock-in timer and the macOS desktop app. On delivery Apple sees the routing details, and for the live timer a structured status rather than free text. | United States and Ireland. | Standard Contractual Clauses with the UK Addendum. Apple sees who downloaded the app, under the individual's own Apple account, not under your workspace. |
| Google LLC (United States and Ireland) | Distributes the Android application through Google Play. Acts as the final carrier, through Firebase Cloud Messaging, when Expo delivers a notification to an Android device. Firebase Cloud Messaging is used only to carry the notification; no Firebase analytics, crash reporting or other Firebase service is used. | United States and Ireland. | Standard Contractual Clauses with the UK Addendum. As above. |
Browser notifications. Notifications shown in a web browser, in the staff web app and the operator console, are sent by our own server using the Web Push standard (VAPID). They travel through the push service run by the browser's maker: Google (Firebase Cloud Messaging) for Chrome and Edge, Mozilla for Firefox, and Apple for Safari. The content is encrypted with keys held only by the recipient's browser, so that service sees the destination, the timing and the size of a message, and never its content. This is why browser notifications carry a materially lower transfer risk than the mobile path.
Section C: Sub-processors used only if you switch the feature on
Each of these is engaged only where the relevant feature is enabled in your workspace. Where a feature is off, no data goes to the sub-processor.
| Sub-processor | Feature | What they receive | Where | Safeguard |
|---|
If no rows appear above, no optional sub-processor is engaged for
[to be completed: The customer's full workspace web address.].
The payroll and accounting integrations we support are Xero, QuickBooks Online, FreeAgent, Staffology by IRIS, Sage Business Cloud and BrightPay Connect. The row above names the one you have connected. Connecting none of them sends nothing to any of them.
The two artificial intelligence features, stated plainly. Automated receipt reading and the natural-language scheduling assistant both send data to Anthropic PBC in the United States, and both are on by default at the platform level, which means they are live for you as soon as the corresponding feature is available in your plan and switched on in your workspace. Neither sends anything when the feature is not in use. Nothing sent to Anthropic is used to train any model, ours or theirs. If you do not want either feature used in your workspace, tell us at privacy@otisio.com and we will disable it for you.
Map tiles are in Section A, not here. An earlier draft treated maps as a location or geofencing feature and then removed them altogether. Both were wrong. The map appears on the screen where any administrator adds or edits a site, which every workspace uses, so the OpenStreetMap Foundation is a core sub-processor and is listed in Section A. Turning location capture and geofencing off does not remove it; it only removes the location trail, which is the second place the same tiles are drawn.
Section D: Where we deliberately do not use a third party
These are stated because customers ask, and because the answer is a positive one.
| Function | Position |
|---|---|
| Facial recognition | No third-party facial recognition service is used at any point. Both face detection and the mathematical embedding run on the clock-in device. Detection uses a component supplied by Google (MediaPipe BlazeFace), and every byte of that runtime and model is served from our own origin rather than a content delivery network, so no image is sent to Google and Google is not contacted at all. Where a server-side embedding is needed it runs on our own host using the same model. No face image, and no face template, is sent to any external provider. |
| Artificial intelligence, and what it is not used for | We do send data to an AI provider, for the two named features in Section C, and nothing else. What we do not do: no data from your workspace is used to train any model, ours or a provider's; no AI is used to score, rank, rate or make a decision about a worker; no AI reads your chat messages, your HR documents or any file other than the expense receipt a claimant submits to be read; and no AI feature runs silently, because each one is the thing the person clicked. Only two AI integrations exist in the product and both are named in Section C. |
| File storage | Files you upload are stored on infrastructure we control and are served only through authenticated application routes. There is no public bucket and no public link, and no file is reachable without signing in and holding the right permission. |
| Error and crash reporting | No third-party error tracking service is connected. Errors are logged on our own infrastructure. |
| Advertising and profiling | No advertising network, no data broker, no profiling vendor. We do not sell data and we do not enrich it from third parties. |
| Location tracking outside clock events | No background location service, and no telematics provider. The mobile applications hold no background location permission. |
| Session replay on sensitive screens | The session replay tool described in Section A is never loaded on the facial recognition screens, the kiosk screens or the sign-in screen, and never on our staging environments. An automated security test asserts each of those exclusions on every change. |
Section E: Other suppliers, and integrations not currently engaged
Published because customers ask, and because a list that only shows the flattering answer is not worth reading. None of the following processes personal data from your workspace on our instructions.
E1. Suppliers with access to our systems, but not to your data
| Supplier | Position |
|---|---|
| GitHub, Inc. (United States, a Microsoft company) | Source control and the automated deployment pipeline. No customer personal data is stored in source control. GitHub is disclosed because the deployment pipeline has the ability to reach production, which is relevant to your assessment of us, but it is not a sub-processor and it receives none of your workspace data. |
E2. Processing where we are the controller, not your processor
| Supplier | Position |
|---|---|
| HubSpot | Our own sales and customer relationship management. Holds the business contact details of people who deal with us commercially. It holds no workforce data. We are the controller for that processing and our privacy policy covers it. |
| Google (Analytics) | Analytics on our public marketing pages only, subject to consent, and it does not load until a visitor accepts. It does not run inside the signed-in application. We are the controller for that processing. Also listed in Section A for visibility. |
| Companies House | Company name and number lookup at sign-up. Public register data, not personal data from your workspace. |
| GOV.UK bank holidays | A read-only public feed. Nothing leaves. |
E3. Built into the software but not currently engaged
None of these currently processes any customer personal data. If any is activated, it moves into Section A, B or C and you receive the notice period first.
| Integration | Status |
|---|---|
| Object storage (S3-compatible, including Cloudflare R2) | Supported by the application and selectable by configuration. Where it is not selected, uploaded files sit on the application server's own disk and are covered by the backup arrangements described in Section A. |
| Alternative email providers (Postmark, Resend, Amazon SES) | Configurable but not in use. Email goes through Brevo. |
| Sign in with Google, and Sign in with Apple, at sign-up and sign-in | Both are implemented, and each is offered only where its credentials are configured. Where a button is shown and a person chooses it, that provider sees the sign-in exchange and the email address. Nobody is required to use one: an email address and password always works. This is separate from a customer's own enterprise single sign-on, which is covered in Section C. |
Changes to this list
-
We will give you at least 30 days' prior notice of a new or replacement sub-processor, by email to your data protection contact and your billing contact, and by updating this page.
-
You may object on reasonable data protection grounds within 30 days of the notice. Tell us at privacy@otisio.com and set out your grounds.
-
If we cannot resolve the objection within 30 days, you may terminate the affected part of the service, or your agreement with us, without penalty and get a refund of fees paid in advance for the unused period.
-
Where a change is urgent and needed to keep the service secure or running, we may make it immediately and tell you straight away, with the objection right still applying afterwards.
-
We remain responsible to you for the acts and omissions of every sub-processor as if they were our own, and we impose data protection terms on each of them that are no less protective than those in our Data Processing Agreement with you.
Questions
Contact privacy@otisio.com, or legal@otisio.com for anything else.
Siege One Limited, company number 17110871, registered office 38 Angelica Avenue, Stotfold, Hitchin, England, SG5 4HH. Version 2026-08-v3, 25 August 2026.
Sub-processor List version 2026-08-v3, effective 25 August 2026. Generated on 13 September 2026. Source text SHA-256 129cbabb00612a6f.