Back to home

Sub-Processor List

Third-party data processors we engage

Version 1.0 | Effective: January 2026

Document Format Options

You are viewing the interactive web version of this document. For a traditional legal document format suitable for records, printing, or legal review, use the options below.

Currently viewing: Interactive Format

1. Introduction

This document lists the sub-processors engaged by RUNO Legal Technology Limited ("RUNO") to process personal data on behalf of our customers. This list is maintained pursuant to our obligations under GDPR Article 28 and our Data Processing Agreements with customers.

2. Sub-Processor Change Notification

2.1 Notification Process

  • Customers are notified 30 days in advance of any new sub-processor engagement
  • Notifications are sent via email to the designated contact
  • Customers may object within 14 days of notification
  • This list is updated upon any changes

2.2 Subscribe to Updates

To receive sub-processor change notifications:

  • Email: compliance@runo.legal
  • Subject: "Sub-processor notification subscription"
  • Include: Company name, contact email, contract reference

3. Current Sub-Processors

3.1 Infrastructure & Hosting

Sub-ProcessorServiceData ProcessedLocationSafeguards
Railway Inc.Cloud hosting platformAll customer dataUSA / EUSCCs, SOC 2 Type II
Amazon Web ServicesCloud infrastructure (backup)Customer data (if selected)EU (Ireland, Frankfurt)Adequacy, SOC 2
Cloudflare Inc.CDN, DDoS protection, WAFIP addresses, request metadataGlobalSCCs, ISO 27001

3.2 Database & Storage

Sub-ProcessorServiceData ProcessedLocationSafeguards
PostgreSQL (Railway)Database hostingAll application dataEURailway DPA applies
Redis LabsCaching, session storageSession data, cacheEUSCCs, SOC 2

3.3 AI & Machine Learning

Sub-ProcessorServiceData ProcessedLocationSafeguards
AnthropicAI/LLM services (Claude API)Document content, promptsUSASCCs, DPA, no training
OpenAI (optional)AI services (alternative)Document content if selectedUSASCCs, DPA, no training

AI Data Handling Note:

  • • AI providers do not train their models on customer data
  • • Data is processed only for the requested operation
  • • No persistent storage of customer content by AI providers
  • • Audit logging maintained for all AI interactions

3.4 Email & Communications

Sub-ProcessorServiceData ProcessedLocationSafeguards
Twilio SendGridTransactional emailEmail addresses, contentUSASCCs, SOC 2 Type II
TwilioSMS notifications (optional)Phone numbers, SMS contentUSASCCs, SOC 2 Type II

3.5 Payment Processing

Sub-ProcessorServiceData ProcessedLocationSafeguards
StripePayment processingPayment card details, billingUSA / EUSCCs, PCI DSS Level 1

Note: RUNO does not store payment card details. All payment data is processed directly by Stripe.

3.6 Monitoring & Security

Sub-ProcessorServiceData ProcessedLocationSafeguards
Sentry (optional)Error trackingError logs, limited contextUSASCCs, SOC 2
CloudflareWAF, DDoS protectionRequest metadata, IPsGlobalSCCs, ISO 27001

4. Key Sub-Processor Details

Railway Inc.

  • Service: Primary cloud hosting platform
  • Website: railway.app
  • Certifications: SOC 2 Type II
  • Data Location: USA and EU regions available

Anthropic

  • Service: AI language model (Claude API)
  • Website: anthropic.com
  • Data Handling: No training on customer data
  • Certifications: SOC 2 Type II

Twilio SendGrid

  • Service: Transactional email delivery
  • Website: sendgrid.com
  • Certifications: SOC 2 Type II, ISO 27001
  • Data Location: United States

Stripe

  • Service: Payment processing
  • Website: stripe.com
  • Certifications: PCI DSS Level 1, SOC 2 Type II
  • Data Location: USA / EU

5. Data Transfer Safeguards

5.1 Transfers to USA

For sub-processors located in the USA:

  • • Standard Contractual Clauses (SCCs)
  • • Encryption in transit and at rest
  • • Pseudonymisation where possible
  • • Transfer Impact Assessments

5.2 Within EU/EEA

Transfers within the EU/EEA are permitted without additional safeguards under GDPR adequacy provisions.

5.3 UK Transfers

Post-Brexit, UK transfers are governed by:

  • • UK-EU adequacy decision
  • • UK addendum to SCCs

7. Objection Process

7.1 Right to Object

Customers may object to new sub-processors within 14 days of notification.

7.2 Objection Procedure

  1. Submit written objection to compliance@runo.legal
  2. Include specific concerns and reasons
  3. RUNO will attempt to address concerns
  4. If unresolved, customer may terminate affected services

7.3 Resolution

RUNO will:

  • • Discuss concerns with customer
  • • Explore alternative solutions
  • • Provide additional safeguards if possible
  • • Allow termination without penalty if objection cannot be resolved

10. Certification Availability

The following certifications are available upon request (under NDA):

Sub-ProcessorAvailable Certifications
RailwaySOC 2 Type II
AnthropicSOC 2 Type II
CloudflareISO 27001, SOC 2 Type II
SendGridSOC 2 Type II, ISO 27001
StripePCI DSS Level 1, SOC 2 Type II

To request certification copies, contact compliance@runo.legal.

8. Version History

VersionDateChanges
1.0January 2026Initial release

9. Contact Information

Sub-Processor Inquiries

compliance@runo.legal

Data Protection Officer

dpo@runo.legal

Subscribe to Updates

Email compliance@runo.legal with subject "Sub-processor subscription"

This sub-processor list is accurate as of the date indicated. Customers will be notified of changes in accordance with their Data Processing Agreement.

Related Documentation