Platform documentation

Subprocessors and integrations

Last updated: 20 July 2026.

Elevale (operated by Saint Financial Group Limited) uses trusted subprocessors to deliver the platform. The platform infrastructure is operated by Saint Financial Group Limited (Elevale). We provide at least 30 days notice before adding subprocessors that process personal data, where required by our Data Processing Agreement.

Platform subprocessors

Core infrastructure and optional AI providers that process personal data on our instructions
Subprocessor Purpose Data processed Location
Supabase Database, authentication, file storage Account data, workspace content, sessions EU / US
Fly.io Application hosting Request logs, application data in transit EU / US
Stripe Payment processing Billing contacts, payment method metadata, subscription and wallet transactions EU / US
AWS SES Transactional email Email addresses, notification content EU / US
Cloudflare Marketing website delivery, CDN, and security IP addresses, request metadata Global
CRM & marketing automation provider Newsletter, enquiry, and marketing contact management Name, business name, email, phone, marketing engagement EU / US
OpenAI AI chat, embeddings, insights (when enabled) Prompts and workspace context you submit to AI features US
Anthropic AI chat and analysis (when enabled) Prompts and workspace context you submit to AI features US
Google (Gemini) AI chat and embeddings (when enabled) Prompts and workspace context you submit to AI features US / EU
Perplexity Live web research in AI features (when enabled) Search queries and context you submit US
ElevenLabs Voice mode and TTS (when enabled) Audio, transcripts, voice session data US / EU

AI subprocessors are invoked only when you or your workspace use AI features. Usage is metered via the prepaid AI wallet (USD). We configure API usage to minimise training on your content where provider terms allow.

Marketing, analytics, and advertising (marketing website)

On our marketing website, with your consent where required, we use analytics and advertising technologies. These providers act as independent or joint controllers under their own privacy policies:

Marketing site technologies (consent required where applicable)
Provider Purpose
Google Analytics Website traffic and usage measurement
Google Ads Ad delivery, measurement, and retargeting
Meta (Facebook/Instagram) Ads Ad delivery, measurement, and retargeting
LinkedIn Ads Ad delivery, measurement, and retargeting to business audiences

You can manage analytics and advertising cookies via our cookie banner. See our Cookie Policy.

Customer-connected integrations

When you connect third-party services via OAuth or API keys, data flows to those providers under your account and their privacy policies. You control which integrations are enabled per workspace. Examples include:

  • Google Analytics / Google Ads: advertising and web analytics metrics
  • Meta (Facebook / Instagram): social advertising metrics
  • Xero: accounting data
  • Other integrations as listed in workspace settings

These providers are not Elevale subprocessors for data you choose to connect; you act as controller of that integration data.

International transfers

Where personal data is transferred outside the UK or EEA, we use Standard Contractual Clauses, the UK International Data Transfer Agreement, and supplementary measures where required. See our Data Processing Agreement.

Changes to subprocessors

We will update this page when subprocessors change. Material additions that process personal data will be notified in accordance with our DPA. Contact contact form for enterprise subprocessor notifications.

Related documents

Contact: contact form