1. Subprocessor Engagement Policy
EntireFM enforces rigorous vendor due diligence before engaging any third-party technology provider. Subprocessors must demonstrate robust technical security controls, UK GDPR compliance, and undergo regular security reviews.
2. Live Audited Subprocessor Register
The following organisations are currently authorised to process data on behalf of EntireFM:
- Vercel Inc. (Infrastructure & Cloud): Edge website hosting, static asset delivery, and serverless edge compute infrastructure. [Primary Hosting: UK / EU / Global Edge POPs | Safeguard: UK Addendum to EU Standard Contractual Clauses (SCCs) & Data Processing Addendum]
- Supabase Inc. / AWS London (eu-west-2) (Database & Storage): Relational database persistence, CAFM asset records, work order dispatch, and encrypted document vault. [Primary Hosting: London, United Kingdom (AWS eu-west-2) | Safeguard: UK Addendum to EU SCCs & Supabase Enterprise Data Processing Agreement]
- Resend Inc. (Communications & Email): Transactional service emails, work order notifications, client survey confirmations, and newsletter distribution. [Primary Hosting: EU (Frankfurt / Ireland) | Safeguard: UK Addendum to EU SCCs & Data Processing Agreement]
- Google LLC (Google Analytics 4) (Security & Telemetry): Aggregated website traffic analysis and user journey telemetry (strictly conditional upon explicit user cookie consent). [Primary Hosting: European Union / United States | Safeguard: UK Extension to EU-US Data Privacy Framework / Standard Contractual Clauses]
| Subprocessor | Category | Purpose | Location | UK Transfer Basis |
|---|---|---|---|---|
| Vercel Inc. | Infrastructure & Cloud | Edge website hosting, static asset delivery, and serverless edge compute infrastructure. | UK / EU / Global Edge POPs | UK Addendum to EU Standard Contractual Clauses (SCCs) & Data Processing Addendum |
| Supabase Inc. / AWS London (eu-west-2) | Database & Storage | Relational database persistence, CAFM asset records, work order dispatch, and encrypted document vault. | London, United Kingdom (AWS eu-west-2) | UK Addendum to EU SCCs & Supabase Enterprise Data Processing Agreement |
| Resend Inc. | Communications & Email | Transactional service emails, work order notifications, client survey confirmations, and newsletter distribution. | EU (Frankfurt / Ireland) | UK Addendum to EU SCCs & Data Processing Agreement |
| Google LLC (Google Analytics 4) | Security & Telemetry | Aggregated website traffic analysis and user journey telemetry (strictly conditional upon explicit user cookie consent). | European Union / United States | UK Extension to EU-US Data Privacy Framework / Standard Contractual Clauses |
3. Notification of Subprocessor Changes
EntireFM shall provide contracted clients with at least 30 days’ advance written notice before onboarding any new subprocessor. Clients have the right to object on legitimate data protection grounds.
Authorised by: EntireFM Legal, Risk & Compliance Committee
Operating Company: EntireFM (trading name of Alkota Group Limited). Registered in England and Wales (Company No. 13535215).
This policy is formally reviewed annually and immediately following any statutory or operational changes.
Data Protection & Legal Governance Inquiries
For statutory requests, data protection questions, contract notices, or governance inquiries, please contact our designated compliance team.
Related Governance Policies
View Legal CentrePrivacy Notice
Comprehensive UK GDPR, DPA 2018, and PECR privacy notice explaining how EntireFM collects, uses, protects, and respects personal information across all FM services, B2B marketing, and digital platforms.
Data Processing Agreement (UK GDPR Art 28)
Statutory Data Processing Agreement (DPA) incorporating UK GDPR Article 28 terms where EntireFM processes building occupant and client personal data on behalf of commercial property clients.
Information Security & Trust Overview
High-level security overview covering database encryption, role-based access controls, tenant isolation, automated backups, and vulnerability management.
Data Protection & Governance Framework
Internal governance standards, accountability measures, data classification, breach management protocols, and technical controls enforced across EntireFM operations.


