- Effective
- 2 August 2026
- Version
- 2.0.0
- Scope
- Customers using services involving the listed suppliers
On this page
Subprocessor & Third-Party Provider List
This list identifies core suppliers that may host, transmit or otherwise process data for one or more services. A provider is relevant only where the Client uses the corresponding function.
1. Core providers
| Provider | Purpose | Typical location | Relevant services |
|---|---|---|---|
| 20i Ltd | Web hosting, infrastructure and related platform services | United Kingdom and provider-designated regions | Websites, portals and hosted applications |
| Cloudflare, Inc. | DNS, content delivery, traffic security, proxy and performance services | Global network | Public websites, HostedTable and protected endpoints |
| Microsoft Corporation | Business email, identity and productivity services | UK, EEA and other Microsoft regions | Email delivery, administration and support |
| ClickSend / Sinch group | SMS transmission and delivery reporting | Provider network, potentially international | HostedTable and customer communications |
| Ubiquiti Inc. | Cloud network management, device telemetry and remote administration | Provider cloud regions, potentially United States | UniFi, managed network and guest Wi-Fi services |
| Xero | Accounting, invoicing and financial integration | Xero-designated regions | Billing and customer account administration |
| Stripe | Payment processing and fraud controls | Provider-designated regions | Services where Stripe payments are enabled |
| GoCardless | Direct Debit and payment processing | Provider-designated regions | Recurring billing and collection |
2. Provider roles
Some listed providers act as our subprocessors, some act as independent controllers, and some may contract directly with the Client or venue. The applicable role depends on the service configuration, payment flow and provider terms.
3. Changes
Providers may be added, replaced or removed for security, resilience, cost, capability or legal reasons. Material new subprocessors affecting Client Personal Data will be notified in accordance with the Data Processing Addendum.
4. International transfers
Where a provider receives a restricted transfer, we use an adequacy regulation or appropriate safeguards such as the UK IDTA or Addendum where required. A provider’s global network may process routing and security metadata in multiple countries.
5. Customer-specific suppliers
A Client may instruct us to integrate with its own supplier. Such a supplier is not automatically our subprocessor. The Client remains responsible for its contract, lawful basis and data-sharing arrangement unless the Order states otherwise.
Legal notices
Formal notices must be sent using the notice method stated in the applicable Order or through the authenticated customer portal. Where no method is stated, notices may be delivered to the registered office above. Operational support messages are not formal legal notices unless expressly identified as such.
Contracting entity: DM Digital UK Services Ltd, company number 17166861, registered office Hoults Yard, Mailing Exchange, Walker Road, Newcastle upon Tyne, NE5 2HL, United Kingdom.
