Subprocessors
Every third party that processes visitor or client data on our behalf, what it does, and where it operates.
Effective /CWT Studio, Ontario, Canada
01Current subprocessors
We keep the vendor list short on purpose. Each provider below has a defined job, receives only the data that job requires, and is covered by a written agreement. Analytics providers receive nothing until a visitor turns analytics on in the cookie settings.
| Provider | Purpose | Data involved | Region |
|---|---|---|---|
| Website hosting and content delivery | Serves the website and its static assets | IP address, request headers, page requested | United States, global edge network |
| Managed application database and serverless functions | Stores intake submissions and runs the functions behind our forms | Name, work email, company, intake answers | United States |
| Transactional email delivery (Resend) | Delivers the roadmap summary, resource downloads and form notifications | Recipient email address, message content | United States |
| Scheduling (Calendly) | Runs the booking flow for the 30-minute intro | Name, email, answers you type into the booking form | United States |
| Headless content platform (Sanity) | Stores and serves blog content | No visitor personal data; published article content only | United States, global edge network |
| Google Analytics 4 | Aggregate traffic and conversion measurement, consent-gated | Pseudonymous identifier, page views, referrer, device and coarse region | United States |
| Microsoft Clarity | Aggregate usability measurement, consent-gated | Pseudonymous identifier, interaction events, page structure | United States |
02Client platforms
During an engagement we work inside platforms the client already owns and licenses, such as a CRM, a billing system or a reporting tool. Those platforms are the client's vendors, not ours. We access them under the client's direction and permissions, we do not copy data out of them except where the engagement requires it, and access is removed at the end of the engagement or on request.
03What we require of them
- A written agreement limiting processing to our documented instructions.
- Confidentiality obligations covering their personnel.
- Encryption of data in transit, and at rest where the provider stores it.
- Notification to us of a security incident affecting our data.
- Standard Contractual Clauses, or the UK Addendum where applicable, for transfers out of the EU, EEA, UK or Switzerland.
- Deletion or return of data at the end of the relationship.
Under PIPEDA we remain accountable for personal information we transfer to a provider for processing. Using a provider does not move that responsibility off us.
04Notice of changes
When we add or replace a provider that processes personal information, we update this page and change the effective date at the top. Clients under an active engagement receive notice by email before a new provider begins processing their data, and may object on reasonable data protection grounds.
05Questions
For a copy of the processing terms with a specific provider, or to raise an objection, write to shannon@thecwtstudio.com. Related reading: the privacy notice and the security overview.