GrailAtlasAn independent reference for mechanical watches

Sub-processors

Under GDPR Art. 28 we maintain a list of every third-party processor that touches data on Grail Atlas’s behalf. This page is the canonical record. It’s updated in the same change-set as any processor change — adding, removing, or scope-shifting — and the git history is the canonical timeline.

State badges. ACTIVE means the processor is receiving data from live traffic right now. CONFIGURED · NOT TRANSMITTING means credentials or SDK exist but no code path sends data today. FUTURE means planned for a feature that hasn’t shipped. The list is honest about each state so a reader can see what’s actually happening vs. what’s scaffolded.

Active today (7)

Vercel, Supabase, and Upstash are involved on every page load. Cloudflare handles DNS for every domain lookup. Resend handles outbound email. Voyage AI receives query text when you use natural language search. Anthropic receives editorial prompts from the blog-draft cron job (not from visitor traffic).

Configured but not transmitting (2)

Wired into the codebase or env but currently inert. Listed so the picture is honest: these names appear inpackage.json or .env.example but no line of executing code sends them data today. Each one moves to ACTIVE the day the wiring lands, with the privacy policy + ROPA updated in the same commit.

Future (2)

Planned for known features. Listed so the road-map is visible rather than emerging as a surprise.

Notable absences

Things the audience may reasonably wonder about that are not currently in use:

How we notify of changes

For an existing user account, a material change to this list (a new processor, a meaningful scope change, or a removal) is announced in the next available newsletter and recorded in the public changelog. The page itself is git-versioned; the commit history is the canonical timeline.

Standard Contractual Clauses

For every US-located sub-processor that handles EU personal data we rely on the European Commission’s Standard Contractual Clauses (SCCs) as the transfer mechanism. Transfer Impact Assessments per processor are still pending — that’s a counsel-driven workstream that will open alongside the broader legal engagement.

← Privacy Policy · Cookie Policy · Affiliate disclosure

Sub-processors | Grail Atlas