Sub-Processors

Last updated: 28 August 2026 · Version 1.2

Eatpol acts as a data processor on behalf of our clients (the data controllers). To deliver our services we rely on a small number of trusted third-party sub-processors. Each is bound by a data processing agreement (or equivalent contractual terms) and is permitted to process personal data only as needed to provide its service to us.

Our platform infrastructure is hosted entirely within the European Union — AWS Paris (eu-west-3) for storage, databases and application compute, and AWS Stockholm (eu-north-1) for video-analysis compute — with encryption in transit (TLS) and at rest by default.

The tables below list every sub-processor, separated by the surface each one serves. Not every platform sub-processor is engaged on every project: an engagement that recruits no participants through the Eatpol app engages neither Tremendous nor Firebase Cloud Messaging, and a computer-vision analysis engagement performed on client-supplied footage involves AWS alone unless the engagement documentation records otherwise. The applicable sub-processors for an individual engagement are confirmed in that documentation.

Platform and participant services

These may be engaged in delivering a client project or in operating the Eatpol research panel.

Sub-processorPurposeData processedLocationSafeguard
Amazon Web Services (AWS) Cloud infrastructure: compute, storage, database, content delivery All platform data (encrypted) EU (Paris, eu-west-3 and Stockholm, eu-north-1) AWS DPA + SCCs
Anthropic AI-assisted interviews and analysis of derived text Pseudonymized transcripts and summaries — direct identifiers removed, but the data remains personal data (see what this means) United States Anthropic Commercial Terms; no training on our data; no retention; SCCs
Tremendous Delivery of reward and incentive payments to research participants Participant name, email address and payment amount United States Provider DPA + SCCs
Google (Firebase Cloud Messaging) Push-notification delivery to the Eatpol participant mobile app Device push token and notification content EU / US Google DPA + SCCs
Google (reCAPTCHA) Bot protection on the participant enrolment and interview pages IP address and browser interaction signals EU / US Google DPA + SCCs
Google (Gemini API) Generating packaging-label design concepts in the Label Designer Client-supplied product briefs and packaging imagery. No participant personal data and no research footage EU / US Google DPA + SCCs

Public marketing website

These serve eatpol.com only and are never involved in client project data or participant data.

Sub-processorPurposeData processedLocationSafeguard
Netlify Marketing website hosting & form handling (incl. data-deletion requests) Contact details submitted via forms EU / US Netlify DPA + SCCs
Google Analytics Aggregate website analytics. The analytics tag loads on all pages; measurement and cookies are enabled only after consent IP address and browser data on page load; page-view events after consent EU Google DPA; IP anonymization enabled; measurement gated on cookie consent
Google (Fonts) Web font delivery on the marketing website IP address and browser data of website visitors EU / US Google DPA + SCCs
Microsoft Demo-call booking (Microsoft Bookings) on the marketing website Name, email address and booking details submitted by the visitor EU / US Microsoft Products and Services DPA + SCCs
Cloudflare Bot protection on the marketing-website forms (Turnstile) and delivery of common web libraries (cdnjs) IP address and browser signals of website visitors EU / US Cloudflare DPA + SCCs
jsDelivr Delivery of common web libraries on the marketing website IP address and browser data of website visitors EU / US Content delivery only; no personal data stored
Notification of changes. We will provide at least 30 days’ advance notice before adding or replacing a sub-processor, giving clients the opportunity to object. To receive change notifications, contact us at the address below.

International transfers

Where a sub-processor processes data outside the EU/EEA, the transfer is governed by the European Commission’s Standard Contractual Clauses (SCCs) together with supplementary technical measures (encryption in transit and at rest, data minimization and pseudonymization). The two transfers that carry participant personal data are Anthropic (United States), which receives pseudonymized transcripts and summaries and retains no data, and Tremendous (United States), which receives the name, email address and amount needed to pay a participant’s reward.

Research video and imagery are never sent to a third-party AI provider. All computer-vision analysis is performed by Eatpol’s own models running on Eatpol-controlled EU infrastructure.

What “pseudonymized” means

Under the GDPR these two terms are not interchangeable, and we use the one that describes what we actually do.

The interview transcripts and summaries we send to Anthropic are pseudonymized rather than anonymized, for two reasons. First, we still hold the information that links a transcript back to a participant — that is precisely what allows us to act on an access, correction or erasure request. Second, a research interview is a person speaking freely about their own life, so the text itself may contain details they chose to mention.

This is why the transfer is governed by Standard Contractual Clauses. If the data were genuinely anonymous, the GDPR would not apply to it and those safeguards would not be needed. Calling it pseudonymized is both the more accurate description and the one that commits us to the higher standard: the transcripts are treated as personal data at every stage, the provider trains no models on them and retains nothing.

Changes in this version

Version 1.2 (28 August 2026) adds Tremendous, Google (Firebase Cloud Messaging), Google (reCAPTCHA) and the Google (Gemini API) to the platform table. These services were already in use when version 1.1 was published; they are newly disclosed here, not newly engaged. The Anthropic entry now states that the transcripts transferred are pseudonymized rather than anonymized — direct identifiers are removed, but the data remains personal data, which is why the transfer is governed by the SCCs described above.

Contact

Questions about our sub-processors or data protection practices? Contact our Data Protection Officer: mtufano@eatpol.com. See also our Privacy Policy.