Sub-Processors

Last updated: 17 August 2026

This page lists the third-party sub-processors that may process personal data on behalf of Surging Markets Ltd as part of delivering the SurgingMarkets / Market Makers Method platform. We maintain Data Processing Agreements (DPAs) with each sub-processor in line with Article 28 GDPR / UK GDPR. We will provide at least 30 days' notice via this page before adding or replacing a sub-processor that processes personal data of EU/UK data subjects.

Current Sub-Processor List

Vendor Purpose Data Categories Region DPA
Stripe, Inc.Payment processing, subscription billing, fraud signalsEmail, name, billing address, last-4 of card, IP, purchase historyUSA (SCCs)Auto-accepted via Stripe ToS + standalone DPA at stripe.com/legal/dpa
Mailgun (Sinch)Transactional email — password reset, receipts, alertsEmail, name, message contentEU region selectableSigned at mailgun.com/dpa
SendGrid (Twilio)Backup transactional emailEmail, name, message contentUSA (SCCs)Under Twilio MSA
Pusher Ltd. (MessageBird)Real-time chat, dashboard ticks, signal broadcastingUser ID, nickname, channel name, message payloadUK (SCCs)Signed at pusher.com/legal/dpa
SentryError tracking, crash reportsUser ID/email (if attached), IP, stack traces, breadcrumbsUSA (SCCs); EU region availableSigned at sentry.io/legal/dpa
VultrVPS / server hosting — full data layerAll application data (controller of physical storage)USA & EU regionsSigned at vultr.com/legal/dpa
CloudflareCDN, DNS, DDoS mitigation (where active)IP, request metadataGlobal (SCCs)cloudflare.com/cloudflare-customer-dpa
Google reCAPTCHABot mitigation on signup & loginIP, browser fingerprint, behaviour signalsUSA (SCCs via Google)Google ToS / Google Cloud DPA (Enterprise tier)
Meta Platforms (Facebook Pixel)Conversion tracking, retargeting (consent-gated)IP, browser fingerprint, hashed email (CAPI), conversion eventsUSA (SCCs)Meta Business Tools Controller Addendum + Custom Audiences Terms — joint controller arrangement applies
Google Tag Manager / GA4 / Google AdsTag deployment + anonymised analytics (consent-gated)IP, page events, conversion eventsUSA (SCCs via Google)Google Ads / GA4 DPA
Plausible AnalyticsCookieless aggregate analyticsHashed visitor ID derived from IP+UAEU (Germany)plausible.io/dpa
TwelveDataMarket price feed (symbols only)None — symbol-level outbound only, no PIIUSAN/A — non-processor for personal data
FinnhubSymbol import (legacy)None — symbol-level onlyUSAN/A — non-processor
Financial Modeling Prep (FMP)Market data fallbackNone — symbol-level onlyUSAN/A — non-processor
Anthropic / OpenAIAI content generation (admin tools and Surge AI assistant)Prompt content — admin-side primarily; minimised user PIIUSA (SCCs)anthropic.com/legal/dpa, openai.com/policies/data-processing-addendum
ViloudVideo streaming for PPV contentViewer IP, playback eventsUSAviloud.tv terms — DPA in review
Apple App Store (at iOS launch)Distribution, optional IAP receipt validationReceipt data, Apple-resolved identifiersGlobalApple Developer Agreement
Affiliate networks (Impact / PartnerStack / MintBird)Referral attribution & conversion trackingclickId, conversion eventsVaries per networkNetwork-dependent — verified per partner

EU / UK Data Transfers

Where personal data is transferred outside the EEA / UK to a country without an adequacy decision, transfers rely on the European Commission's Standard Contractual Clauses (2021 modules) embedded in each sub-processor's DPA. EU data residency is selected wherever available (Mailgun EU region, Sentry EU, Plausible EU, Vultr EU regions).

Notifications of Change

Material changes to this sub-processor list will be posted here. Customers with active DPAs in place may object to a new sub-processor within 30 days of the change being posted by emailing [email protected].

Contact

For DPA copies, sub-processor questions, or Article 28 documentation: [email protected].

← Back to Privacy Policy  ·  Open source notices