1.Purpose of this page
- 1.1Clause 7 of the data processing agreement gives CEDX general authorisation to engage sub-processors. This page is the list that authorisation refers to, and it forms part of that agreement.
- 1.2A sub-processor is listed here if it may process personal data contained in customer data, whether or not it does so in practice for a given customer. A supplier that never touches customer data (an office cleaning contractor, for example) is not listed.
- 1.3The list distinguishes between sub-processors engaged for every customer and those engaged only where a particular product or option is subscribed for. A customer that does not subscribe to a product is not subject to the sub-processors listed against it.
- 1.4Where a sub-processor holds only encrypted data and has no ability to decrypt it, that is stated explicitly. Such a party is still listed, because we do not think the distinction should be ours to make quietly.
- 1.5The version number of this page changes whenever an entry is added, removed or materially amended. The change history is in clause 8.
2.Infrastructure sub-processors
These parties provide the compute, storage and network capacity on which the platform runs. They are engaged for every customer. Data held with them is encrypted at rest with keys that they do not hold.
| Sub-processor | Purpose | Location of processing | Categories of personal data |
|---|---|---|---|
| Meridian Cloud Services Ltd | Primary compute, object storage and managed database capacity for all eleven regions. | Region selected by the customer. Company established in the United Kingdom. | All categories present in customer data, held encrypted. Keys are held by CEDX; Meridian cannot decrypt. |
| Meridian Cloud Key Services Ltd | Hardware security modules holding encryption keys and customer-managed key material. | Same region as the customer's tenant. | Key material only. No customer records. |
| Cormorant Networks BV | Content delivery, edge termination and denial-of-service mitigation. | Global edge; termination in the customer's region. Company established in the Netherlands. | Network metadata, IP addresses and request headers. No stored records. |
| Ferrous Systems GmbH | Encrypted offsite backup custody and restoration testing. | Within the customer's region. Company established in Germany. | All categories present in customer data, held encrypted. Ferrous cannot decrypt. |
3.Platform sub-processors
These parties support functions common to every application on the platform, authentication, observability, communications and support. They are engaged for every customer.
| Sub-processor | Purpose | Location of processing | Categories of personal data |
|---|---|---|---|
| Halyard Observability Inc. | Aggregation of platform telemetry, error traces and performance metrics. | Ireland and the United States. Transfers under the Standard Contractual Clauses. | User and tenant identifiers, IP addresses, request paths. Record contents are redacted before transmission. |
| Sable Messaging Ltd | Transactional email: notifications, alerts, password resets and invoices. | United Kingdom and Ireland. | Name, email address, and the content of the message being sent. |
| Corvid Telecom SA | Delivery of one-time codes by SMS and voice, where a customer enables it. | Switzerland, with regional carrier routing. | Telephone number and the one-time code. Retained for 72 hours. |
| Lantern Support Systems Ltd | The support ticketing platform used by CEDX support and managed operations teams. | United Kingdom, Germany and Singapore. | Contact details of the requester and anything a customer chooses to include in a ticket, including attachments. |
| Ardent Language Services Ltd | Human translation of product interfaces and documentation. | United Kingdom and Poland. | Interface strings only. Access to customer records is not provisioned. |
4.Product-specific sub-processors
These parties are engaged only where the relevant product or optional capability is subscribed for. A customer that has not subscribed to the product is not subject to the sub-processor.
| Sub-processor | Purpose | Location of processing | Categories of personal data |
|---|---|---|---|
| Arclight Payments Ltd. CEDX Ledger, CEDX Store | Card acquiring, settlement and payment reconciliation. | United Kingdom, Ireland and the United States. | Cardholder name, tokenised payment instrument, transaction amount and reference. Full card numbers are never held by CEDX. |
| Northwind Data Corp. CEDX Insight, warehouse connector | Managed analytics warehouse, where a customer elects to replicate data to it. | Customer-selected region across Europe, North America and Asia-Pacific. | Whichever datasets the customer configures for replication. |
| Thornbury Inference Ltd. CEDX Mira | Hosted model inference for the AI layer. | United Kingdom and Ireland only. No transfer outside the region. | Prompt content and the records the requesting user is already entitled to see. Not retained after the response; not used for training. |
| Whitcombe Screening Ltd. CEDX People, screening option | Pre-employment and right-to-work screening, where a customer enables it. | United Kingdom. | Identity documents, employment history and screening outcomes for the candidates a customer submits. |
| Calder Signing BV. CEDX Contract | Qualified electronic signature and long-term validation. | Netherlands and Germany. | Signatory name, email address, IP address, signature audit trail and the executed document. |
| Beacon Maps Ltd. CEDX Field | Geocoding and route optimisation for field service scheduling. | Ireland. | Service addresses and engineer location data during a shift. |
5.CEDX group entities
Affiliates within the CEDX group are sub-processors in their own right. They operate under an intra-group agreement incorporating the same obligations as the data processing agreement, and, where relevant, the Standard Contractual Clauses.
| Sub-processor | Purpose | Location of processing | Categories of personal data |
|---|---|---|---|
| CEDX Systems GmbH | European operations, EU support and managed operations. | Germany. | As required to deliver support and operations for European customers. |
| CEDX Systems Inc. | Americas support, professional services and managed operations. | United States. Transfers under the Standard Contractual Clauses. | As required to deliver support and services to customers who have enabled follow-the-sun access. |
| CEDX Systems Pte. Ltd. | Asia-Pacific support and managed operations. | Singapore. Transfers under the Standard Contractual Clauses. | As required to deliver support and operations for Asia-Pacific customers. |
| CEDX Systems Canada Inc. | Platform engineering and, where a customer has agreed in writing, defect investigation on production data. | Canada, which benefits from a UK and EU adequacy decision. | Limited to the records necessary to reproduce a specific reported defect. |
6.Notification of changes
- 6.1CEDX gives at least thirty days' notice before a new sub-processor begins processing customer personal data, and before an existing sub-processor's role is materially extended.
- 6.2Notice is given by updating this page and by email to the notification address each customer has registered. Any number of addresses may be registered, and a distribution list is acceptable.
- 6.3To register for notifications, write to privacy@cedxsystems.com from an address associated with the customer account, or add the address in the tenant's notification settings.
- 6.4Removing a sub-processor, or narrowing what one may access, is not a change requiring notice. It is recorded in the change history in clause 8 in any event.
- 6.5Where a sub-processor must be engaged at short notice to preserve the security or availability of the Services, CEDX may do so before the notice period expires. It will notify affected customers within one Working Day and explain why, and clause 7 continues to apply.
7.Objecting to a sub-processor
- 7.1A customer may object to a new or replacement sub-processor within thirty days of notice, on reasonable grounds relating to data protection. Objections go to privacy@cedxsystems.com and should state the ground relied on.
- 7.2CEDX will respond within ten Working Days, and will discuss the objection in good faith. Where possible it will offer a configuration change, a regional alternative or a workaround that avoids the sub-processor for that customer.
- 7.3Where no reasonable alternative can be made available within thirty days of the objection, the customer may terminate the affected subscription on written notice and receive a refund of fees paid for the unused remainder of the subscription term.
- 7.4An objection does not suspend the engagement of the sub-processor for other customers, and does not by itself entitle the objecting customer to withhold fees.
8.Change history
Every addition, removal and material amendment for the past two years. Entries are retained indefinitely and older ones are available on request.
| Date | Change | Sub-processor | Effective |
|---|---|---|---|
| 22 May 2026 | Added | Beacon Maps Ltd, for CEDX Field route optimisation. | 22 June 2026 |
| 3 March 2026 | Amended | Thornbury Inference Ltd, processing restricted to the United Kingdom and Ireland; the previous US region was withdrawn. | 3 March 2026 |
| 17 January 2026 | Removed | Pellworth Analytics Ltd, product marketing analytics, discontinued. | 17 January 2026 |
| 8 October 2025 | Added | Calder Signing BV, for CEDX Contract qualified signatures. | 10 November 2025 |
| 2 July 2025 | Amended | Halyard Observability Inc., record contents now redacted before transmission; scope narrowed to identifiers and request metadata. | 2 July 2025 |
| 14 April 2025 | Added | Ferrous Systems GmbH, replacing in-house backup custody. | 16 May 2025 |
| 9 December 2024 | Removed | Ashcombe Voice Ltd, replaced by Corvid Telecom SA. | 9 December 2024 |
9.Due diligence and ongoing assurance
- 9.1Before a sub-processor is engaged it is assessed against a documented standard covering security certification, breach history, financial stability, transfer mechanisms and the enforceability of our contractual rights in its jurisdiction.
- 9.2Every sub-processor is engaged under a written contract imposing obligations no less onerous than those CEDX owes its customers, including audit rights, breach notification within twenty-four hours and deletion on termination.
- 9.3Every sub-processor is reassessed at least annually. Those with access to unencrypted customer personal data are reassessed twice a year and must provide a current independent assurance report.
- 9.4CEDX maintains a transfer risk assessment for every sub-processor established outside the United Kingdom and the European Economic Area, reviewed annually and after any material change in the law of the recipient country.
- 9.5A copy of the due diligence summary for any listed sub-processor is available to customers on request, with commercial terms redacted.
- 9.6CEDX remains fully liable to the customer for the acts and omissions of every sub-processor listed on this page.