Subprocessor List
Last updated: 20 August 2026
What Are Subprocessors?
When Clothink Ltd processes your personal data to deliver the Service, we engage certain third-party companies (subprocessors) to assist us. Each subprocessor acts only on our instructions and is contractually required to protect your data and use it solely for the purposes we specify.
For more information about how we use your data and your rights, please see our Privacy Policy.
Current Subprocessors
The table below summarises the categories of third-party subprocessors we currently engage, together with the purpose, the categories of personal data processed, the country where processing typically takes place, and a summary of how long categories of data tend to be retained (exact periods depend on provider defaults, our configuration, and legal obligations).
The named list of subprocessors is available on request and under our Data Processing Agreement (DPA). Contact us via the contact page if you need the full named list.
| Category | Purpose | Data processed | Location | Retention (summary) |
|---|---|---|---|---|
| Cloud database, authentication and file storage | Database, authentication, and file storage | Account data, user content, metadata, authentication tokens | United States | Retained while your account is active; deleted or anonymised after closure subject to backups and legal holds per the provider’s platform terms. |
| AI inference for design generation | AI content generation (design concepts, mockups, tech packs) | Text prompts, images uploaded for generation | United States | Processing for inference is largely transient; logs and billing metadata may be retained per the provider’s terms and our configuration. |
| Payment processing | Payment processing and subscription management | Billing address, payment method details, subscription status | United States / Global | Payment and customer records retained per the provider’s obligations and legal requirements (often multi-year for tax and fraud prevention). |
| Application hosting | Application hosting and web analytics | Usage data, page views, performance metrics, IP address | United States | Hosting logs and analytics metrics per plan and product settings (reporting windows vary by plan). |
| Product analytics | Product analytics and session replay on the signed-in workspace | Usage events, account identifiers, and session replays of the signed-in workspace (form inputs masked). Internal accounts are excluded from replay. | United States | Product analytics events retained per project settings; session replays retained for 30 days. |
| Error monitoring | Error and performance monitoring | Error logs, stack traces, session replays when errors occur (with text and input masking). No PII intentionally sent. | United States | Issues, replays, and performance data retained per plan and organisation settings (commonly 30–90 days for errors on paid tiers). |
| Transactional and marketing email | Transactional email delivery and optional product-update / tips emails, including marketing-site product-update subscriptions | Email addresses, message content, delivery and engagement events (opens, clicks, bounces) | United States | Message metadata and delivery records retained for deliverability, abuse prevention, and legal compliance. |
| Pattern and graphic generation | AI-powered pattern and graphic generation | Text prompts for pattern and graphic generation | United States | Prompts and outputs processed to deliver generation; retained per the provider’s policy and product settings. |
| Rate limiting | Rate limiting and abuse prevention | Hashed request identifiers. No personally identifiable information is stored. | United States | Short-lived counters/TTL-based data for rate limiting; not used as a long-term personal data store. |
| Marketing CMS | Marketing CMS (SEO metadata and optional page copy when configured) | Public marketing content and SEO fields served to browsers; CMS Studio is operator-only | United States / Global (region confirmed in project settings) | Published marketing content until removed or replaced in the CMS; see the provider’s privacy notice for platform retention. |
| Category | Purpose / Data | Retention |
|---|---|---|
| Cloud database, authentication and file storage | Database, authentication, and file storage Account data, user content, metadata, authentication tokens United States | Retained while your account is active; deleted or anonymised after closure subject to backups and legal holds per the provider’s platform terms. |
| AI inference for design generation | AI content generation (design concepts, mockups, tech packs) Text prompts, images uploaded for generation United States | Processing for inference is largely transient; logs and billing metadata may be retained per the provider’s terms and our configuration. |
| Payment processing | Payment processing and subscription management Billing address, payment method details, subscription status United States / Global | Payment and customer records retained per the provider’s obligations and legal requirements (often multi-year for tax and fraud prevention). |
| Application hosting | Application hosting and web analytics Usage data, page views, performance metrics, IP address United States | Hosting logs and analytics metrics per plan and product settings (reporting windows vary by plan). |
| Product analytics | Product analytics and session replay on the signed-in workspace Usage events, account identifiers, and session replays of the signed-in workspace (form inputs masked). Internal accounts are excluded from replay. United States | Product analytics events retained per project settings; session replays retained for 30 days. |
| Error monitoring | Error and performance monitoring Error logs, stack traces, session replays when errors occur (with text and input masking). No PII intentionally sent. United States | Issues, replays, and performance data retained per plan and organisation settings (commonly 30–90 days for errors on paid tiers). |
| Transactional and marketing email | Transactional email delivery and optional product-update / tips emails, including marketing-site product-update subscriptions Email addresses, message content, delivery and engagement events (opens, clicks, bounces) United States | Message metadata and delivery records retained for deliverability, abuse prevention, and legal compliance. |
| Pattern and graphic generation | AI-powered pattern and graphic generation Text prompts for pattern and graphic generation United States | Prompts and outputs processed to deliver generation; retained per the provider’s policy and product settings. |
| Rate limiting | Rate limiting and abuse prevention Hashed request identifiers. No personally identifiable information is stored. United States | Short-lived counters/TTL-based data for rate limiting; not used as a long-term personal data store. |
| Marketing CMS | Marketing CMS (SEO metadata and optional page copy when configured) Public marketing content and SEO fields served to browsers; CMS Studio is operator-only United States / Global (region confirmed in project settings) | Published marketing content until removed or replaced in the CMS; see the provider’s privacy notice for platform retention. |
Cloud database, authentication and file storage
Purpose: Database, authentication, and file storage
Data processed: Account data, user content, metadata, authentication tokens
Location: United States
Retention (summary)
Retained while your account is active; deleted or anonymised after closure subject to backups and legal holds per the provider’s platform terms.
AI inference for design generation
Purpose: AI content generation (design concepts, mockups, tech packs)
Data processed: Text prompts, images uploaded for generation
Location: United States
Retention (summary)
Processing for inference is largely transient; logs and billing metadata may be retained per the provider’s terms and our configuration.
Payment processing
Purpose: Payment processing and subscription management
Data processed: Billing address, payment method details, subscription status
Location: United States / Global
Retention (summary)
Payment and customer records retained per the provider’s obligations and legal requirements (often multi-year for tax and fraud prevention).
Application hosting
Purpose: Application hosting and web analytics
Data processed: Usage data, page views, performance metrics, IP address
Location: United States
Retention (summary)
Hosting logs and analytics metrics per plan and product settings (reporting windows vary by plan).
Product analytics
Purpose: Product analytics and session replay on the signed-in workspace
Data processed: Usage events, account identifiers, and session replays of the signed-in workspace (form inputs masked). Internal accounts are excluded from replay.
Location: United States
Retention (summary)
Product analytics events retained per project settings; session replays retained for 30 days.
Error monitoring
Purpose: Error and performance monitoring
Data processed: Error logs, stack traces, session replays when errors occur (with text and input masking). No PII intentionally sent.
Location: United States
Retention (summary)
Issues, replays, and performance data retained per plan and organisation settings (commonly 30–90 days for errors on paid tiers).
Transactional and marketing email
Purpose: Transactional email delivery and optional product-update / tips emails, including marketing-site product-update subscriptions
Data processed: Email addresses, message content, delivery and engagement events (opens, clicks, bounces)
Location: United States
Retention (summary)
Message metadata and delivery records retained for deliverability, abuse prevention, and legal compliance.
Pattern and graphic generation
Purpose: AI-powered pattern and graphic generation
Data processed: Text prompts for pattern and graphic generation
Location: United States
Retention (summary)
Prompts and outputs processed to deliver generation; retained per the provider’s policy and product settings.
Rate limiting
Purpose: Rate limiting and abuse prevention
Data processed: Hashed request identifiers. No personally identifiable information is stored.
Location: United States
Retention (summary)
Short-lived counters/TTL-based data for rate limiting; not used as a long-term personal data store.
Marketing CMS
Purpose: Marketing CMS (SEO metadata and optional page copy when configured)
Data processed: Public marketing content and SEO fields served to browsers; CMS Studio is operator-only
Location: United States / Global (region confirmed in project settings)
Retention (summary)
Published marketing content until removed or replaced in the CMS; see the provider’s privacy notice for platform retention.
International Transfers
Subprocessors in the categories above are currently based in or process data in the United States. Where personal data is transferred outside the UK or EEA, we rely on one or more of the following safeguards:
- UK SCCs / IDTAs:UK-approved Standard Contractual Clauses or International Data Transfer Agreements (IDTAs) approved by the Information Commissioner's Office (ICO), for transfers affecting UK residents.
- EU SCCs: Standard Contractual Clauses adopted by the European Commission (2021/914), for transfers affecting EU/EEA residents.
- Adequacy decisions by the UK government or European Commission where applicable.
Each subprocessor maintains its own Data Processing Agreement (DPA) covering the relevant transfer mechanisms. The named providers and their DPA documentation are available on request.
Changes to This List
We review and update this list whenever we add or remove a subprocessor category. The “Last updated” date at the top of this page reflects the most recent revision. If you have questions about a specific subprocessor, please contact us through our contact page.
This list is provided for transparency purposes in accordance with UK GDPR and GDPR Article 13/14 requirements. Return to Privacy Policy.