Subprocessor List

Last updated: 20 August 2026

What Are Subprocessors?

When Clothink Ltd processes your personal data to deliver the Service, we engage certain third-party companies (subprocessors) to assist us. Each subprocessor acts only on our instructions and is contractually required to protect your data and use it solely for the purposes we specify.

For more information about how we use your data and your rights, please see our Privacy Policy.

Current Subprocessors

The table below summarises the categories of third-party subprocessors we currently engage, together with the purpose, the categories of personal data processed, the country where processing typically takes place, and a summary of how long categories of data tend to be retained (exact periods depend on provider defaults, our configuration, and legal obligations).

The named list of subprocessors is available on request and under our Data Processing Agreement (DPA). Contact us via the contact page if you need the full named list.

Cloud database, authentication and file storage

Purpose: Database, authentication, and file storage

Data processed: Account data, user content, metadata, authentication tokens

Location: United States

Retention (summary)

Retained while your account is active; deleted or anonymised after closure subject to backups and legal holds per the provider’s platform terms.

AI inference for design generation

Purpose: AI content generation (design concepts, mockups, tech packs)

Data processed: Text prompts, images uploaded for generation

Location: United States

Retention (summary)

Processing for inference is largely transient; logs and billing metadata may be retained per the provider’s terms and our configuration.

Payment processing

Purpose: Payment processing and subscription management

Data processed: Billing address, payment method details, subscription status

Location: United States / Global

Retention (summary)

Payment and customer records retained per the provider’s obligations and legal requirements (often multi-year for tax and fraud prevention).

Application hosting

Purpose: Application hosting and web analytics

Data processed: Usage data, page views, performance metrics, IP address

Location: United States

Retention (summary)

Hosting logs and analytics metrics per plan and product settings (reporting windows vary by plan).

Product analytics

Purpose: Product analytics and session replay on the signed-in workspace

Data processed: Usage events, account identifiers, and session replays of the signed-in workspace (form inputs masked). Internal accounts are excluded from replay.

Location: United States

Retention (summary)

Product analytics events retained per project settings; session replays retained for 30 days.

Error monitoring

Purpose: Error and performance monitoring

Data processed: Error logs, stack traces, session replays when errors occur (with text and input masking). No PII intentionally sent.

Location: United States

Retention (summary)

Issues, replays, and performance data retained per plan and organisation settings (commonly 30–90 days for errors on paid tiers).

Transactional and marketing email

Purpose: Transactional email delivery and optional product-update / tips emails, including marketing-site product-update subscriptions

Data processed: Email addresses, message content, delivery and engagement events (opens, clicks, bounces)

Location: United States

Retention (summary)

Message metadata and delivery records retained for deliverability, abuse prevention, and legal compliance.

Pattern and graphic generation

Purpose: AI-powered pattern and graphic generation

Data processed: Text prompts for pattern and graphic generation

Location: United States

Retention (summary)

Prompts and outputs processed to deliver generation; retained per the provider’s policy and product settings.

Rate limiting

Purpose: Rate limiting and abuse prevention

Data processed: Hashed request identifiers. No personally identifiable information is stored.

Location: United States

Retention (summary)

Short-lived counters/TTL-based data for rate limiting; not used as a long-term personal data store.

Marketing CMS

Purpose: Marketing CMS (SEO metadata and optional page copy when configured)

Data processed: Public marketing content and SEO fields served to browsers; CMS Studio is operator-only

Location: United States / Global (region confirmed in project settings)

Retention (summary)

Published marketing content until removed or replaced in the CMS; see the provider’s privacy notice for platform retention.

International Transfers

Subprocessors in the categories above are currently based in or process data in the United States. Where personal data is transferred outside the UK or EEA, we rely on one or more of the following safeguards:

  • UK SCCs / IDTAs:UK-approved Standard Contractual Clauses or International Data Transfer Agreements (IDTAs) approved by the Information Commissioner's Office (ICO), for transfers affecting UK residents.
  • EU SCCs: Standard Contractual Clauses adopted by the European Commission (2021/914), for transfers affecting EU/EEA residents.
  • Adequacy decisions by the UK government or European Commission where applicable.

Each subprocessor maintains its own Data Processing Agreement (DPA) covering the relevant transfer mechanisms. The named providers and their DPA documentation are available on request.

Changes to This List

We review and update this list whenever we add or remove a subprocessor category. The “Last updated” date at the top of this page reflects the most recent revision. If you have questions about a specific subprocessor, please contact us through our contact page.

This list is provided for transparency purposes in accordance with UK GDPR and GDPR Article 13/14 requirements. Return to Privacy Policy.