Trust

Security & Sub-processors

Last updated: 11 June 2026

We know you're trusting us with access to your CRM, billing, and analytics data. Here's a plain-English overview of how we protect it. For the full legal detail, see our Privacy Policy.

Data hosted in the UK (AWS eu-west-2)
Read-only integration access
No raw CRM/billing data stored
Encrypted in transit (TLS) & at rest

1. How we protect your data

2. Sub-processors

We use the following third-party providers ("sub-processors") to deliver our products. We carry out due diligence on each provider and only share the minimum data necessary for them to perform their function.

Sub-processorPurposeLocationData shared
Supabase (AWS)Database & authenticationUK (eu-west-2, London)All account & platform data
AnthropicAI insight & content generation (Claude API)USA (processed in transit, not retained for training)Computed metrics, ICP/targets — no PII
NangoOAuth connection management for integrationsEUOAuth tokens for connected tools only
Make.comWorkflow automation (scheduled metric pulls, emails)EUAccount & metrics data in transit
ResendTransactional email (welcome, digest, receipts)EU/USAName, email address, email content
StripePayment processingUSA (UK IDTA / SCCs in place)Billing & payment data (not stored by us)
NetlifyWebsite & app hosting / CDNGlobalWebsite traffic logs

We'll update this page if our sub-processor list changes, and notify customers of material changes by email where required.

3. Reporting a security issue

If you discover a security vulnerability, please report it responsibly to security@ouridea.ai. Please don't access, modify, or delete other users' data, and give us reasonable time to investigate and fix the issue before any public disclosure. We won't take legal action against good-faith security research conducted in line with this policy.

4. Incident response

In the event of a data breach affecting your personal data, we'll notify affected customers without undue delay, and the ICO within 72 hours where required under UK GDPR.

5. Questions

For security or compliance questions (including requests for a DPA — see our DPA template), email adam@ouridea.ai.

Related: Privacy Policy · Cookie Policy · Acceptable Use Policy · Refund & Cancellation Policy