Legal
Sub-processors
Last updated 9 August 2026
Agencies using Vector are usually processors for their own clients, which makes us a sub-processor. Many client contracts require sub-processors to be disclosed and sometimes approved in advance — so this page exists to make that a two-minute task rather than a two-week one.
Current sub-processors
| Provider | Purpose | Data | Region |
|---|---|---|---|
| Hosting provider | Application servers, database, object storage | All customer data | EU |
| Google LLC | Google Ads API — the source of the advertising data we analyse. We read only; we never write. | Advertising performance data belonging to accounts you connect | Global (your own existing relationship) |
| Anthropic | Generates the readable text of a recommendation from an already-computed finding | Aggregated metrics only — no personal data, no raw search terms, no account identifiers | EU where available, with zero data retention configured |
| Transactional email provider | Sign-in links, notifications and digests | User name and email address | EU |
| Error monitoring | Application error reports | Technical diagnostics with personal data scrubbed before transmission | EU |
What is never sent to a third party
Raw search term text is never sent to the language model provider or to any analytics service. The payload used to generate recommendation text contains aggregated metrics for a single account and nothing else — no account identifiers, no client names, no free text from end users.
Notice of change
We will publish any new or replacement sub-processor here and notify account owners by email at least 30 days before it begins processing customer data, so that you have time to raise an objection or inform your own clients.
Documents available on request
A counter-signable data processing agreement, a one-page security summary, and — for customers using conflict groups — an exportable report showing exactly who has access to which clients as of a given date. Write to privacy@vboom.io.