[ Legal ] Subprocessors
Subprocessors
Every supplier that touches personal data on our behalf, what it does, and what it actually receives. We give 30 days notice before adding a new one.
How we use this list
These are the suppliers that process personal data on our behalf. Each one is bound by a written data processing agreement that limits it to our instructions and holds it to security terms at least as strong as our own.
We keep the list current. Before we add a new subprocessor that handles customer data, we tell affected customers by email at least 30 days in advance. If you object on reasonable data protection grounds and we cannot offer an alternative, you can end your plan without paying for the rest of the term.
Infrastructure
- Vercel
- United States. Hosts dirr.ai and the websites we build. Receives request data: IP address, user agent, and the content of the pages themselves.
- Supabase
- United States. Our database, file storage and customer sign-in. Holds account details, intake answers, briefs, uploaded files and site content.
- Upstash
- United States. Rate limiting and spend counters. Receives short lived keys derived from IP addresses, and nothing else.
Payments
- Stripe
- United States and Ireland. Takes payment and runs subscriptions, invoices and refunds. Receives your name, email and billing details. Card numbers go straight to Stripe and never reach us. Stripe is also a controller in its own right for fraud prevention and regulatory purposes.
Building your site
- Anthropic
- United States. The Claude models that draft your pages and run the brief chat. Receives what you told us about your business. Under business API terms that do not permit training on our data.
- Firecrawl
- United States. Reads what is publicly published at a website address you give us, so we can prefill your answers. Receives the address, and returns what was already public.
- Unsplash and Pexels
- United States. Stock photography for pages that need it. Receives search terms, never personal data.
Contacting you
- Resend
- United States. Sends the service email: sign-in codes, welcome mail, build notices, edit request updates and the leads your contact form collects. Receives sender and recipient addresses and the message.
- Slack
- United States. Internal operator alerts so a human notices a new purchase or a stuck build. Receives business name, plan and event, not the contents of your site.
- Cal.com
- United States. Only if you book a call about the Custom package. Receives your name, email and the time you picked.
Advertising, and only with consent
- Meta Platforms
- United States and Ireland. Ad measurement through the Meta Pixel and the matching server-side events. Receives event data and a hashed email address, and only after you accept in the cookie banner. Nothing is sent if you decline.
Transfers outside the EU and EEA
Most of these suppliers are in the United States. Where a supplier is certified under the EU-US Data Privacy Framework we rely on that certification. Otherwise we rely on the European Commission's Standard Contractual Clauses together with the supplier's own technical measures.
Ask at dirr.ai/contact and we will tell you which mechanism covers a specific supplier and send you a copy of the clauses.
Company details are in the terms.
Last updated 2026-08-12 · questions: get in touch