1. How we disclose our sub-processors
These are the categories of third parties Far & Wide uses to operate the platform. GDPR permits disclosure of recipients by category (Articles 13-14), and we deliberately keep the specific providers confidential to protect commercially sensitive detail of how the platform is built. The full named list — each provider's identity, location and role — is available to customers in our Data Processing Agreement and on request (under NDA for enterprise accounts). We notify enterprise account holders before adding a new sub-processor category.
2. Categories of sub-processors
- Payment processing — subscription and order billing (EU + US; SCCs / DPF). Receives the billing email plus the card brand and last four digits only; never full card numbers.
- Hosting, delivery and log ingestion — serves the website, portal and API routes, and ingests the AI-visibility log-drain signals (EU region + global edge; SCCs / DPF).
- EU database, authentication and file storage — where accounts, brand data, runs, artifacts and visitor-signal tables are held (EU region, Frankfurt; SCCs / DPF for any US-parent access).
- EU audit compute — runs the audit pipeline (EU / EEA, Germany).
- Transactional email — delivery of sign-in links, password resets and account email (SCCs).
- Customer-relationship management — customer communications, where used (SCCs).
- Website and product analytics — website analytics and EU-hosted product analytics and session recordings, both consent-gated.
- Internal team notification — alerts our founders when a new pilot application arrives (relays the application's name, email, website and country).
- AI answer engines — the platforms we measure your brand against; requests are designed to carry no personal data.
- Data-collection and search-measurement providers — collect public web content and search results; designed to receive no personal data.
3. Notes
- DPF = EU-US Data Privacy Framework (the post-Schrems II adequacy mechanism for certified US recipients).
- SCCs = Standard Contractual Clauses (European Commission Decision 2021/914).
- Named list on request. The identity, location and role of each specific sub-processor is available to customers in the DPA and on request under NDA. Each US recipient has been assessed for surveillance-law risk under our Transfer Impact Assessment.
- AI engines receive no personal data by design: the audit processes public information about companies, brands and products — not personal data about individuals. Query prompts carry only the question text and the brand/company facts you configured, and we operate with model-training on submitted data disabled.
- The one visitor-data path: if you enable the AI-visibility log drain on your own website, your server logs (including visitor IP and user-agent) stream to our EU hosting and EU database purely to attribute AI-driven crawls and visits to you. For that data you are the controller and we are your processor; we keep it for the life of your account and delete it when you close the account.
4. Questions
Questions about our sub-processors, or to receive the full named list under NDA: hello@farandwide.io.
