Sub-processors
Last reviewed: 12 August 2026
Quick Policy, a Pineapple Tapped Limited company (Company No. 13376705) uses the third-party services below to run Quick Policy. Each is a sub-processor under UK GDPR: they may process customer personal data on our instructions in order to provide their part of the service. This page is referenced by our data processing terms and is kept current as services change.
Currently in use
| Service | Used for | Data involved |
|---|---|---|
| Railway | Application hosting and the managed PostgreSQL database. | All account, organisation, policy, training, incident and audit data held by the platform. |
| Tigris Data | S3-compatible object storage for uploaded files. | Evidence files, uploaded documents, exported packs and brand assets, plus their filenames. |
| Anthropic | AI model provider for policy drafting, training content and related generation. | The organisation profile, policy text and prompts sent for a generation request. For policy drafting the profile includes the names, job titles and departments of current staff from the Team directory, so that policies can name the people who own each control, and a policy revision also includes the names of the staff who reviewed it; email addresses are not sent. Not used to train their models under Anthropic’s commercial terms. |
| OpenAI | AI model provider for onboarding analysis, compliance review and search embeddings, and the backup model for policy drafting. | Onboarding answers, policy text and search queries sent for those specific features. When it handles a policy drafting request, it receives the same organisation profile as the primary provider, including the names, job titles and departments of current staff; email addresses are not sent. |
| Upstash | Managed Redis used for API rate limiting. | Short-lived request counters keyed by identifier. No policy or document content. |
How long AI working files are kept
When a policy is drafted, we keep the organisation profile snapshot sent to the AI provider and the in-progress draft data from each generation step. These working files are kept for 12 months after the draft finishes, then stripped. Files still in use are kept while they are needed: the profile snapshot a current policy was drafted from, the document-control details printed on an exported policy version, and drafts still awaiting a decision, such as an open revision. The policy itself and its version history are kept. Answers given to a draft's follow-up questions are kept with the draft's record, so they can be offered again when the policy is redrafted, and are not stripped at 12 months. This covers the copies held in our own database.
Integrated but not yet enabled
These are built into the product but are not active on this deployment, so no customer data reaches them today. They will move to the table above when enabled.
| Service | Would be used for | Data involved |
|---|---|---|
| Stripe | Payment processing and subscription billing. | Billing contact and payment details, handled by Stripe directly. Not yet enabled on this deployment — no billing data has been sent. |
Changes to this list
We update this page when a sub-processor is added, removed, or its role changes. If you would like advance notice of changes, or you have a question about a specific service, contact us and we will add you to the notification list.
Related
See our Privacy Notice for what we process and why, and our Terms for the contractual position.