Data Processing & Sub-processors
Effective date: July 28, 2026
1. Purpose of this page
This page describes the third-party sub-processors we use to store and process personal data collected through the Service, and summarizes how our data handling aligns with applicable data protection law, including the EU/UK General Data Protection Regulation (GDPR) and India's Digital Personal Data Protection Act, 2023 (DPDP Act).
2. Our sub-processors
We use the following categories of sub-processors to operate the Service:
- Supabase (database, authentication, and file storage) — stores lead records, user accounts, and CRM data in a managed Postgres database with row-level security controls.
- Resend (transactional and marketing email delivery) — sends registration confirmations, welcome emails, and assignment notifications on our behalf.
- WhatsApp Business Cloud API (Meta Platforms) — delivers WhatsApp messages such as masterclass reminders, webinar links, and lead/assignment notifications.
Each sub-processor is contractually bound to process personal data only on our instructions and to apply appropriate technical and organizational security measures.
3. Data location
Personal data is stored on our sub-processors' cloud infrastructure. We select sub-processors that maintain recognized security and compliance certifications for the services they provide to us.
4. GDPR alignment
For individuals in the UK/EU, we act as the data controller for personal data collected through the Service, and our sub-processors act as data processors under written data processing agreements. Where applicable, you have the rights described in our Privacy Policy, including access, rectification, erasure, and objection to processing.
5. DPDP Act (India) alignment
For individuals in India, we process personal data (including phone numbers) as a "Data Fiduciary" under the DPDP Act, on the basis of your explicit consent obtained at registration. We take reasonable security safeguards to protect personal data against unauthorized access or breach, and you may withdraw consent or request erasure of your data at any time as described in our Privacy Policy.
6. Security measures
- Database access is restricted using row-level security (RLS) policies scoped per table.
- Administrative actions (e.g. managing credentials or site content) require an authenticated admin role, verified server-side.
- Secrets and API credentials are never exposed to the browser and are stored separately from public marketing content.
7. Updates to sub-processors
We may add or change sub-processors as our Service evolves. This page will be updated to reflect the current list, and the effective date at the top will change accordingly.
8. Contact us
Questions about our data processing practices can be sent to connect@aslamkureshi.com.
