Subprocessors and International Transfers

Version 1.0.0Took effect 17 September 2026

What this page is

Innovology Ltd, trading as SailCoach, is the data controller for the personal data in this service. We do not run our own data centre, so some of the processing is carried out by other companies acting on our instructions. Those companies are our processors — often called subprocessors, because we are ourselves a processor for clubs and coaches who use SailCoach to run their programmes.

This page lists every one of them: who they are, what they do for us, what personal data reaches them, and where the processing happens. It also lists what we deliberately do not use, because a short list of absences tells you more than a long list of reassurances.

Read it alongside the Privacy Policy, which explains why we process data at all, and the Cookie Policy, which covers the handful of these that your own browser contacts directly.

How to read the "where" column

Where the code and the vendor configuration do not prove a hosting region, the entry says to be confirmed. We would rather show you an honest gap than a confident guess. Confirming these regions is live work, and its status is set out in full under "Where the data goes" below.

One partial exception, so the pages agree: our own worker containers report their region to us as they run, and they report EU West and US East. That tells us where those containers are. It does not tell us where the managed database, cache or object store sit — they report nothing — and it is not a contractual commitment from our host about where personal data is processed. So the rows below still say to be confirmed, and the Environmental Policy uses the same two regions only to reason about electricity grids.

Hosting and core platform

ProcessorWhat it does for usPersonal data it receivesWhere
Railway Corp. (US)Runs everything: the website, the admin console, the API, the authentication service, the gateway, and the background workers.All platform data — accounts, sailor profiles including those of children, guardian links, coaching notes, session records, medical notes, photos and video, GPS race tracks.To be confirmed
MongoDB, on RailwayOur main database. We run the database software ourselves on Railway infrastructure; this is not MongoDB's own hosted Atlas service, and MongoDB Inc. receives nothing.Everything in the row above.Follows Railway — to be confirmed
Redis, on RailwayJob queue and live updates. When a video needs transcoding or a race needs analysing, the job sits here until a worker picks it up.Job instructions containing account, sailor and race identifiers. Not free-text notes.Follows Railway — to be confirmed
Object storage, on RailwayThe private bucket holding uploaded files.Profile photos, session photos and documents, session video and audio — including images and recordings of children — and the smaller versions we generate from them.To be confirmed. The storage region setting in our code defaults to a US value, but S3-compatible services frequently ignore that setting, so we do not treat it as evidence.

Everything above is one commercial relationship: Railway. If Railway's region for our services is confirmed as outside the UK, that is a single transfer question covering the whole platform, which is why it is the most important unconfirmed item on this page.

Files in the bucket are private and are served through short-lived signed links, so a link cannot be shared or guessed. Traffic between you and us is encrypted in transit with HTTPS. We do not currently claim encryption at rest, because we have not verified it; Security says more.

Monitoring, email and AI

ProcessorWhat it does for usPersonal data it receivesWhere
Sentry (Functional Software, Inc., US)Error monitoring, performance tracing and session replay. When something breaks, this is how we find out.Your email address, username and account ID are attached to error reports on purpose, so we can tell whether a fault hit one person or everyone. Replays capture a reconstruction of the screen; see below. Authorisation headers and cookies are stripped from our API's error reports before they are sent; reports from the website's own server are not filtered that way, which is a gap we are closing.To be confirmed (we have not verified whether our Sentry organisation sits on US or EU infrastructure)
Resend (US)Every email we send: address verification, coach and club invitations, parent–child link invitations, and notifications. We also ask Resend afterwards whether a message was delivered.Recipient email address, sender and recipient names, the context of an invitation, and the body of the message. Where an invitation concerns a child, the child's first name appears in it.To be confirmed (Resend offers an EU sending region; we have not selected one)
Anthropic (US)Five features, all using the Claude Haiku model: summarising and scoring one piece of coach feedback; synthesising a sailor's whole feedback history into themes; suggesting drills from recent feedback; producing group-level insights for a session; and tidying a spoken note into a structured written one.Coaches' free text about a sailor. No sailor is named on any path — every prompt refers to "the sailor" and tells the model never to guess a name. On the feedback-history path, coaches appear as "Coach 1", "Coach 2" and so on. On the group-insights path, names are additionally stripped from the text itself by a pattern match, which is pseudonymisation and not anonymisation. For voice notes: the transcript of what was said, up to 20,000 characters.US

Session replay, specifically

Sentry records 10% of sessions at random and 100% of sessions in which an error occurs. From this release, replays are masked: text is obscured and media is blocked before the recording leaves your browser, so a replay shows us layout and interaction rather than the content of anyone's notes. Before this release, replays captured on-screen text unmasked. Replay sits behind the analytics consent category described in the Cookie Policy, so it does not run at all unless you allow it.

Error reports and performance traces are a different matter: they are sent whatever you choose about cookies, because we treat them as strictly necessary to keep the service running. Replay is the only part of Sentry that is optional. We have not decided whether replay should run on signed-in pages at all; that question is open on our DPIA register.

AI, specifically

Two of the five have a screen you can use today — group-level session insights, and voice-note tidying. Both fail soft: with no API key configured they fall back to deterministic code and nothing leaves us. The other three are API endpoints with no screen in the app; without a key they return an error rather than a result. Most of what looks clever in SailCoach — the Helm Grade, the headroom verdict, the race analysis and the coach reflection — is statistics and templated prose, not AI, and no personal data leaves our systems for any of it. Which parts are genuinely AI, what we commit to, and what the outputs must never be used for is set out in How We Use AI.

We rely on Anthropic's commercial API terms, under which inputs and outputs are not used to train their models. Confirming that position contractually for our account is an outstanding item, listed at the end of this page.

Sign-in and speech

ProcessorWhat it does for usPersonal data it receivesWhere
Google — OAuth sign-in"Sign in with Google", where our authentication service has it enabled.Your email address, name, profile picture and Google account ID come to us. Google learns that you signed in to SailCoach.Global
Google — Chrome's speech recognition serviceDictating a note. The button uses the speech recognition built into your browser.In Chrome and other Chromium browsers, your voice is sent to Google's servers to be transcribed. That includes a child's voice if a child dictates a note. We do not receive the audio — only the text that comes back, which then goes to Anthropic to be tidied.Global

The speech point deserves emphasis because it is easy to miss and nothing on screen makes it obvious. If you would rather Google never received your voice, type the note instead. Safari and Firefox handle dictation differently, and some do it on the device; we cannot promise which, because it is your browser's decision, not ours.

Our authentication is self-hosted. There is no Auth0, Clerk, Firebase Auth or similar — passwords and sessions live in our own database.

Maps, weather and media

ProcessorWhat it does for usPersonal data it receivesWhere
Open-MeteoWind and weather for sessions and races, and turning a venue name into coordinates.The venue or club text someone typed, plus coordinates and a date. Requests are made by our servers, so your IP address is not disclosed.To be confirmed
OpenStreetMap FoundationMap tiles for every map in the product. Loaded by your browser, directly.Your IP address, your user-agent, and the tile coordinates — which reveal roughly which venue or session you are looking at.To be confirmed (OSMF is a UK charity; we have not verified where the tile servers run)
Cloudflare (cdnjs)The map pin images, also loaded by your browser, directly.Your IP address and user-agent.Global network
CloudinaryHosts the background video on our public home page. Nothing inside the app.The IP address and user-agent of anyone who visits the home page.To be confirmed
Google (YouTube)Plays a video where a coach has embedded one in session content. We use the no-cookie player, so no advertising cookies are set.The viewer's IP address, user-agent, and the video watched.Global
Google (Fonts)Supplies the web font our email templates ask for. Nothing on the website itself: our own fonts are served by us.Nothing, unless your mail app loads remote content — in which case Google sees your IP address and user-agent at the moment you open the email. Turning off remote image loading stops it.Global

The five browser-direct entries are the ones you can see for yourself — four in the app, and the email font in your mail app. They are covered in the Cookie Policy, including the remaining YouTube gap: the player still loads as soon as the page opens, rather than waiting for a click.

Developer tooling

ProcessorWhat it does for usPersonal data it receivesWhere
GitHub (Microsoft, US)Source code hosting and automated testing.Developer accounts and code only. No user data. Our automated tests run against throwaway local databases, and a build check fails if anyone points a development environment at the live API — a control we added after exactly that happened once.US
Microsoft Container Registry, npm registryBase images and software libraries pulled while building the app.None.US

What we do not use

Each of these is verifiable in our codebase, and each stays true until this page says otherwise.

  • No payment provider. SailCoach is free today. There is no Stripe, no PayPal, no card processing of any kind, because there is nothing to pay for. Paid plans are planned; when one exists, this page will name the provider before it takes a payment.
  • No advertising. No ad networks, no ad tags, no Meta pixel, no conversion tracking, no retargeting. We do not sell or rent personal data, and we do not share it with data brokers.
  • No third-party product analytics. No Google Analytics, no PostHog, no Mixpanel, no Amplitude, no Segment, no Hotjar, no Plausible. Our usage measurement is entirely first-party and stays in our own database.
  • No hosted authentication provider.
  • No push-notification vendor. The app can be installed to your home screen, but nothing sends you push notifications and no push service holds a device token for you.
  • No third-party chat, support or session-recording widget beyond the Sentry replay described above.
  • No third-party transcription or image processing on our servers. Video transcoding, image resizing and text recognition all run on our own workers. The exception is dictation, which your own browser does — and on Chrome that means Google, as the table above sets out.
  • No Google Maps, Mapbox or MapTiler for map tiles. We do use Google Maps as a destination: a venue's location links out to google.com/maps with its coordinates in the address. That is a link you choose to follow, and Google's terms govern it from that point.
  • No Cloudflare R2 or Backblaze B2. Some of our internal design notes describe a tiered storage design using them. It was never built, and listing it here would be listing a plan as a fact.

Sites we read data from

Separately from the processors above, we collect published race results and GPS race tracks from TracTrac, MetaSail, Sailwave, host club results pages, SailRacer, TackTracker and the Internet Archive. These organisations are not our processors — we are reading what they publish, not sending them your data. But that reading brings named sailors, including children, into our database who never signed up with us. That is a significant matter and it has its own treatment, under Art. 14 of the UK GDPR, in the Privacy Policy.

Where the data goes

Most of the companies on this page are based in the United States. Transferring personal data out of the UK is allowed, but only with a lawful transfer mechanism in place under Chapter V of the UK GDPR. The two that matter here:

  • The UK International Data Transfer Agreement (IDTA), or the UK Addendum bolted on to the EU Standard Contractual Clauses. Most US vendors incorporate one or both into the data processing addendum attached to their standard terms.
  • The EU Standard Contractual Clauses (Commission Implementing Decision 2021/914), for the personal data of our users in the EU, for whom EU GDPR applies alongside.

Where a UK-facing transfer relies on those clauses, a transfer risk assessment is also required — a written judgement about whether the destination country's laws undermine the protection the clauses promise.

Honest status

ProcessorMechanism relied onStatus
Railway (and the database, queue and storage running on it)Vendor DPA incorporating SCCs and the UK Addendum, accepted as part of their online termsAccepted but not individually reviewed or countersigned; region unconfirmed; transfer risk assessment outstanding
SentryVendor DPA with SCCs and UK Addendum in their standard termsAccepted; organisation region and replay retention period to be confirmed; transfer risk assessment outstanding
ResendVendor DPA in their standard termsAccepted; sending region and how long they retain message bodies to be confirmed
AnthropicCommercial API terms, under which API inputs and outputs are not used for model trainingRelied on; a signed DPA is outstanding
Google (OAuth, speech, YouTube, Fonts)Google's controller and processor terms, which include SCCsAccepted through use of the platform; we have not reviewed the sharing scope configured on our OAuth application. Self-hosting the email font would remove the Fonts hop entirely, and we intend to do that
Open-MeteoNo account, no contract. We send venue text and coordinates, never a user identifier or IP addressNo contract in place. We are reviewing whether a free public API is appropriate for production use
OpenStreetMap Foundation, Cloudflare (cdnjs), CloudinaryNo contract. These are requests your own browser makes; each organisation's own privacy notice governs what it does with your IP addressNo contract, and none available. Self-hosting the map pin images would remove the Cloudflare hop entirely, and we intend to do that
GitHub, Microsoft Container Registry, npmVendor termsDeveloper data only; no user data in scope

We have not yet completed the full documented review and transfer risk assessment set that a platform holding children's data should have. That work is underway, it is tracked, and this table is where its progress will show.

Two related points, stated plainly rather than buried:

  • We have not appointed an EU Article 27 representative. Some of our users are in the EU, so this is an outstanding step, not a settled position.
  • We have not appointed a Data Protection Officer. Our assessment is that we sit below the Art. 37 threshold, but the regular-and-systematic-monitoring limb is arguable given the size of our race-results corpus, so we treat it as a judgement rather than a settled answer and review it whenever we materially expand what we collect. The reasoning is in the Privacy Policy and the DPIA. Privacy questions go to [email protected] and reach a person who can act on them.

Changes to this list

This document is versioned. Every version stays published at its own version number, so you can compare what we said on any past date with what we say today.

When a processor is added, removed, or starts handling a materially different kind of data, we publish a new version with a new effective date and a summary of what changed. For an addition that affects personal data, we publish it before data starts flowing, not after. If the change is significant — a new category of data going somewhere new, or a new country — we will also tell account holders by email.

Clubs and coaches who use SailCoach as a processor for their own programmes: this page is your notice of intended changes to subprocessors under Art. 28(2). You have 30 days from a new version's effective date to object.

How to object, and how to complain

Write to [email protected] with the processor and your reason. We will reply within five working days, explain whether the processing can be delivered another way, and say what we will do. If we cannot resolve it and the processor is essential to the service, we will say so rather than leave you waiting — and you can ask us to close your account and to give you a copy of your data. Both are done by hand today; there is no button for either. Your Data Rights explains what to send and what to expect.

You can also complain to us at [email protected], or directly to the Information Commissioner's Office at ico.org.uk/make-a-complaint or 0303 123 1113. You do not have to come to us first.

Innovology Ltd is registered in England and Wales and is the controller responsible for the processors listed here.