checkmAIt Platform data register · Sept 2026
Client information sheet

Where your data goes, and who protects it

Every system we build for you runs on established platforms that each publish their own GDPR commitments, audits and data agreements. This sheet lists them all in one place, with links to the source documents, so you can check any of it yourself or pass it to your own advisers.

Three parties, three roles

Under GDPR the business collecting the data decides why it is used. checkmAIt builds and operates the system on your instructions. The platforms below store and process the data under contracts they publish and are audited against. Each layer is accountable for its own part.

Controller You

You own the relationship with your customers and decide what data is collected and why.

Processor checkmAIt

We design, build and run the system to your brief. We only touch data to deliver the service and we choose vetted platforms to run it on.

Sub-processors The platforms

Hosting, AI models, telephony and CRM vendors. Each one signs GDPR terms, publishes its audits and lists its own suppliers.

The full stack in one table

DPA is the Data Processing Agreement, the GDPR contract each platform gives its customers. DPF is the EU-US Data Privacy Framework, the approved route for moving EU and UK data to the US. SCCs are Standard Contractual Clauses, the EU's model contract that does the same job. SOC 2 and ISO 27001 are independent security audits.

PlatformWhat it doesDPATransfer basisSOC 2ISO 27001EU hosting
AnthropicClaude AI modelsIn termsSCCsYesYesVia AWS / Google EU
Retell AIVoice agent engineSigned onlineSCCsYesYesUS only
TwilioPhone numbers, callsIn termsDPF + SCCsYesYesIreland
ElevenLabsVoice synthesisIn termsDPF + SCCsYesYesEnterprise only
RailwayApp hostingSigned onlineDPF + SCCsYesNoAmsterdam
VercelWeb hostingIn termsDPF + SCCsYesYes5 EU regions
SupabaseDatabase and loginsIn termsSCCsYesYes6 EU regions
GitHubCode storageIn termsDPF + SCCsYesYesEnterprise only
GoHighLevelCRMIn termsDPF + SCCsYesYesUS only
GoogleGmail, Calendar, MapsIn termsDPF + SCCsYesYesEnterprise only
StripePaymentsIn termsDPF + SCCsYesPCI Level 1Irish entity
SlackAlerts and notificationsSigned onlineDPF + SCCsYesYesBusiness+ only
CalendlyBooking linksIn termsDPF + SCCsYesYesUS only
FathomMeeting notesIn termsDPF + SCCsYesNoUS only

"In terms" means the DPA applies automatically when the platform's standard terms are accepted. "Signed online" means we execute it through the platform's own portal. Reviewed 6 September 2026 against each vendor's live pages. The vendor's own documents take precedence over this summary.

Anthropic (Claude)

Reads, drafts, classifies

Claude is the model behind the reasoning in our systems: reading enquiries, drafting replies, summarising calls. Anthropic's commercial terms include a GDPR data processing agreement with EU Standard Contractual Clauses, so nothing extra needs signing. It holds SOC 2 Type II, ISO 27001 and ISO 42001, the standard for AI management systems.

Anthropic does not train its models on anything sent through the API. That is a contractual commitment in its commercial terms, not a setting. Its own API processes data in the US. Where a client needs data to stay physically inside the EU, the same Claude models run through AWS Bedrock or Google Vertex AI in Frankfurt, Ireland, Paris or Stockholm.

DPAIn commercial terms
Transfer basisSCCs + UK Addendum
AuditsSOC 2 II · ISO 27001 · ISO 42001
Data locationUS, or EU via AWS / Google

Retell AI

Runs the conversation

Retell is the engine that answers and holds the call: it listens, thinks and speaks in real time. It is SOC 2 Type II and HIPAA audited, and offers a GDPR data processing agreement with Standard Contractual Clauses through its online signing portal, which we execute for every voice-agent account.

Recordings and transcripts are stored in the US; Retell does not currently offer EU hosting. We reduce what is held there with two per-agent controls: personal-data redaction, which strips names, numbers and addresses from stored transcripts, and an automatic deletion window so recordings are purged on a schedule rather than kept indefinitely.

DPASigned via portal
Transfer basisSCCs + UK IDTA
AuditsSOC 2 I & II · HIPAA · ISO 27001
Data locationUS (AWS), redaction + auto-delete

Twilio

Phone numbers and call routing

Twilio provides the phone numbers and carries the calls to and from the voice agent. It is one of the most thoroughly certified vendors in this list: EU-US Data Privacy Framework, Binding Corporate Rules, ISO 27001, 27017 and 27018, SOC 2 Type II and PCI DSS Level 1. Its data processing agreement has been part of its standard terms since 2020.

Twilio offers an Ireland region so that call records and recordings can be kept inside the EU. Twilio does not delete recordings on its own, so we set a retention routine on each account rather than leave recordings to accumulate.

DPAIn terms of service
Transfer basisDPF · BCRs · SCCs
AuditsSOC 2 II · ISO 27001/17/18 · PCI L1
Data locationUS or Ireland (IE1)

ElevenLabs

The voice itself

ElevenLabs generates the natural-sounding voice the agent speaks with. Its EU data controller is based in Warsaw, it is certified under the EU-US Data Privacy Framework, and its data processing agreement with Standard Contractual Clauses applies automatically to business accounts. It holds SOC 2 Type II, ISO 27001 and PCI DSS Level 1.

On standard plans ElevenLabs may use content to improve its models unless the "Data use" setting is switched off. We turn it off when an account is created. EU-only storage and zero-retention mode exist on Enterprise contracts if a project calls for them.

DPAIn terms (business accounts)
Transfer basisDPF + SCCs
AuditsSOC 2 II · ISO 27001 · PCI L1
Data locationUS; EU on Enterprise

Railway

Runs dashboards and back-end services

Railway hosts the servers and dashboards we build. It is SOC 2 Type II audited and certified under the EU-US Data Privacy Framework, with a data processing agreement that includes Standard Contractual Clauses. Railway's DPA is executed through its online form rather than applying automatically, and we complete that for our account.

Railway has an Amsterdam region, so a client's application and its stored data can be deployed to sit inside the EU.

DPASigned via online form
Transfer basisDPF + SCCs
AuditsSOC 2 II · SOC 3 · HIPAA
Data locationUS or Amsterdam

Vercel

Hosts websites and web apps

Vercel hosts the public-facing websites and some web applications. It holds SOC 2 Type II, ISO 27001 and PCI DSS, is certified under the EU-US Data Privacy Framework, and its data processing agreement applies automatically on acceptance of its terms.

Server code can run in Dublin, London, Paris, Frankfurt or Stockholm. The default is a US region, so we set the EU region deliberately on projects that need it.

DPAIn terms
Transfer basisDPF + SCCs
AuditsSOC 2 II · ISO 27001 · PCI DSS
Data locationUS default; 5 EU regions

Supabase

Database and user logins

Supabase provides the database and login system behind our web applications. It is SOC 2 Type II and ISO 27001 certified, and its data processing agreement with Standard Contractual Clauses applies automatically on acceptance of its terms. A countersigned copy is available on request.

Each project is pinned to one data centre, and Supabase offers six in Europe including Ireland, London, Frankfurt and Zurich. This is a genuine data-location control: the database itself does not leave the chosen region.

DPAIn terms
Transfer basisSCCs + UK Addendum
AuditsSOC 2 II · ISO 27001 · HIPAA
Data locationPinned; 6 EU regions

GitHub

Stores the code

GitHub, owned by Microsoft, stores the source code of what we build and deploys updates. It holds SOC 2 Type II and ISO 27001, is certified under the EU-US Data Privacy Framework, and its data protection agreement is built into its standard customer terms.

GitHub holds code, not customer records. Client data such as contact details, call recordings or CRM entries is never committed to a repository; it lives in the database, CRM and voice platforms listed elsewhere on this sheet.

DPAIn customer terms
Transfer basisDPF + SCCs
AuditsSOC 2 II · ISO 27001 · CSA STAR
Data locationUS; code only

GoHighLevel

CRM and pipeline

GoHighLevel is the CRM that voice agents and outbound systems write leads and call outcomes into. It is certified under the EU-US Data Privacy Framework, backs that with Standard Contractual Clauses in its data processing agreement, and holds SOC 2 Type II and ISO 27001. The DPA applies automatically with the terms of service, and a copy can be downloaded from the account's compliance settings.

Data is hosted in the US with support teams in India; there is no EU hosting option.

DPAIn terms; copy in-app
Transfer basisDPF + SCCs
AuditsSOC 2 II · ISO 27001
Data locationUS only

Google

Gmail, Calendar and Maps

Our systems connect to Google in two ways. Gmail and Calendar are Google Workspace services: Google acts as a processor under its Cloud Data Processing Addendum, which applies automatically, and both services are inside Google's SOC 2 and ISO 27001 scope. Google is certified under the EU-US Data Privacy Framework and can pin Workspace data to EU data centres on Enterprise plans.

Google Maps is used only to look up public business listings. For that service Google acts as an independent controller under separate Controller terms rather than as our processor. Any of our software that reads a client's Gmail or Calendar is also bound by Google's own API user-data policy, which limits use to the feature the client authorised.

DPAIn terms (Cloud DPA)
Transfer basisDPF + SCCs
AuditsSOC 1/2/3 · ISO 27001/17/18/701
Data locationGlobal; EU on Enterprise

Stripe

Payments

Where a build takes payments, Stripe handles them. Card details never touch our systems. Stripe is the most regulated vendor here: PCI DSS Service Provider Level 1, SOC 1 and SOC 2 Type II, certified under the EU-US Data Privacy Framework with Standard Contractual Clauses as a fallback. Its data processing agreement is part of its standard services agreement.

UK and EU businesses contract with Stripe Payments Europe Ltd in Ireland as the regulated entity.

DPAIn services agreement
Transfer basisDPF + SCCs
AuditsPCI L1 · SOC 1 · SOC 2 II
Data locationGlobal; Irish entity for UK/EU

These are tools checkmAIt uses to run the engagement rather than parts of the system we hand over. They are listed because they can touch your name, email and meeting content.

Slack

Alerts and internal notifications

Slack, owned by Salesforce, receives alerts from our systems: a new booking, a missed call, a follow-up due. It is covered by the EU-US Data Privacy Framework, offers Standard Contractual Clauses to every customer, and holds SOC 2 Type II, ISO 27001 and ISO 42001. Its data processing agreement is a separate document executed online, which we complete for our workspace.

DPASigned online
Transfer basisDPF + SCCs
AuditsSOC 2 II · ISO 27001 · ISO 42001
Data locationUS; EU on Business+

Calendly

Booking links

Calendly runs the links people use to book calls with us and, in some builds, with you. Its data processing agreement applies automatically on acceptance of its terms, it is certified under the EU-US Data Privacy Framework with Standard Contractual Clauses as a backstop, and it holds SOC 2 Type II and ISO 27001. Booking data is stored in the US.

DPAIn terms
Transfer basisDPF + SCCs
AuditsSOC 2 II · ISO 27001 · CSA STAR
Data locationUS

Fathom

Meeting recording and notes

Fathom records and transcribes our video calls so that requirements are captured accurately. It is certified under the EU-US Data Privacy Framework with Standard Contractual Clauses as a fallback, holds SOC 2 Type II and HIPAA, and its data processing agreement is incorporated into its terms. Recordings are stored in the US and summarised by AI providers that are contractually barred from training on the content.

Because it records, we tell everyone on a call that Fathom is running and stop it on request.

DPAIn terms
Transfer basisDPF + SCCs
AuditsSOC 2 II · HIPAA
Data locationUS

What we do on every build

How we handle your data

The platforms above cover the infrastructure. This section covers checkmAIt itself: what we do with data that reaches us while building and running your system, and what you can hold us to.

Questions or requests about data: joe@thecheckmait.com. If you believe we have mishandled personal data you can also complain to your local data protection authority. In the UK that is the Information Commissioner's Office.

Questions

Need something specific?

If your compliance team wants a particular audit report, a countersigned DPA from any platform, or a build scoped to EU-only hosting, tell us what they need and we will arrange it with the vendor.

checkmAIt · Every move, considered. thecheckmait.com