Sub-processors
Last updated: 2026-09-02
1. Introduction
In plain terms: these are the outside companies that help us run SearchChamp: our cloud host, our AI model providers, our SEO and AI-answer data source, and our payment processor. We vet each one, bind them to data-protection terms, and tell you before we add a new one. This page also describes two neighbouring categories for full transparency: services you connect to your own account (section 3) and the consent-based analytics and advertising tools on our public website (section 4).
Atlio Limited (“Atlio Limited”), a company registered in New Zealand, uses the sub-processors listed below to deliver the SearchChamp platform. SearchChamp is a product of Atlio Limited. Atlio Limited conducts regional operations in the United Arab Emirates through its branch, Atlio Information Technology LLC. A sub-processor is a third-party company that processes personal data on Atlio Limited’s behalf in the course of providing services to our customers.
This list is maintained in accordance with our Data Processing Addendum and is updated whenever we add, change, or remove a sub-processor. Customers are notified at least 14 days before we add or replace a sub-processor, by email (if opted in) and by update of this page. The general written authorisation in section 5 of the DPA covers the sub-processors in section 2 of this page.
For the purposes of this list:
- SCCs refers to the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module 2: Controller-to-Processor or Module 3: Processor-to-Processor as applicable).
- UK Addendum refers to the International Data Transfer Addendum to the EU SCCs issued by the UK ICO.
- Adequacy decision refers to a European Commission adequacy decision in effect at the time of transfer.
2. Current sub-processors
Last updated: 2026-09-02
Each sub-processor is listed with its purpose, the categories of data it processes, where the processing happens, and the safeguard that covers any international transfer.
Amazon Web Services (AWS)
| Entity | Amazon Web Services, Inc. (US) |
|---|---|
| Purpose | Primary cloud infrastructure: application hosting (Lambda, Amplify), relational database (RDS PostgreSQL), authentication (Cognito), storage (S3, DynamoDB), CDN (CloudFront), secrets management (Secrets Manager), event bus (EventBridge), message queues (SQS), and email delivery (SES) for account and notification emails. Hosts all production data, including our first-party data-collection gateway. |
| Personal data | Account data, usage logs, IP addresses, AI agent outputs, billing records, notification and digest emails |
| Non-personal data | Application code, configuration, anonymised metrics |
| Region | eu-west-1 (Ireland) |
| Transfer mechanism | Adequacy decision (EEA data stays in Ireland). SCCs for any cross-region replication. |
| Privacy policy | aws.amazon.com/privacy |
Anthropic
| Entity | Anthropic PBC (US) |
|---|---|
| Purpose | Claude API: powers AI generation and analysis tasks across SearchChamp’s agents, including the Atlio Agent chat, Content Writer, Brand Voice, llms.txt Generator, Site Auditor suggestions, and backlink outreach drafting. Processes the content and instructions submitted to those jobs. The Claude engine of the AI Visibility feature exists in the platform but is disabled by default for all customers and does not currently run (see the Perplexity and xAI entries for the same status). |
| Personal data | Potentially: content submitted in AI agent prompts, including outreach drafts that may contain contact names and email addresses |
| Non-personal data | Keywords, URLs, SEO instructions |
| Region | United States |
| Transfer mechanism | Anthropic’s data processing terms, which incorporate SCCs (Module 3: Processor-to-Processor). Model inputs are not used to train Anthropic models under its commercial API terms. |
| Privacy policy | anthropic.com/privacy |
OpenAI
| Entity | OpenAI, LLC (US) |
|---|---|
| Purpose | OpenAI API, three uses: (1) text embeddings that power content scoring and internal-link suggestions; (2) optional image generation in the Content Writer where the DALL·E model is selected; (3) on-demand ChatGPT answer checks run from the Atlio Agent chat and Research Studio. Scheduled AI Visibility collection of ChatGPT answers no longer calls OpenAI directly; it is collected through DataForSEO (see that entry). |
| Personal data | Potentially: content submitted for embeddings, image generation, or on-demand answer checks (may include personal data if you submit it) |
| Non-personal data | Keywords, URLs, article text, image briefs |
| Region | United States |
| Transfer mechanism | OpenAI’s data processing terms, which incorporate SCCs (Module 3: Processor-to-Processor). API inputs are not used to train OpenAI models under its API terms. |
| Privacy policy | openai.com/privacy |
OpenRouter
| Entity | OpenRouter, Inc. (US) |
|---|---|
| Purpose | OpenRouter API: routes AI text-generation requests to a fixed allowlist of nine model hosts. Powers Content Writer drafting, polishing, and quality checks, the daily brief, the Atlio Agent chat answer, outreach pitch drafting, and certain other AI tasks. Requests carry data_collection: deny, so no model host is permitted to train on our data. |
| Personal data | Potentially: content submitted in AI generation tasks, chat answers, and outreach drafts (may include personal data if you submit it) |
| Non-personal data | Keywords, URLs, SEO instructions, article and chat text |
| Region | United States (gateway). Routed model hosts operate in the United States (GMICloud, DeepInfra, Fireworks, Parasail, CoreWeave, Novita), China (StreamLake, DeepSeek first-party), and Sweden with a Finland data centre (Inceptron). |
| Transfer mechanism | OpenRouter’s data processing terms, which incorporate SCCs (Module 3: Processor-to-Processor). OpenRouter binds each model host to provider terms under the same data-handling commitments. |
| Privacy policy | openrouter.ai/privacy |
| Entity | Google LLC / Google Ireland Limited |
|---|---|
| Purpose | Two uses as our sub-processor: (1) the Gemini generative API, which powers the Atlio Agent chat where the Gemini model is selected, default hero-image generation in the Content Writer, and on-demand Gemini answer checks; (2) Google reCAPTCHA, which protects our free public tools against automated abuse. Scheduled AI Visibility collection of Gemini answers and of Google AI Overviews and AI Mode results is collected through DataForSEO (see that entry). Integrations you connect yourself (Search Console, Analytics, Ads, Gmail) are described in section 3. |
| Personal data | Potentially: content submitted to Gemini tasks; for reCAPTCHA, device and usage signals including the IP address of free-tool visitors |
| Non-personal data | Keywords, URLs, image briefs, chat text |
| Region | Global (Google data centres) |
| Transfer mechanism | SCCs (Module 3: Processor-to-Processor) and Google’s Data Processing Terms for EEA/UK customers. Gemini API inputs are not used to train Google models under its paid API terms. |
| Privacy policy | policies.google.com/privacy |
DataForSEO
| Entity | DataForSEO OÜ (Estonia, reg. 14502291) |
|---|---|
| Purpose | SEO and AI-answer data: provides keyword volume, SERP, backlink, rank-tracking, and site-audit data. It is also the collection surface for the AI Visibility feature’s engines: ChatGPT and Gemini answers are collected through its AI endpoints, Google AI Overviews and Google AI Mode results through its SERP endpoints, and the Microsoft Copilot surface is measured from Bing search results it supplies. |
| Personal data | None intended: queries are limited to keywords, URLs, domain names, and the AI prompts you configure; any incidental personal data you place in those values remains protected under EU law (intra-EU processing) |
| Non-personal data | Keywords, URLs, domain names, AI prompt text, engine answers, SERP and backlink data |
| Region | Estonia (EU) |
| Transfer mechanism | Intra-EU processing (no third-country transfer mechanism required). |
| Privacy policy | dataforseo.com/privacy-policy |
Stripe
| Entity | Stripe, Inc. (US) and its affiliates |
|---|---|
| Purpose | Payment processing: handles all subscription billing, payment-method storage, invoicing, and refunds. Checkout and billing management run on pages hosted by Stripe; we do not load Stripe scripts on our own domain, and full card numbers never reach SearchChamp servers. |
| Personal data | Name, email, billing address, payment card data (full card numbers never reach SearchChamp servers) |
| Non-personal data | Subscription plan identifiers, payment amounts |
| Region | United States / Global |
| Transfer mechanism | SCCs (Module 2: Controller-to-Processor) for EEA/UK customers. UK Addendum where applicable. Stripe is PCI-DSS Level 1 certified. |
| Privacy policy | stripe.com/privacy |
AWS Cognito (service detail)
| Entity | Amazon Web Services, Inc. (US) |
|---|---|
| Purpose | Identity and access management: stores user accounts, hashed passwords, MFA configuration, and remembered-device identifiers, and issues the tokens that keep you signed in. Used for authentication and authorisation. |
| Personal data | Email address, hashed password, MFA settings, remembered-device identifiers |
| Non-personal data | Token configuration |
| Region | eu-west-1 (Ireland) |
| Transfer mechanism | Adequacy decision (EEA data stays in Ireland). Included in the AWS DPA. |
| Privacy policy | aws.amazon.com/privacy |
Perplexity (engaged, currently inactive)
| Entity | Perplexity AI, Inc. (US) |
|---|---|
| Purpose | Perplexity API: the Perplexity engine of the AI Visibility feature. The integration is built and the vendor relationship is in place, but the engine is disabled by default for all customers and is not currently processing customer data. If it is enabled as part of a future plan or add-on, this page will be updated first. |
| Personal data | None currently (engine disabled by default; no customer data is sent while disabled) |
| Non-personal data | None currently |
| Region | United States |
| Transfer mechanism | Perplexity’s data processing terms; transfers safeguarded as described in section 8 of our DPA. |
| Privacy policy | perplexity.ai/privacy |
xAI (engaged, currently inactive)
| Entity | xAI Corp. (US) |
|---|---|
| Purpose | xAI (Grok) API: the Grok engine of the AI Visibility feature. The integration is built and the vendor relationship is in place, but the engine is disabled by default for all customers and is not currently processing customer data. If it is enabled as part of a future plan or add-on, this page will be updated first. |
| Personal data | None currently (engine disabled by default; no customer data is sent while disabled) |
| Non-personal data | None currently |
| Region | United States |
| Transfer mechanism | xAI’s data processing terms; transfers safeguarded as described in section 8 of our DPA. |
| Privacy policy | x.ai/privacy |
3. Connected services you control
In plain terms: some features work by connecting SearchChamp to accounts you already hold with other companies. You choose whether to connect them, we access them only to do what the feature says, and you can disconnect them at any time. These companies serve you under your own agreement with them; they are not our sub-processors, and we list them here so the full picture of data movement is in one place.
- Google integrations: Google Search Console (search query and click data, read-only), Google Analytics 4 (audience and traffic metrics, read-only), and Google Ads (campaign and keyword data; we read this data and do not create or change campaigns). Each is connected via OAuth consent that you grant and can revoke at any time, in SearchChamp or in your Google account settings.
- Email sending for backlink outreach: you can connect a Gmail or Microsoft Outlook mailbox. SearchChamp uses it to send the outreach emails you approve and to read delivery signals such as bounces and replies to those emails. Sending happens from your own mailbox under your own Google or Microsoft account; access tokens are stored encrypted and the connection can be removed at any time.
- Publishing platforms: when you connect a site, SearchChamp publishes and updates content on it at your instruction. Supported platforms include WordPress, Shopify, Wix, Squarespace, Webflow, Ghost, BigCommerce, HubSpot, Duda, HighLevel, Salla, and custom webhooks you configure.
- Notification destinations: you can route SearchChamp notifications to tools you use, such as a Slack workspace or Linear. We send the notification content you configure to the destination you chose; the tokens involved are stored encrypted.
Data sent to or read from a connected service is processed by that provider under its own terms and privacy policy. If we ever engage one of these companies to process personal data on our behalf, rather than at your instruction, it will be added to section 2 first.
4. Analytics and advertising recipients on our website
In plain terms: our public marketing pages use consent-based analytics and advertising tags. They are off by default in every region and stay off until you accept them in our consent banner. The signed-in product contains no advertising or analytics tags at all.
When you grant consent on our public website, the following companies receive the data their tags collect, acting under their own terms: Google (Analytics with Analytics consent; Ads with Marketing consent), Microsoft (Advertising and Clarity, Marketing consent), Meta (Marketing consent), and TikTok (Marketing consent). The cookies involved, their lifetimes, and how to withdraw consent are documented in our Cookie Policy.
If you subscribe to a paid plan while holding an active Marketing grant, we also send a server-side conversion event to Meta and TikTok so the sale is attributed to the ad that led to it. That event contains a SHA-256 hash of the subscribing administrator’s email address and a billing event identifier used for de-duplication; it is sent only where the Marketing grant was given and never otherwise.
These companies are recipients rather than sub-processors: they do not process customer workspace data, and nothing from your signed-in SearchChamp account is shared with them beyond the conversion event described above.
5. Changes to this list
Atlio Limited will update this page whenever a sub-processor is added, changed, or removed. The addition or replacement of a sub-processor will be communicated to customers at least 14 days in advance, consistent with section 5 of our Data Processing Addendum.
Notification methods:
- Email to the primary account holder (for customers who have opted in to sub-processor notifications);
- Update of this page with a revised “last updated” date.
Customers may object to a new sub-processor as described in section 5 of the Data Processing Addendum.
Change history
| Date | Change |
|---|---|
| 2026-09-02 | Disclosure revision, verified against the deployed platform. Documented that scheduled AI Visibility collection of ChatGPT and Gemini answers, Google AI Overviews, Google AI Mode, and the Microsoft Copilot surface now runs through DataForSEO rather than the direct OpenAI and Google APIs. Recorded that the Claude, Perplexity, and Grok engines are disabled by default for all customers (Anthropic remains active for AI agent tasks; the Perplexity and xAI entries are marked engaged but inactive). Clarified OpenAI’s continuing uses: embeddings, optional image generation, and on-demand answer checks. Added section 3 (connected services under your control: Google integrations, Gmail and Microsoft Outlook outreach mailboxes, publishing platforms, Slack and Linear notification destinations) and section 4 (consent-based website analytics and advertising recipients, including the hashed-email conversion event to Meta and TikTok), and disclosed Google reCAPTCHA on the free public tools. No new sub-processor was engaged and no new processing was introduced. |
| 2026-08-14 | Completed the Bedrock to OpenRouter migration: AWS Bedrock is removed as an inference sub-processor and the LLM text paths it served now route through the already-declared OpenRouter allowlist. Image generation uses the Google Gemini API (declared under the Google entry). No new sub-processor was added. |
| 2026-08-13 | Added OpenRouter and its nine routed model hosts (GMICloud, DeepInfra, Fireworks, Parasail, CoreWeave, and Novita in the US; StreamLake and DeepSeek first-party in China; Inceptron in Sweden with a Finland data centre) as sub-processors for certain AI agent tasks and the Atlio Agent chat answer. All requests carry data_collection: deny (no model training on customer data). |
| 2026-07-02 | Disclosure correction: added Perplexity and xAI (AI Visibility engines in use since the feature launched) and documented Google’s Gemini API use; corrected DataForSEO’s legal entity to DataForSEO OÜ (Estonia); clarified AI-provider retention terms and the AWS service list. No new processing was introduced. |
| 2026-05-11 | Initial publication of sub-processor list. |
6. Contact
To opt in to sub-processor change notifications, or for questions about our sub-processors:
Atlio Limited (New Zealand)UAE branch: Atlio Information Technology LLC, Dubai, United Arab Emirates
Email: legal@searchchamp.com