Important
Processor and subprocessor arrangements are service-specific. This page gives the Group framework without falsely implying that every supplier is used by every subsidiary or product.
Scope
This page provides group-level information about how The Raeburn Holding Group Limited and relevant Raeburn Group companies use service providers to process personal data.
It does not replace a Data Processing Agreement (DPA), service-specific privacy notice or product-specific subprocessor list where one is required. The contract issued by the relevant Group company determines the parties’ roles for a particular service.
Controller and processor roles
A Group company may act as a controller where it decides why and how personal data is used, and as a processor where it handles customer personal data only on documented instructions. The same company can have different roles for different processing activities.
Where a Group company acts as a processor, its obligations should be set out in the applicable contract or DPA in accordance with Article 28 UK GDPR where required.
Types of service provider
- cloud hosting, storage and database providers;
- communications, email and messaging providers;
- payment and financial-technology providers;
- identity, authentication, security and fraud-prevention providers;
- CRM, support, analytics and operational software providers;
- AI, machine-learning and automation providers where authorised for the relevant use; and
- professional advisers and specialist contractors where necessary.
Supplier selection and contracts
We seek to use suppliers that are appropriate to the nature and risk of the processing. Depending on the service, this can include review of security controls, privacy terms, hosting locations, certifications, data-retention controls and incident procedures.
Where a supplier processes personal data on our behalf, we use contractual terms intended to address confidentiality, security, subprocessing, assistance with rights, deletion or return of data, and breach notification as required by applicable law.
Subprocessors
Some customer-facing services may depend on subprocessors. Where a service contract requires a named subprocessor list or advance notice of changes, the relevant Group company will provide that information through the contract, product documentation, trust site or another designated mechanism.
We do not publish a generic provider as a subprocessor for every Group company merely because one business in the Group uses that provider. Subprocessor status depends on the specific service and data flow.
International transfers
Where personal data is transferred outside the United Kingdom and UK transfer restrictions apply, we use an available legal mechanism such as UK adequacy regulations, the International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, or another recognised safeguard.
Additional technical or organisational measures may be applied where appropriate to the transfer risk.
Customer responsibilities
Customers remain responsible for ensuring they have a lawful basis and appropriate authority for personal data they instruct a Group company to process. Customers should not provide data that the relevant contract does not permit or that is unnecessary for the service.
Where a customer is a controller and a Group company is its processor, the customer remains responsible for its own controller obligations, including transparency, lawful basis and responding to data-subject rights except to the extent the processor is contractually required to assist.
Security and incidents
Security controls are risk-based and vary by product. Group-level security information is available through our Trust & Security site. Where a Group company acts as processor, qualifying personal-data incidents are handled under the notification obligations in the applicable DPA or service contract.
Data subject requests
If you are an individual seeking to exercise privacy rights, use the route in our Privacy Policy. If your data was provided to us by one of our customers and we act only as that customer’s processor, we may need to refer the request to the customer as controller.
Commercial and privacy enquiries
Questions about DPAs, subprocessors or data-processing terms can be sent to contact@theraeburngroup.com.