Subprocessors

Last updated: 8 August 2026


1. What this page is

Running Energicore means relying on a small number of specialist providers for things like hosting, payments and error monitoring. Where one of those providers handles personal data on our behalf, they are a subprocessor. This page names all of them.

We publish it for two reasons. Organisations that use Energicore to serve their own residents or clients are the data controller for that information, and we act as their processor. Under UK GDPR Article 28 they are entitled to know who else is involved, and to object before anything changes. Everyone else simply deserves a straight answer about where their information goes.


2. Platform subprocessors

These providers process data belonging to people and organisations using the platform.

Subprocessors that process platform user and organisation data
SubprocessorWhat they do for usWhere processing happens
Amazon Web Services (AWS)Application hosting, database, caching, file storage, content delivery, transactional email, and the AI models behind the in-product assistant.United Kingdom (London) for hosting and storage; Ireland for AI inference, restricted to EU-only inference profiles.
Microsoft AzureConverts knowledgebase search queries into vector embeddings so the assistant can retrieve relevant guidance.European Union
StripeSubscription billing and payment processing for organisational customers. Card details are entered directly with Stripe and never reach Energicore's systems.European Union and United States
PostHogProduct analytics used to understand how the platform is used and where it fails people.European Union
SentryError and performance monitoring, so faults are caught and diagnosed.European Union (Germany)
Ideal PostcodesUK address and postcode lookup, used to identify a property accurately at the point of entry.United Kingdom
Google AnalyticsWebsite analytics on our public pages. Loaded only after a visitor gives analytics consent, and never on signed-in property pages.United States

Property records, account details and everything you enter about your home are processed only in the United Kingdom or the European Economic Area. Neither of the two providers above that operate outside the EEA touches that data: Stripe handles billing for organisational customers on global payment infrastructure, and Google Analytics runs on our public marketing pages only, after consent, and never where a property or a person is identified. Both transfers are covered by appropriate safeguards, described below.


3. Corporate and internal systems

These providers are not part of the platform. They process data because our own team uses them to build and run the service.

Providers used internally by the Energicore team
SubprocessorWhat they do for usWhere processing happens
AnthropicClaude is used across the business for software engineering, analysis and internal tooling. Where that work touches production or development systems, it may incidentally process personal data held there.United States and European Union

4. Who is not a subprocessor

Some names you might expect to find here are deliberately absent, because they never receive your data.

  • AI model providers: The assistant is powered by Claude models, and knowledgebase search uses OpenAI embedding models. In both cases we reach those models through AWS and Microsoft respectively, and neither Anthropic nor OpenAI receives the data we send. AWS and Microsoft are the subprocessors; the model developers license the technology and see nothing.
  • Sign-in providers: You can sign in with a Google, Microsoft or Facebook account. When you do, that provider confirms your identity to us. They act as an independent controller for your account with them, and we do not send them your property or platform data.
  • Official data sources: Energicore reads from the UK Government EPC register and published grant scheme criteria. These are sources we retrieve from, not recipients we disclose to.

5. How subprocessors are governed

Every subprocessor listed here is engaged under a written contract imposing data protection obligations no weaker than the ones we owe our own customers, as required by UK GDPR Article 28(4). We assess each one before engaging them, and we only share the minimum data needed for the purpose described in the table.

Where a provider processes data outside the UK or EEA, that transfer is covered by an approved safeguard such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.


6. Changes to this list

Before a new subprocessor begins processing data belonging to an organisational customer, we will update this page and give at least 30 days' notice. Organisational customers with a signed Data Processing Agreement are notified directly by email. Anyone else who would like to be told about changes as they happen, rather than checking back, can write to hello@energicore.app and ask to be added to the notification list.

Organisational customers may object to a proposed subprocessor on reasonable data protection grounds within that period, by writing to the same address. We will work with you to resolve the objection, and we will not route your data to the proposed subprocessor while your objection is open. If we cannot resolve it together, you may terminate the affected services without penalty.

Exceptionally, where replacing a subprocessor is urgently necessary to maintain the security or availability of the service, we may engage the replacement immediately. We will update this page and notify customers without undue delay, and the right to object then applies from the date of that notice, on the same terms as above. The location commitments in section 2 hold even in that situation.


7. Related documents and contact

How we handle personal data generally is set out in our Privacy Policy. Our technical and organisational safeguards, and how to request a Data Processing Agreement, are covered on our Security and Compliance page.

For questions about anything on this page, contact us at hello@energicore.app.