Supplier and Subprocessor Schedule
Updated 11 September 2026
This Schedule identifies suppliers that may process personal data in connection with Tarlara services. A supplier is a Subprocessor where it processes Customer Personal Data for Tarlara while Tarlara acts as Processor.
| Provider and status | Purpose and information | Processing location and safeguard |
|---|---|---|
| Supabase — current | Database, authentication and file storage. Account information, Customer records and uploaded files. | Primary Customer Data environment is configured in the EEA. |
| Cloudflare — current | Application delivery, security and storage. Network and security information and protected stored data. | Global service. |
| OpenAI API — current where AI is used | AI-assisted functionality. Information submitted for the requested AI task and generated output. | Processing outside the UK may occur. |
| GitHub Actions — current | Automated operational workflows. Information processed temporarily by an enabled workflow. | Hosted processing location may vary. |
| Microsoft 365 — current | Business, support, privacy and legal communications. Contact details, correspondence and attachments. | |
| Stripe — current | Payment processing. Billing contact, transaction and payment information. Stripe may act independently for regulated and fraud-prevention purposes. |
International transfers
Where a restricted transfer occurs, Tarlara uses an appropriate mechanism such as UK adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses. Further information or a copy of the applicable safeguard can be requested from privacy@tarlaradigital.com.
Changes
Tarlara maintains this Schedule as relevant providers change and follows the notice and objection procedure in the Data Processing Agreement.