Sub-processors

Sub-processors and third-party recipients

Every third party that receives data through Joulely. Compiled by reading the code and the running production configuration. “Sub-processor” is used in its Article 28 sense: a third party that processes personal data on our behalf. Recipients that are not sub-processors in that strict sense are separated out and labelled, because a Data Protection Officer would rather see them classified here than find them in a network trace.

Partners get at least 30 days' written notice before a sub-processor that touches their data is added or replaced, with a 14-day right to object on reasonable documented data-protection grounds. That is a clause in the data processing agreement.

Sub-processors that process partner or customer personal data

  • Hetzner Online GmbH — hosting. Sees everything we hold, at rest. The sensitive core is encrypted in the application before it reaches storage. Application and database in Nuremberg, Germany. Offsite backup copy in Falkenstein, Germany. Both verified against the hosts themselves.
  • Hildebrand Technology Ltd, trading as Glowmarkt — smart-meter data. Retrieves consumption data from the DCC. Sees the MPAN or MPRN, the half-hourly electricity, gas and export consumption, and the access token issued for that meter point. United Kingdom, UK-only hosting under our agreement with them.
  • Stripe — payments. Subscription billing for our own consumers and metered billing for business partners. Sees the billing email address, subscription and customer identifiers, and the payment details the customer enters directly with Stripe. Card details are never handled by, or transmitted through, our systems. The contracting entity and processing regions are the ones in Stripe's own data processing agreement, which governs them.
  • Resend — transactional email. Sign-in codes, magic links, service notifications, operational alerts and newsletters. Sees the recipient email address and the full content of the message, which for a sign-in email includes the one-time code. The contracting entity and processing region are the ones in Resend's own data processing agreement, which governs them.
  • Which of those touch a partner's customers. Hetzner, for hosting, and Hildebrand where the partner uses our meter connection rather than supplying its own data. Stripe and Resend handle our own billing and our own users, not the partner's customers. The binding version of this is an annex to the data processing agreement.

Sources we query, which process nothing for us

Not sub-processors: they do no processing on our behalf and hold nothing for us. Listed because a lookup does send them something.

  • postcodes.io. Resolves a postcode to a grid-supply region, local authority and coordinates. Outward code only for the grid-region lookup. Full postcode for the property-level lookups behind some estimates.
  • EPC Open Data. Energy Performance Certificate lookup. Receives a postcode or address.
  • National Grid carbon intensity API. Region identifier only. No personal data.
  • Octopus Energy public API, supplier websites, Ofgem and public price sources. Outbound reads of published tariff data. Nothing is sent.
  • police.uk and HM Land Registry open data. Area context for the local-area feature. Receives a postcode or area identifier.

Loaded into the visitor's browser

This is the section a Data Protection Officer usually finds in a network trace after a vendor has failed to mention it, so here it is in full. Nothing loads from anywhere but this domain. No analytics beacon, no tag manager, no font CDN, no pixel, no error-reporting service, no content delivery network. Loading any page on this site contacts joulely.co.uk and nothing else, so no other party — ours or anybody else’s — sees a visitor’s IP address or user-agent. This is checked on every deploy against the rendered pages, not against a list somebody maintains by hand.

Until 13 August 2026 that was not true. Every page carried a cookieless analytics beacon from tally.arx52.co.uk, a host we run ourselves, which received the page address, the IP address and the user-agent. It was removed once our own analytics replaced what it was for. It is recorded here because it was live, and because it was injected in a way that made it invisible to anything except a real network trace.

Web fonts used to be the exception, and are not any more. Until 2026-08-13 Fraunces and Inter were loaded from Google's CDN, so Google received the IP address and user-agent of every visitor to every page. The files are now served from this domain, so that recipient no longer exists.

Nothing else is loaded from anywhere. No Sentry, no Cloudflare, no Google Analytics, no Plausible, no third-party analytics service, no advertising or marketing pixel, no CDN and no remote stylesheet, script, image or font. Product analytics inside the application are first-party, stored in our own database, region-level, with no IP address column and a pseudonymous identifier.

Distribution and the app platform

  • Google Play. Distributes the Android app and reports aggregate install and crash metrics. Play's own relationship with the user is governed by Google's terms, not ours.
  • Expo push notifications. Would deliver the device push token and the text of a notification, composed from that household's own figures. Currently disabled: sending needs an environment flag that is not set in production.

Deliberately absent

  • Bill images have no third party at all. Optical character recognition runs on infrastructure we operate: a local model on the application host and a second server of ours at the same hosting provider. No bill image is sent to any third-party API. Image bytes are held in memory, never written to disk and never logged.
  • No AI or large language model provider processes customer or partner data. An external model provider exists in the code as a non-default fallback for bill reading that has to be selected explicitly. It is not selected in production. If a feature is ever introduced that would send data to a model provider, that is a new sub-processor and it gets the 30 days' notice and the objection right.
  • No data broker, no data sale, no advertising network. We do not sell, rent or share personal data for anyone's marketing, and we take £0 commission from any energy supplier on any switch or placement.
  • n3rgy is in the code and is not in use. A second meter-data adapter exists so we are not locked to one provider. It is not the configured source in production. Activating it for a partner's customers would make it a new sub-processor requiring notice.

Limits of this list

  • Hildebrand's own sub-processors are not listed. Our agreement with them contains no sub-processor clause, so it gives us no contractual right to obtain that list or to flow obligations down to it. We will not warrant a chain we cannot compel disclosure of. We will use reasonable endeavours to obtain that right at the next renewal or amendment and will tell partners if we do. The limitation is written into the data processing agreement rather than smoothed over, because promising a complete chain would be a warranty breached on day one.
  • Two processing regions are outstanding. The contracting entity and processing region for Stripe and for Resend are the ones in their own data processing agreements. We have not transcribed them onto this page. The row stays open until it can be read off the governing document rather than assumed from where each company is best known.
  • The data centre of our second bill-reading server. It is at the same hosting provider, verified by reverse DNS. The specific data centre has not been checked. It processes bill images in memory only and stores nothing, and the region still belongs on this list.
  • The analytics host is listed as ours on the basis that we run it. Whether it sits inside the same legal entity, and therefore whether it is an internal system or a separate controller to be named, is being confirmed. It is described above either way, because a browser contacts it either way, and that is the part a network trace shows.

Version 2026-08-13. Questions about this list, or notice of objection to a change, to business@joulely.co.uk. Where this page and the annex to the executed data processing agreement differ, the executed annex governs the contract.

Trust pack · Security · Service levels · Data processing agreement

Joulely

Your home bills, checked on your own numbers — £0 commission on any switch.

Check your home · Check your energy bill (free) · Council tax check · Guides

About · For business · Who we support · Privacy & your data · Terms · Tariff data & supplier corrections