★ Sub-processors
Sub-processors and third-party recipients
Every third party that receives data through Joulely. Compiled by reading the code
and the running production configuration. “Sub-processor” is used in its Article 28
sense: a third party that processes personal data on our behalf. Recipients that are not
sub-processors in that strict sense are separated out and labelled, because a Data Protection
Officer would rather see them classified here than find them in a network trace.
Partners get at least 30 days' written notice before a sub-processor that touches
their data is added or replaced, with a 14-day right to object on reasonable documented
data-protection grounds. That is a clause in the data processing
agreement.
Sub-processors that process partner or customer personal data
- Hetzner Online GmbH — hosting. Sees everything we hold, at rest. The
sensitive core is encrypted in the application before it reaches storage. Application and
database in Nuremberg, Germany. Offsite backup copy in Falkenstein, Germany. Both verified
against the hosts themselves.
- Hildebrand Technology Ltd, trading as Glowmarkt — smart-meter data.
Retrieves consumption data from the DCC. Sees the MPAN or MPRN, the half-hourly
electricity, gas and export consumption, and the access token issued for that meter point.
United Kingdom, UK-only hosting under our agreement with them.
- Stripe — payments. Subscription billing for our own consumers and
metered billing for business partners. Sees the billing email address, subscription and
customer identifiers, and the payment details the customer enters directly with Stripe. Card
details are never handled by, or transmitted through, our systems. The contracting entity and
processing regions are the ones in Stripe's own data processing agreement, which governs
them.
- Resend — transactional email. Sign-in codes, magic links, service
notifications, operational alerts and newsletters. Sees the recipient email address and the
full content of the message, which for a sign-in email includes the one-time code. The
contracting entity and processing region are the ones in Resend's own data processing
agreement, which governs them.
- Which of those touch a partner's customers. Hetzner, for hosting, and
Hildebrand where the partner uses our meter connection rather than supplying its own data.
Stripe and Resend handle our own billing and our own users, not the partner's customers. The
binding version of this is an annex to the data processing
agreement.
Sources we query, which process nothing for us
Not sub-processors: they do no processing on our behalf and hold nothing for us.
Listed because a lookup does send them something.
- postcodes.io. Resolves a postcode to a grid-supply region, local authority and
coordinates. Outward code only for the grid-region lookup. Full postcode for the
property-level lookups behind some estimates.
- EPC Open Data. Energy Performance Certificate lookup. Receives a postcode or
address.
- National Grid carbon intensity API. Region identifier only. No personal
data.
- Octopus Energy public API, supplier websites, Ofgem and public price sources.
Outbound reads of published tariff data. Nothing is sent.
- police.uk and HM Land Registry open data. Area context for the local-area
feature. Receives a postcode or area identifier.
Loaded into the visitor's browser
This is the section a Data Protection Officer usually finds in a network trace
after a vendor has failed to mention it, so here it is in full. Nothing loads from anywhere
but this domain. No analytics beacon, no tag manager, no font CDN, no pixel, no
error-reporting service, no content delivery network. Loading any page on this site contacts
joulely.co.uk and nothing else, so no other party — ours or anybody else’s —
sees a visitor’s IP address or user-agent. This is checked on every deploy against the
rendered pages, not against a list somebody maintains by hand.
Until 13 August 2026 that was not true. Every page carried a cookieless
analytics beacon from tally.arx52.co.uk, a host we run ourselves, which received
the page address, the IP address and the user-agent. It was removed once our own analytics
replaced what it was for. It is recorded here because it was live, and because it was injected
in a way that made it invisible to anything except a real network trace.
Web fonts used to be the exception, and are not any more. Until 2026-08-13
Fraunces and Inter were loaded from Google's CDN, so Google received the IP address and
user-agent of every visitor to every page. The files are now served from this domain, so that
recipient no longer exists.
Nothing else is loaded from anywhere. No Sentry, no Cloudflare, no Google
Analytics, no Plausible, no third-party analytics service, no advertising or marketing pixel, no
CDN and no remote stylesheet, script, image or font. Product analytics inside the application are
first-party, stored in our own database, region-level, with no IP address column and a
pseudonymous identifier.
Distribution and the app platform
- Google Play. Distributes the Android app and reports aggregate install and
crash metrics. Play's own relationship with the user is governed by Google's terms, not
ours.
- Expo push notifications. Would deliver the device push token and the text of a
notification, composed from that household's own figures. Currently disabled: sending needs an
environment flag that is not set in production.
Deliberately absent
- Bill images have no third party at all. Optical character recognition runs on
infrastructure we operate: a local model on the application host and a second server of ours
at the same hosting provider. No bill image is sent to any third-party API. Image bytes are
held in memory, never written to disk and never logged.
- No AI or large language model provider processes customer or partner data. An
external model provider exists in the code as a non-default fallback for bill reading that has
to be selected explicitly. It is not selected in production. If a feature is ever introduced
that would send data to a model provider, that is a new sub-processor and it gets the 30 days'
notice and the objection right.
- No data broker, no data sale, no advertising network. We do not sell, rent or
share personal data for anyone's marketing, and we take £0 commission from any energy
supplier on any switch or placement.
- n3rgy is in the code and is not in use. A second meter-data adapter exists so
we are not locked to one provider. It is not the configured source in production. Activating
it for a partner's customers would make it a new sub-processor requiring notice.
Limits of this list
- Hildebrand's own sub-processors are not listed. Our agreement with them
contains no sub-processor clause, so it gives us no contractual right to obtain that list or
to flow obligations down to it. We will not warrant a chain we cannot compel disclosure of. We
will use reasonable endeavours to obtain that right at the next renewal or amendment and will
tell partners if we do. The limitation is written into the data processing agreement rather
than smoothed over, because promising a complete chain would be a warranty breached on day
one.
- Two processing regions are outstanding. The contracting entity and processing
region for Stripe and for Resend are the ones in their own data processing agreements. We have
not transcribed them onto this page. The row stays open until it can be read off the governing
document rather than assumed from where each company is best known.
- The data centre of our second bill-reading server. It is at the same hosting
provider, verified by reverse DNS. The specific data centre has not been checked. It processes
bill images in memory only and stores nothing, and the region still belongs on this
list.
- The analytics host is listed as ours on the basis that we run it. Whether it
sits inside the same legal entity, and therefore whether it is an internal system or a
separate controller to be named, is being confirmed. It is described above either way, because
a browser contacts it either way, and that is the part a network trace shows.
Version 2026-08-13. Questions about this list, or notice of
objection to a change, to business@joulely.co.uk.
Where this page and the annex to the executed data processing agreement differ, the executed
annex governs the contract.
Trust pack · Security · Service levels · Data processing agreement