Skip to main content
Status Official 
REF: GDPR (Article 28) and ISO 27001:2022 (Clause 8.15)  
Last Update 21/07/2026 

Overview 

This page provides a comprehensive list of subprocessors engaged by Pen Test Partners LLP (PTP) to process personal data on our behalf. We maintain this inventory to ensure transparency, compliance with UK GDPR (Article 28), and alignment with ISO 27001:2022 for supplier management. 

Review this list to understand which subprocessors may process your data. Contact [email protected] for further details or objections. 

Purpose: 

  • Inform data subjects (e.g., customers, employees, prospects) about third parties processing personal data. 
  • Support compliance with data protection laws and contractual obligations. 
  • Enable customers to assess subprocessors for their own compliance needs. 

Responsible Party: PTP’s Data Protection Officer (DPO): Renato Ellis 

This inventory is reviewed at least once a year by the DPO. 

Subprocessor Inventory 

Subprocessor Name  Purpose of Processing  Data Categories Processed  Data Location  DPA Status  Security Certifications  Subprocessor’s Subprocessors  
Microsoft O365  Email, document storage, collaboration  Client contacts, employee records  EU/UK Data Centres  Signed ISO 27001, SOC 2 Type II  AWS (for storage)  
Google Analytics  Website analytics  IP addresses, cookies, usage data  US (with IDTA/SCCs)  Signed  ISO 27001, SOC 2  Google Cloud  
Cloudflare  DDoS protection, CDN  IP addresses, traffic data  Global (with SCCs)  Signed  ISO 27001, SOC 2  N/A  
Salesforce  CRM, client relationship management  Client records, project data  EU/US (with IDTA)  Signed  ISO 27001, SOC 2  AWS, Salesforce subcontractors  
Datanet – Veeam Cloud Connect Cloud storage, backup services Client data backups UK/EU Signed ISO 27001, SOC 2, FIPS 140-3, CMMC v2 Level 1 Impossible Cloud (EU) 

Definitions  

  • Subprocessor: A third party engaged by PTP to process personal data on behalf of our customers (data controllers).  
  • DPA (Data Processing Agreement): Contractual agreement outlining data protection obligations between PTP and the subprocessor.  
  • DPIA (Data Protection Impact Assessment): Assessment of risks posed by processing activities.  
  • IDTA (International Data Transfer Agreement): UK-approved mechanism for transferring data outside the UK.  
  • SCCs (Standard Contractual Clauses): EU-approved mechanism for international data transfers.  

Contact Us  

For questions or updates regarding this inventory, please contact:  

Click. Click. Fake it until they make it… inside
  • Social Engineering
Click. Click. Fake it until they make it… inside

7 Min Read

Jul 23, 2026

Flying with the Flipper Zero 
  • Aviation Cyber Security
  • Hardware Hacking
Flying with the Flipper Zero 

7 Min Read

Jul 10, 2026

EN 303 645 is the baseline, not the finish line for IoT security 
  • Cyber Regulation
  • Hardware Hacking
  • Internet Of Things
EN 303 645 is the baseline, not the finish line for IoT security 

17 Min Read

Jul 03, 2026