| Status | Official |
| REF: | GDPR (Article 28) and ISO 27001:2022 (Clause 8.15) |
| Last Update | 21/07/2026 |
Overview
This page provides a comprehensive list of subprocessors engaged by Pen Test Partners LLP (PTP) to process personal data on our behalf. We maintain this inventory to ensure transparency, compliance with UK GDPR (Article 28), and alignment with ISO 27001:2022 for supplier management.
Review this list to understand which subprocessors may process your data. Contact [email protected] for further details or objections.
Purpose:
- Inform data subjects (e.g., customers, employees, prospects) about third parties processing personal data.
- Support compliance with data protection laws and contractual obligations.
- Enable customers to assess subprocessors for their own compliance needs.
Responsible Party: PTP’s Data Protection Officer (DPO): Renato Ellis
This inventory is reviewed at least once a year by the DPO.
Subprocessor Inventory
| Subprocessor Name | Purpose of Processing | Data Categories Processed | Data Location | DPA Status | Security Certifications | Subprocessor’s Subprocessors |
| Microsoft O365 | Email, document storage, collaboration | Client contacts, employee records | EU/UK Data Centres | Signed | ISO 27001, SOC 2 Type II | AWS (for storage) |
| Google Analytics | Website analytics | IP addresses, cookies, usage data | US (with IDTA/SCCs) | Signed | ISO 27001, SOC 2 | Google Cloud |
| Cloudflare | DDoS protection, CDN | IP addresses, traffic data | Global (with SCCs) | Signed | ISO 27001, SOC 2 | N/A |
| Salesforce | CRM, client relationship management | Client records, project data | EU/US (with IDTA) | Signed | ISO 27001, SOC 2 | AWS, Salesforce subcontractors |
| Datanet – Veeam Cloud Connect | Cloud storage, backup services | Client data backups | UK/EU | Signed | ISO 27001, SOC 2, FIPS 140-3, CMMC v2 Level 1 | Impossible Cloud (EU) |
Definitions
- Subprocessor: A third party engaged by PTP to process personal data on behalf of our customers (data controllers).
- DPA (Data Processing Agreement): Contractual agreement outlining data protection obligations between PTP and the subprocessor.
- DPIA (Data Protection Impact Assessment): Assessment of risks posed by processing activities.
- IDTA (International Data Transfer Agreement): UK-approved mechanism for transferring data outside the UK.
- SCCs (Standard Contractual Clauses): EU-approved mechanism for international data transfers.
Contact Us
For questions or updates regarding this inventory, please contact:
- Data Protection Officer (DPO): [email protected]