2 named + mailbox infrastructure
Vercel hosts the site, Cal.com runs scheduling, mailbox and calendar infrastructure holds inquiries and invites.
No analytics vendors
No measurement, advertising, or enrichment processors. Upwork and LinkedIn are outbound links, not processors.
Project vendors only per SOW
Foundation models, tools, and APIs are allowlisted per engagement with provider, purpose, data, and retention fixed.
14-day objection right
Advance notice before material project-vendor changes, written objection on reasonable grounds, safe alternative or exit.
Nº 01
Overview — what a subprocessor is
A subprocessor processes personal data on behalf of BRANCLE TECHNOLOGIES LLC (“Brancle,” “we,” “us”), 212 N. 2nd St. STE 100, Richmond, KY 40475, to help us operate brancle.com or perform a signed statement of work (“SOW”). Processors act only on our documented instructions under Article 28(3) terms, and we remain responsible for their performance of data protection duties. This page is the versioned list incorporated by our DPA (Policy #6); general authorization with objection rights is set there.
Nº 02
Site processors — every visitor
| Vendor | Role & data | Location & safeguards |
|---|---|---|
| Vercel Inc. — hosting | Serves brancle.com; IP, timestamps, routes, error traces, artifacts and platform backups for operation and security | United States; TLS in transit, platform encryption at rest, DPA terms with SCCs where a transfer mechanism applies |
| Cal.com, Inc. — scheduling | Renders the booking modal and booking page (event arqamwithbrancle/30min); booking name, email, timezone, notes; embed cookies and localStorage to hold availability and selection | United States; TLS in transit, platform encryption at rest, DPA terms with SCCs where applicable; exact Cal-operated cookie names per Cal.com docs |
| Mailbox and calendar infrastructure — inquiry handling | Delivers, stores, and holds inquiry mail to hello@brancle.com and security@brancle.com plus calendar copies of bookings and correspondence history | United States; access-controlled need-to-know mailboxes and calendars, TLS in transit, platform encryption at rest |
Fonts (Inter, Fraunces, JetBrains Mono) are self-hosted with the site build and involve no font vendor as processor. Server logs roll on a 90-day schedule with booking and inquiry copies at 24 months per Privacy §9; processor copies follow the same windows unless the vendor’s platform requires shorter technical retention.
Nº 03
Project vendors — per SOW only
No foundation-model, tool, or API processor touches project personal data until your SOW names it. Each SOW allowlist fixes provider, purpose, data sent, retention, and version pin — for example, the model provider for summarization scope, the integration middleware for a named CRM, or the transcription service for a call-review step.
| Field | SOW entry |
|---|---|
| Provider | Legal vendor name and service (no generic TBD at signature) |
| Purpose | Workflow step and function, tied to Annex I purposes |
| Data sent | Categories and subjects limited to that step |
| Retention & version | Retention window plus model or API version pin and re-validation trigger |
Until an SOW names project vendors, the Site-processor table above is the complete list. Brancle itself acts as processor for project data in your systems under the DPA; you remain controller.
Nº 04
What isn't a subprocessor here
- Upwork and LinkedIn — plain outbound links to our profiles; their policies apply only after you click through.
- Your mail client handling a mailto: draft — your software, not our processor.
- Authorities receiving compelled disclosures and any business transferee — governed by Privacy §7, not processor terms.
Nº 05
Changes and your objection right
For project vendors with material access to project personal data, we notify affected SOW clients at least 14 days before adding or replacing the vendor. Object in writing on reasonable data-protection grounds within that window to hello@brancle.com (copying security@brancle.com for security-relevant objections); we propose a safe alternative, and if none is reasonably available either party may terminate the affected SOW portion with a pro-rata refund of prepaid, unaccepted fees as the exclusive remedy for the change.
Site-processor changes are posted here with a new Effective date and version-history entry below. Direct email goes to active SOW clients for project-vendor changes; past inquiry threads are not broadcast unless the change affects retained inquiry data.
Nº 06
International transfers
Site processors operate in the United States. Where a transfer requires a mechanism under GDPR or UK GDPR, EU Standard Contractual Clauses (Module Two or Three as applicable, UK Addendum where relevant) are incorporated with you as exporter and the vendor via Brancle as importer chain, supplemented by this page plus DPA Annexes I–III. Project-data residency elections (“environments you control”) are fixed per SOW.
Nº 07
Version history — appended, never rewritten
| Version | Date | Change |
|---|---|---|
| v1.0 | September 6, 2026 | Initial publication: Vercel hosting, Cal.com scheduling, mailbox and calendar infrastructure; project-vendor schema with none pre-SOW |
Nº 08
Changes to this page & contact
We update this ledger as vendors, the scheduler, hosting, or law changes by posting the revised version with a new Effective date and appending to the history above. The current version always lives at https://brancle.com/subprocessors and companions our DPA (Policy #6), Privacy (Policy #1), Cookies (Policy #3), and Security (Policy #4).
Owner contact
BRANCLE TECHNOLOGIES LLC
212 N. 2nd St. STE 100, Richmond, KY 40475
General: hello@brancle.com
Security-relevant objections: security@brancle.com · Site: https://brancle.com
This page is provided for transparency and does not constitute legal advice. Project allowlists in your signed SOW control for project vendors on conflict.