SUB-PROCESSORS
1. What this page is
This page lists the third-party service providers ("sub-processors") that Planfocus Consulting Pty Ltd (the operator of AdviceStudio.ai) engages to help us deliver the Platform to you. Each sub-processor processes some category of customer or client personal information on our behalf, under written data-protection commitments.
We publish this list to comply with our Data Processing Agreement (DPA) and to give you advance visibility of every party that touches your data.
2. Current sub-processors
| Provider | Purpose | Data processed | Region | Attestations |
|---|---|---|---|---|
| Amazon Web Services (AWS) | Hosting: compute, storage, network, email, secrets, logs. | All Platform data — application database, secrets, logs, backups, transactional email. | ap-southeast-2 (Sydney). Email sent from this region may transit other regions. | SOC 1/2/3, ISO 27001, ISO 27017, ISO 27018, ISO 27701, IRAP, PCI-DSS L1. |
| Anthropic | Large-language-model inference (deck generation, edit suggestions). | Adviser-supplied notes with client personal information redacted before transmission. We do not send client PII to Anthropic. | Anthropic (US-based inference). | SOC 2 Type 2. |
| Stripe | Payment processing: subscription billing, top-up wallet, customer portal. | Adviser name, email, billing details, subscription metadata. Card data is held by Stripe; we do not see card numbers. | Stripe (US-based processing; AU-region card acceptance). | PCI-DSS L1, SOC 1/2 (Type 2). |
| Amazon SES | Transactional email (sign-up verification, OTP, password reset, billing notifications). | Adviser email address and message body. We do not include client personal information in any system-generated email. | ap-southeast-2. | Inherits AWS attestations. |
We also use the following service providers in the operation of our business; these are not in the data-processing path of customer-facing features and we list them for transparency:
| Provider | Purpose | Data |
|---|---|---|
| GitHub | Source code hosting and dependency vulnerability monitoring. | Source code only. No customer data. |
| Microsoft 365 | Internal Company email and calendar. | Internal Company communications only. No customer data. |
| Vanta | Continuous compliance evidence collection. | Aggregated configuration metadata about our internal systems. No customer data. |
3. How we choose and review sub-processors
Before engaging a new sub-processor, we conduct a documented security review covering the sub-processor's published attestations (SOC 2, ISO 27001, IRAP, PCI-DSS), their data-processing agreement terms, their incident-response posture, and their data-return commitments on termination.
We review this list every three months to confirm the sub-processors named here remain current, that their attestations are in force, and that the scope of data we share with them remains accurate.
4. Notification of changes
When we engage a new sub-processor that will process personal information, we publish the update on this page at least 30 days before the new sub-processor begins processing your data. By using the Platform you agree that publication on this page is sufficient notice.
If you object to a new sub-processor on reasonable security or compliance grounds, please contact us at privacy@advicestudio.ai within 30 days of the publication date.
5. Sub-processor obligations
Every sub-processor we engage is bound by data-protection obligations no less protective than those in our DPA with you. We remain responsible to you for the acts and omissions of every sub-processor we engage.
6. Questions
For questions about this list, our DPA, or our data-processing practices generally, contact us at privacy@advicestudio.ai.
© 2026 Planfocus Consulting Pty Ltd. All rights reserved.
AdviceStudio.ai is a platform operated by Planfocus Consulting Pty Ltd | www.advicestudio.ai