Back AdviceStudio.ai

SUB-PROCESSORS

AdviceStudio.ai

www.advicestudio.ai

Operated by Planfocus Consulting Pty Ltd (trading as Planfocus Labs)

Last updated: 8 June 2026

1. What this page is

This page lists the third-party service providers ("sub-processors") that Planfocus Consulting Pty Ltd (the operator of AdviceStudio.ai) engages to help us deliver the Platform to you. Each sub-processor processes some category of customer or client personal information on our behalf, under written data-protection commitments.

We publish this list to comply with our Data Processing Agreement (DPA) and to give you advance visibility of every party that touches your data.

2. Current sub-processors

Provider Purpose Data processed Region Attestations
Amazon Web Services (AWS) Hosting: compute, storage, network, email, secrets, logs. All Platform data — application database, secrets, logs, backups, transactional email. ap-southeast-2 (Sydney). Email sent from this region may transit other regions. SOC 1/2/3, ISO 27001, ISO 27017, ISO 27018, ISO 27701, IRAP, PCI-DSS L1.
Anthropic Large-language-model inference (deck generation, edit suggestions). Adviser-supplied notes with client personal information redacted before transmission. We do not send client PII to Anthropic. Anthropic (US-based inference). SOC 2 Type 2.
Stripe Payment processing: subscription billing, top-up wallet, customer portal. Adviser name, email, billing details, subscription metadata. Card data is held by Stripe; we do not see card numbers. Stripe (US-based processing; AU-region card acceptance). PCI-DSS L1, SOC 1/2 (Type 2).
Amazon SES Transactional email (sign-up verification, OTP, password reset, billing notifications). Adviser email address and message body. We do not include client personal information in any system-generated email. ap-southeast-2. Inherits AWS attestations.

We also use the following service providers in the operation of our business; these are not in the data-processing path of customer-facing features and we list them for transparency:

Provider Purpose Data
GitHub Source code hosting and dependency vulnerability monitoring. Source code only. No customer data.
Microsoft 365 Internal Company email and calendar. Internal Company communications only. No customer data.
Vanta Continuous compliance evidence collection. Aggregated configuration metadata about our internal systems. No customer data.

3. How we choose and review sub-processors

Before engaging a new sub-processor, we conduct a documented security review covering the sub-processor's published attestations (SOC 2, ISO 27001, IRAP, PCI-DSS), their data-processing agreement terms, their incident-response posture, and their data-return commitments on termination.

We review this list every three months to confirm the sub-processors named here remain current, that their attestations are in force, and that the scope of data we share with them remains accurate.

4. Notification of changes

When we engage a new sub-processor that will process personal information, we publish the update on this page at least 30 days before the new sub-processor begins processing your data. By using the Platform you agree that publication on this page is sufficient notice.

If you object to a new sub-processor on reasonable security or compliance grounds, please contact us at privacy@advicestudio.ai within 30 days of the publication date.

5. Sub-processor obligations

Every sub-processor we engage is bound by data-protection obligations no less protective than those in our DPA with you. We remain responsible to you for the acts and omissions of every sub-processor we engage.

6. Questions

For questions about this list, our DPA, or our data-processing practices generally, contact us at privacy@advicestudio.ai.

© 2026 Planfocus Consulting Pty Ltd. All rights reserved.

AdviceStudio.ai is a platform operated by Planfocus Consulting Pty Ltd | www.advicestudio.ai