Legal
Sub-processors & Security
Every third party that may process personal data on our behalf, and the measures protecting it.
Effective 17 September 2026
In plain English
Two providers, both under data processing agreements with Standard Contractual Clauses. This page exists because procurement teams ask for it, and because you should be able to check without asking.
Current sub-processors
These providers process personal data on our instructions in order to run this website. Each is bound by a data processing agreement incorporating the Standard Contractual Clauses where required.
| Provider | What it does | Data it may process | Location |
|---|---|---|---|
| Vercel Inc. | Website hosting, CDN and serverless functions | IP address, request metadata, server logs, and contact form contents in transit | United States, with a global edge network |
| Resend (Plus Five Five, Inc.) | Transactional email delivery for contact form enquiries | Your name, email address and the contents of your enquiry | United States |
We do not use an analytics provider, an advertising network, a CRM or a marketing automation platform for this website. If that changes, this page changes first.
Changes to this list
If we add or replace a sub-processor, we will update this page. Clients under an active agreement are notified in advance in accordance with that agreement, and may object on reasonable data protection grounds. To be told about changes, email hello@miragecapital.co.
Technical and organisational measures
Measures applied to this website:
- All traffic served over HTTPS, with HSTS including subdomains and preload.
- Security response headers set on every route: content type sniffing disabled, framing restricted to same origin, referrer policy limited to same-origin detail, and camera, microphone and geolocation permissions denied.
- Data minimisation by design — the form asks only what is needed to answer an enquiry, and there is no application database holding your submission.
- Abuse controls — a per-address request throttle and a hidden honeypot field, so no CAPTCHA is required and no third-party bot-detection script is loaded.
- Input validated on the server, never trusting the browser, with strict length limits on every field.
- No credentials, payment data or government identifiers are requested or stored.
- Provider credentials held as encrypted environment variables, never committed to source control, and never exposed to the browser.
- Delivery failures are logged for diagnosis so that no enquiry is silently lost.
Measures applicable to client engagements — including access control, environment separation and incident response — are set out in the relevant services agreement and data processing agreement.
Data processing agreement
Where we act as a processor of personal data for a client, we enter into a data processing agreement incorporating the Standard Contractual Clauses and, where relevant, the UK International Data Transfer Addendum. Request a copy at hello@miragecapital.co.
Reporting a vulnerability
If you believe you have found a security issue in this website or in any of our products, email hello@miragecapital.co with enough detail to reproduce it. Please give us a reasonable opportunity to fix it before disclosing it publicly.
We will acknowledge your report, keep you updated, and credit you if you would like to be credited. We will not pursue legal action against good-faith research that respects user privacy and avoids service disruption or data destruction.
If something goes wrong
If a personal data breach occurs, we will notify the relevant supervisory authority within 72 hours of becoming aware of it where the GDPR or UK GDPR requires, and notify affected individuals without undue delay where the risk to them is high.
Related
Questions about any of this? Write to hello@miragecapital.co.