Subprocessor Policy
Information about the sub processors that support our services.
Contact: privacy@tiquo.co
1. Introduction
This policy describes the sub-processors that Tiquo uses to support the delivery of its services. A sub-processor is a third party that processes personal data on behalf of Tiquo. We maintain transparency in how personal data is handled and we only engage sub-processors that meet appropriate technical and organisational standards.
2. How we use sub processors
Tiquo relies on carefully selected service providers to support the hosting and operation of the Tiquo platform. These providers may process personal data when they store, transmit or otherwise handle information on our behalf. Each sub-processor is bound by a written agreement that requires them to safeguard personal data, follow our instructions, and maintain appropriate security measures.
3. List of current sub processors
The following sub processors support the Tiquo platform and may process personal data.
Amazon Web Services, AWS
Service: Cloud hosting, storage and infrastructure used to operate the Tiquo platform.
Processing location: AWS eu-west-1 (Ireland) and AWS us-east-1 (N. Virginia)
Personal data processed. Customer data that is stored or transmitted by our platform.
Vercel
Purpose. Application hosting and delivery for the Tiquo web front end.
Location of processing. Vercel edge network globally for content delivery; build infrastructure in the United States (AWS us-east-1).
Personal data processed. Request data, logs and metadata generated when users interact with the platform.
Purpose. Cloud services, authentication and analytics.
Location of processing. Google data centres globally.
Personal data processed. User identifiers, authentication data, usage data and analytics metadata.
Convex
Purpose. Backend infrastructure and application data storage.
Processing location: AWS eu-west-1 (Ireland) and AWS us-east-1 (N. Virginia)
Personal data processed. Application data and user records.
Stripe
Purpose. Payment processing, billing and financial transaction management.
Location of processing. Stripe infrastructure in the United States and internationally.
Personal data processed. Payment details (tokenised), billing information, transaction records and customer identifiers.
Clerk
Purpose. User authentication, identity management and session handling.
Location of processing. Clerk infrastructure in the United States.
Personal data processed. User credentials, profile information, session data and authentication logs.
Resend
Purpose. Transactional and operational email delivery.
Location of processing. Resend infrastructure in the United States and Ireland.
Personal data processed. Email addresses, message content and delivery metadata.
Twilio
Purpose. SMS messaging and communication services.
Location of processing. Twilio data centres globally.
Personal data processed. Phone numbers, message content and delivery metadata.
Apple
Purpose. Push notification delivery and authentication services.
Location of processing. Apple data centres globally.
Personal data processed. Device tokens, user identifiers and notification content.
Tinybird
Purpose. OLAP querying and analytics data warehousing.
Processing location: AWS eu-west-1 (Ireland) and AWS us-east-1 (N. Virginia)
Personal data processed. Usage data, event logs and aggregated analytics data.
Anthropic
Purpose. AI language model services for platform features.
Location of processing. Anthropic infrastructure in the United States.
Personal data processed. Prompts, queries and generated responses that may contain user-provided content.
Note. Personal data is not used by Anthropic to train models. Processing is subject to Anthropic's data processing terms.
Axiom
Purpose. Observability, logging and performance monitoring.
Location of processing. Axiom infrastructure in the United States.
Personal data processed. Log data, trace data, metrics and event metadata generated by the platform.
4. Changes to sub processors
We may add or replace sub-processors when required to support our services. If we make such a change, we will update this policy and notify customers at least 10 business days in advance. Customers who object to a proposed change may contact us so that we can work together to find a suitable solution.
5. Security and compliance
Tiquo only engages sub-processors that demonstrate strong security practices. Each sub-processor must implement appropriate measures to protect personal data, assist us in meeting our legal obligations and notify us promptly if a security incident occurs.
6. Contact
If you have any questions about this policy or our use of sub processors, please contact us at privacy@tiquo.co
7. Review Schedule
This policy is reviewed quarterly and updated whenever a sub-processor is added or removed.
8. International Data Transfer Mechanisms
For sub-processors located outside the UK, EEA or Switzerland, Tiquo ensures appropriate transfer mechanisms are in place, including the EU Standard Contractual Clauses (EU Commission Decision 2021/914), the UK International Data Transfer Addendum (IDTA) issued by the ICO, and transfer mechanisms recognised by the Swiss Federal Data Protection and Information Commissioner (FDPIC). Transfer Impact Assessments are maintained for sub-processors located in jurisdictions without an adequacy decision, and are available to customers on request.
9. Data Protection Lead
Our Data Protection Lead, oversees sub-processor compliance.
Contact: privacy@tiquo.co
Frågor om detta dokument? Kontakta vårt juridiska team.
Kontakta juridiska teamet