Subprocessors List
Last Updated: 26 July 2026
📋 UK GDPR Article 28 - Subprocessors List
HaveAI Technologies Ltd (UK) - HaveAI Technologies Ltd (UK) uses the following third-party service providers (subprocessors) to deliver its services. This page lists all subprocessors and international data transfer mechanisms we use in compliance with UK GDPR Article 28(2) and our Data Processing Agreement (DPA).
This list is aligned with Data Processing Agreement (DPA) Annex 2: Subprocessors List and provides full transparency for our B2B customers.
⚖️ Legal Basis: UK GDPR Article 28(2) + Article 28(4)
For B2B Customers: Subprocessor changes are notified at least 30 days in advance via email.
| Subprocessor | Service | Data Categories | Location | Transfer Mechanism | Certifications |
|---|---|---|---|---|---|
Google LLC Google Cloud / Gemini AI ai.google.dev ↗ | AI/LLM API Chat message processing (Natural language understanding & generation) | Chat messages (ephemeral) ✓ Zero data retention ✓ No model training | 🌍 USA / EU (Multi-region deployment) | EU-US Data Privacy Framework + Google Cloud DPA | ISO 27001 ISO 27017 ISO 27018 SOC 2 Type II GDPR compliant |
DigitalOcean, LLC Cloud Infrastructure Provider digitalocean.com ↗ | Cloud Hosting VPS / Droplet Servers (Primary infrastructure) | Tüm platform verisi - Account data - Chat conversations - Bot configurations - Lead data - System logs | 🇩🇪 Germany (EU) Frankfurt (FRA1) data center | EEA data residency + SCCs US-incorporated provider; data stored in EU (Frankfurt), EU Standard Contractual Clauses apply | ISO 27001 SOC 2 Type II GDPR compliant EU Standard Contractual Clauses |
Cloudflare, Inc. CDN & Security Services cloudflare.com ↗ | CDN & DDoS Protection DNS management WAF (Web Application Firewall) (Edge network services) | IP addresses HTTP headers Access logs (Edge-cached, ephemeral) | 🌍 USA / Global 300+ edge locations worldwide (incl. EU) | EU-US Data Privacy Framework + Cloudflare DPA + SCCs | ISO 27001 ISO 27018 SOC 2 Type II PCI DSS GDPR compliant |
Telegram Messenger LLP Messaging Platform API telegram.org ↗ | Telegram Bot API Message delivery User interaction interface (Bot hosting & webhooks) | Telegram user IDs Chat messages Bot interactions (End-to-end encrypted via Telegram infrastructure) | 🌍 UAE / EU / USA Distributed global infrastructure | Telegram Privacy Policy End-to-end encryption | Encrypted infrastructure Two-factor auth GDPR-aware |
ZERNIO SOFTWARE SL WhatsApp / Instagram messaging connectivity (BSP bridge) VAT ESB88719281 zernio.com ↗ | Messaging bridge / BSP Routes messages between HaveAI and Meta channels (Only when a WhatsApp or Instagram channel is connected) | WhatsApp / Instagram message content (transient) End-user identifiers (phone number / IG handle) ✓ Media not stored (Meta media_id only) ✓ No model training | 🌍 EEA (Spain / European Economic Area) | Zernio DPA EEA processing | SOC 2 Type II GDPR compliant |
Meta Platforms Ireland Limited WhatsApp Business Platform / Instagram Messaging whatsapp.com/legal ↗ | WhatsApp / Instagram messaging Message delivery on Meta channels (Only when a WhatsApp or Instagram channel is connected) | End-user phone numbers / Instagram handles Chat messages & media (Processed on Meta's messaging infrastructure) | 🌍 EU (Ireland) / USA Global infrastructure | Meta DPA + SCCs EU-US Data Privacy Framework | ISO 27001 SOC 2 GDPR compliant |
PostgreSQL Open-Source Database (Self-Hosted on DigitalOcean) postgresql.org ↗ | Database Management System Primary data storage (Open-source, self-managed) | Tüm uygulama verisi (Hosted on DigitalOcean, LLC infrastructure) | 🇩🇪 Germany (EU) Self-hosted on DigitalOcean (Frankfurt) | EEA (Adequacy Decision) Self-hosted, no external transfer | Open-source AES-256 encryption SSL/TLS connections |
Stripe Payments Europe, Ltd. Payment Processing stripe.com ↗ | Payment Processing Subscription billing Invoice generation (Stripe-hosted checkout) | Billing info Payment references ⚠️ Card data NOT stored by HaveAI | 🇮🇪 Ireland (EU) / 🇺🇸 US Dublin | Adequacy / SCC UK-EU Adequacy + Standard Contractual Clauses | PCI-DSS Level 1 SOC 1 / SOC 2 ISO 27001 |
Resend (Plexo, Inc.) Transactional Email resend.com ↗ | Email Delivery Account & billing notifications Verification emails | Recipient name & email Email content (notifications) | 🇺🇸 United States | SCC / DPF Standard Contractual Clauses | SOC 2 Type II |
Cloudinary Ltd. Media Storage & Delivery cloudinary.com ↗ | Image / Media Hosting Avatars & uploaded media Product images | Uploaded images / files (as provided by the customer) | 🇺🇸 United States / 🇮🇱 IL | SCC Standard Contractual Clauses | ISO 27001 SOC 2 Type II PCI-DSS |
Transfer Mechanisms Explained | Aktarım Mekanizmaları Açıklaması
European Economic Area (EEA) - UK GDPR recognizes EEA as adequate, no additional transfer safeguards needed. Applies to: platform data hosted in Germany/Frankfurt (self-hosted PostgreSQL). Note: the infrastructure provider (DigitalOcean, LLC) is US-incorporated, so EU Standard Contractual Clauses (SCCs) additionally apply to the hosting layer.
US companies certified under EU-US Data Privacy Framework (recognized by UK post-Brexit). Applies to: Google, Cloudflare.
UK GDPR Article 46(2)(c) - EU Commission SCCs 2021 version. Additional safeguard for non-adequate countries.
UK GDPR Article 49(1)(b) - Transfer necessary for contract performance (e.g., payment processing via Stripe).
Data shared with third-party platforms (Telegram) is governed by their own privacy policies and encryption standards.
Google Gemini AI - Zero Data Retention Policy
✓ No data storage: Google Gemini AI does NOT store chat messages sent by HaveAI for more than the time needed to process the request (ephemeral processing).
✓ No model training: Your data is NOT used to train Google's AI models. This is enforced via Google Cloud DPA and API configuration. See Privacy Policy for details.
Security and Compliance Certifications
Tüm alt işleyenler, uluslararası güvenlik standartlarına (ISO 27001, SOC 2 Type II, GDPR) uyumludur ve düzenli bağımsız denetimlere tabidir. Alt işleyen seçiminde güvenlik, uyumluluk ve veri koruma kriterleri önceliklidir.
Primary Data Hosting Location
HaveAI'nin birincil veri hosting lokasyonu 🇩🇪 Germany (EU) - DigitalOcean, LLC Frankfurt (FRA1) data center. Tüm platform verisi EEA sınırları içinde saklanır ve işlenir. Not: hosting sağlayıcısı DigitalOcean ABD merkezli olduğundan, barındırma katmanı için EU Standard Contractual Clauses (SCC) uygulanır.
Subprocessor Change Notification Process | Alt İşleyen Değişiklik Bildirimi
UK GDPR Article 28(2) ve Data Processing Agreement (DPA) gereği, alt işleyen değişikliklerini müşterilerimize önceden bildiririz:
✓30-Day Prior Notice
Yeni alt işleyen ekleme veya değiştirme işlemleri için en az 30 gün önceden yazılı bildirim (email).
✓Email Notification
Tüm B2B müşterilere kayıtlı e-posta adresine bildirim gönderilir (subject: "Subprocessor Change Notice").
✓Right to Object
Müşteriler 30 gün içinde haklı gerekçe ile itiraz edebilir. İtiraz durumunda alternatif çözüm sunulur veya sözleşme sonlandırılabilir.
✓Transparent Updates
Bu sayfa her değişiklikte güncellenir ve "Son Güncelleme" tarihi değiştirilir. RSS feed ve changelog mevcuttur.
Bildirim almak veya itiraz için:
Email: [email protected]
Subject: "Subprocessor Change - Objection" veya "Alt İşleyen Değişikliği - İtiraz"
📖 Additional Information and Resources
→ This page is aligned with Data Processing Agreement (DPA) Annex 2.
→ Personal data processing details: Privacy Policy
→ International data transfer mechanisms: DPA Annex 5
→ Security measures: DPA Annex 3