Subprocessors List

Last Updated: 26 July 2026

📋 UK GDPR Article 28 - Subprocessors List

HaveAI Technologies Ltd (UK) - HaveAI Technologies Ltd (UK) uses the following third-party service providers (subprocessors) to deliver its services. This page lists all subprocessors and international data transfer mechanisms we use in compliance with UK GDPR Article 28(2) and our Data Processing Agreement (DPA).

This list is aligned with Data Processing Agreement (DPA) Annex 2: Subprocessors List and provides full transparency for our B2B customers.

⚖️ Legal Basis: UK GDPR Article 28(2) + Article 28(4)

For B2B Customers: Subprocessor changes are notified at least 30 days in advance via email.

SubprocessorServiceData CategoriesLocationTransfer MechanismCertifications
Google LLC
Google Cloud / Gemini AI
ai.google.dev ↗
AI/LLM API
Chat message processing
(Natural language understanding & generation)
Chat messages (ephemeral)
✓ Zero data retention

✓ No model training
🌍 USA / EU
(Multi-region deployment)
EU-US Data Privacy Framework
+ Google Cloud DPA
ISO 27001
ISO 27017
ISO 27018
SOC 2 Type II
GDPR compliant
DigitalOcean, LLC
Cloud Infrastructure Provider
digitalocean.com ↗
Cloud Hosting
VPS / Droplet Servers
(Primary infrastructure)
Tüm platform verisi
- Account data
- Chat conversations
- Bot configurations
- Lead data
- System logs
🇩🇪 Germany (EU)
Frankfurt (FRA1) data center
EEA data residency + SCCs
US-incorporated provider; data stored in EU (Frankfurt), EU Standard Contractual Clauses apply
ISO 27001
SOC 2 Type II
GDPR compliant
EU Standard Contractual Clauses
Cloudflare, Inc.
CDN & Security Services
cloudflare.com ↗
CDN & DDoS Protection
DNS management
WAF (Web Application Firewall)
(Edge network services)
IP addresses
HTTP headers
Access logs
(Edge-cached, ephemeral)
🌍 USA / Global
300+ edge locations worldwide (incl. EU)
EU-US Data Privacy Framework
+ Cloudflare DPA + SCCs
ISO 27001
ISO 27018
SOC 2 Type II
PCI DSS
GDPR compliant
Telegram Messenger LLP
Messaging Platform API
telegram.org ↗
Telegram Bot API
Message delivery
User interaction interface
(Bot hosting & webhooks)
Telegram user IDs
Chat messages
Bot interactions
(End-to-end encrypted via Telegram infrastructure)
🌍 UAE / EU / USA
Distributed global infrastructure
Telegram Privacy Policy
End-to-end encryption
Encrypted infrastructure
Two-factor auth
GDPR-aware
ZERNIO SOFTWARE SL
WhatsApp / Instagram messaging connectivity (BSP bridge)
VAT ESB88719281
zernio.com ↗
Messaging bridge / BSP
Routes messages between HaveAI and Meta channels
(Only when a WhatsApp or Instagram channel is connected)
WhatsApp / Instagram message content (transient)
End-user identifiers (phone number / IG handle)
✓ Media not stored (Meta media_id only)

✓ No model training
🌍 EEA
(Spain / European Economic Area)
Zernio DPA
EEA processing
SOC 2 Type II
GDPR compliant
Meta Platforms Ireland Limited
WhatsApp Business Platform / Instagram Messaging
whatsapp.com/legal ↗
WhatsApp / Instagram messaging
Message delivery on Meta channels
(Only when a WhatsApp or Instagram channel is connected)
End-user phone numbers / Instagram handles
Chat messages & media
(Processed on Meta's messaging infrastructure)
🌍 EU (Ireland) / USA
Global infrastructure
Meta DPA + SCCs
EU-US Data Privacy Framework
ISO 27001
SOC 2
GDPR compliant
PostgreSQL
Open-Source Database (Self-Hosted on DigitalOcean)
postgresql.org ↗
Database Management System
Primary data storage
(Open-source, self-managed)
Tüm uygulama verisi
(Hosted on DigitalOcean, LLC infrastructure)
🇩🇪 Germany (EU)
Self-hosted on DigitalOcean (Frankfurt)
EEA (Adequacy Decision)
Self-hosted, no external transfer
Open-source
AES-256 encryption
SSL/TLS connections
Stripe Payments Europe, Ltd.
Payment Processing
stripe.com ↗
Payment Processing
Subscription billing
Invoice generation
(Stripe-hosted checkout)
Billing info
Payment references
⚠️ Card data NOT stored by HaveAI
🇮🇪 Ireland (EU) / 🇺🇸 US
Dublin
Adequacy / SCC
UK-EU Adequacy + Standard Contractual Clauses
PCI-DSS Level 1
SOC 1 / SOC 2
ISO 27001
Resend (Plexo, Inc.)
Transactional Email
resend.com ↗
Email Delivery
Account & billing notifications
Verification emails
Recipient name & email
Email content (notifications)
🇺🇸 United StatesSCC / DPF
Standard Contractual Clauses
SOC 2 Type II
Cloudinary Ltd.
Media Storage & Delivery
cloudinary.com ↗
Image / Media Hosting
Avatars & uploaded media
Product images
Uploaded images / files
(as provided by the customer)
🇺🇸 United States / 🇮🇱 ILSCC
Standard Contractual Clauses
ISO 27001
SOC 2 Type II
PCI-DSS

Transfer Mechanisms Explained | Aktarım Mekanizmaları Açıklaması

🟢 EEA (Adequacy Decision)

European Economic Area (EEA) - UK GDPR recognizes EEA as adequate, no additional transfer safeguards needed. Applies to: platform data hosted in Germany/Frankfurt (self-hosted PostgreSQL). Note: the infrastructure provider (DigitalOcean, LLC) is US-incorporated, so EU Standard Contractual Clauses (SCCs) additionally apply to the hosting layer.

🔵 EU-US Data Privacy Framework

US companies certified under EU-US Data Privacy Framework (recognized by UK post-Brexit). Applies to: Google, Cloudflare.

🟣 Standard Contractual Clauses (SCCs)

UK GDPR Article 46(2)(c) - EU Commission SCCs 2021 version. Additional safeguard for non-adequate countries.

🟠 Article 49 Derogations

UK GDPR Article 49(1)(b) - Transfer necessary for contract performance (e.g., payment processing via Stripe).

⚫ Third-Party Terms

Data shared with third-party platforms (Telegram) is governed by their own privacy policies and encryption standards.

Google Gemini AI - Zero Data Retention Policy

✓ No data storage: Google Gemini AI does NOT store chat messages sent by HaveAI for more than the time needed to process the request (ephemeral processing).

✓ No model training: Your data is NOT used to train Google's AI models. This is enforced via Google Cloud DPA and API configuration. See Privacy Policy for details.

Security and Compliance Certifications

Tüm alt işleyenler, uluslararası güvenlik standartlarına (ISO 27001, SOC 2 Type II, GDPR) uyumludur ve düzenli bağımsız denetimlere tabidir. Alt işleyen seçiminde güvenlik, uyumluluk ve veri koruma kriterleri önceliklidir.

Primary Data Hosting Location

HaveAI'nin birincil veri hosting lokasyonu 🇩🇪 Germany (EU) - DigitalOcean, LLC Frankfurt (FRA1) data center. Tüm platform verisi EEA sınırları içinde saklanır ve işlenir. Not: hosting sağlayıcısı DigitalOcean ABD merkezli olduğundan, barındırma katmanı için EU Standard Contractual Clauses (SCC) uygulanır.

Subprocessor Change Notification Process | Alt İşleyen Değişiklik Bildirimi

UK GDPR Article 28(2) ve Data Processing Agreement (DPA) gereği, alt işleyen değişikliklerini müşterilerimize önceden bildiririz:

30-Day Prior Notice

Yeni alt işleyen ekleme veya değiştirme işlemleri için en az 30 gün önceden yazılı bildirim (email).

Email Notification

Tüm B2B müşterilere kayıtlı e-posta adresine bildirim gönderilir (subject: "Subprocessor Change Notice").

Right to Object

Müşteriler 30 gün içinde haklı gerekçe ile itiraz edebilir. İtiraz durumunda alternatif çözüm sunulur veya sözleşme sonlandırılabilir.

Transparent Updates

Bu sayfa her değişiklikte güncellenir ve "Son Güncelleme" tarihi değiştirilir. RSS feed ve changelog mevcuttur.

Bildirim almak veya itiraz için:
Email: [email protected]
Subject: "Subprocessor Change - Objection" veya "Alt İşleyen Değişikliği - İtiraz"

📖 Additional Information and Resources

This page is aligned with Data Processing Agreement (DPA) Annex 2.

Personal data processing details: Privacy Policy

International data transfer mechanisms: DPA Annex 5

Security measures: DPA Annex 3