General and privacy
Third-party and Subprocessor Disclosure
Service provider categories, roles and assessment of international data transfers.
Role assessment
Each supplier's service, processed data categories, location, data protection role and contractual safeguards are recorded. A configured integration is not necessarily enabled in production; only verified active providers are included in the published inventory.
Provider categories
- Hosting, content delivery and security
- Email and customer communication
- Payment, electronic documents and accounting
- Analytics — only after a valid preference
- Project, support and file collaboration tools
Changes and objections
In processor relationships, customers receive notice of a new subprocessor within the agreed period. Reasonable data protection objections are assessed. Where possible, alternatives, configuration changes or termination of the affected service are offered.
International transfers
An international transfer is made after the country, purpose, data category and recipient are verified, the appropriate mechanism is selected and required notification processes are completed. A privacy-policy link alone is not a sufficient safeguard.