padelisto

Vendor and subprocessor register

Register version 2026-07-22 · last reviewed 22 July 2026

This register distinguishes processors/subprocessors from platforms and recipients independently controlled by the customer or user. Padelisto gives customers at least 30 days’ notice before a new subprocessor begins processing customer personal data.

Provider Role and purpose Location / transfer safeguard Controls
Railway Subprocessor: tenant hosting, databases, volumes, backups and infrastructure logs. Selected EU region where configured; adequacy or SCC Module 3 plus TIA for access outside EEA. Tenant-isolated projects; active deletion followed by permanent volume/backup removal within 48 hours.
Resend Subprocessor: transactional email, activation and privacy-verification messages. EEA/US processing as documented; DPF where applicable, otherwise SCC Module 3 and TIA. Email event/content retention capped at 30 days in padelisto configuration.
OpenRouter Subprocessor/gateway for optional AI requests. US; SCC Module 3 and TIA. Per-request provider.zdr=true; only approved Google/OpenAI models; no fallback to non-ZDR endpoint; AI disabled when no suitable endpoint is available.
Google AI endpoints Subprocessor when selected behind the approved AI gateway. Location documented for the endpoint; adequacy/DPF or SCC Module 3 and TIA. Allowlisted model and ZDR-compatible endpoint only.
OpenAI endpoints Subprocessor when selected behind the approved AI gateway. EEA/US as contracted; DPF where applicable, otherwise SCC Module 3 and TIA. Allowlisted model and ZDR-compatible endpoint only.
Plausible Analytics Processor for aggregate marketing-site analytics. Visitor data hosted in the EU. No cookies, custom PII or query-string identifiers; aggregate retention 24 months.
Meta / WhatsApp Separately controlled communication platform/recipient selected by customer and message participant; not automatically a padelisto subprocessor. Under Meta/customer terms and chosen configuration. Service and marketing messages separated; customer configures lawful use and opt-out.
Telegram Separately controlled communication platform/recipient; not automatically a padelisto subprocessor. Under Telegram/user terms. Only configured identifiers and messages are exchanged.
Google Calendar User-authorised external platform/recipient for calendar synchronisation; not automatically a padelisto subprocessor. Under the authorising user’s Google terms. Scoped OAuth; refresh tokens encrypted and excluded from exports.
Google Maps Recipient or processor depending on the concrete configured map operation. Operation-specific; assessed before activation. No activation until role, fields, transfer basis and retention are recorded.

Change history

VersionChange
2026-07-22Initial public register; separated communication/calendar platforms from subprocessors and documented ZDR controls.

Questions or objections: legal@theapps.cloud.