Vendor and subprocessor register
This register distinguishes processors/subprocessors from platforms and recipients independently controlled by the customer or user. Padelisto gives customers at least 30 days’ notice before a new subprocessor begins processing customer personal data.
| Provider | Role and purpose | Location / transfer safeguard | Controls |
|---|---|---|---|
| Railway | Subprocessor: tenant hosting, databases, volumes, backups and infrastructure logs. | Selected EU region where configured; adequacy or SCC Module 3 plus TIA for access outside EEA. | Tenant-isolated projects; active deletion followed by permanent volume/backup removal within 48 hours. |
| Resend | Subprocessor: transactional email, activation and privacy-verification messages. | EEA/US processing as documented; DPF where applicable, otherwise SCC Module 3 and TIA. | Email event/content retention capped at 30 days in padelisto configuration. |
| OpenRouter | Subprocessor/gateway for optional AI requests. | US; SCC Module 3 and TIA. | Per-request provider.zdr=true; only approved Google/OpenAI models; no fallback to non-ZDR endpoint; AI disabled when no suitable endpoint is available. |
| Google AI endpoints | Subprocessor when selected behind the approved AI gateway. | Location documented for the endpoint; adequacy/DPF or SCC Module 3 and TIA. | Allowlisted model and ZDR-compatible endpoint only. |
| OpenAI endpoints | Subprocessor when selected behind the approved AI gateway. | EEA/US as contracted; DPF where applicable, otherwise SCC Module 3 and TIA. | Allowlisted model and ZDR-compatible endpoint only. |
| Plausible Analytics | Processor for aggregate marketing-site analytics. | Visitor data hosted in the EU. | No cookies, custom PII or query-string identifiers; aggregate retention 24 months. |
| Meta / WhatsApp | Separately controlled communication platform/recipient selected by customer and message participant; not automatically a padelisto subprocessor. | Under Meta/customer terms and chosen configuration. | Service and marketing messages separated; customer configures lawful use and opt-out. |
| Telegram | Separately controlled communication platform/recipient; not automatically a padelisto subprocessor. | Under Telegram/user terms. | Only configured identifiers and messages are exchanged. |
| Google Calendar | User-authorised external platform/recipient for calendar synchronisation; not automatically a padelisto subprocessor. | Under the authorising user’s Google terms. | Scoped OAuth; refresh tokens encrypted and excluded from exports. |
| Google Maps | Recipient or processor depending on the concrete configured map operation. | Operation-specific; assessed before activation. | No activation until role, fields, transfer basis and retention are recorded. |
Change history
| Version | Change |
|---|---|
| 2026-07-22 | Initial public register; separated communication/calendar platforms from subprocessors and documented ZDR controls. |
Questions or objections: legal@theapps.cloud.