About this list
A sub-processor is any third party Fidify engages to help deliver the Services on behalf of our customers under GDPR Article 28. Every sub-processor is bound by a written agreement that imposes equivalent data-protection obligations to those in our Data Processing Agreement. Our production infrastructure is hosted in the European Union, on Google Cloud in Belgium. Where a customer's contract names another legal area, that customer's environment is hosted in the region agreed in the contract. The services below process data in the locations listed.
Current sub-processors
| Sub-processor | Purpose | Data categories | Location | Transfer mechanism | Region it serves |
|---|---|---|---|---|---|
| Fidify Mauritius Ltd | Customer support and operational administration, including remote access to EEA-hosted data by Fidify personnel in Mauritius. | Platform data accessed for support, on a need-to-know basis. | Mauritius (remote access to EEA-hosted data). | EU Standard Contractual Clauses, Module 3 (processor-to-processor), intra-group, plus transfer impact assessment and supplementary measures. | All |
| Google Ireland Limited (Google Cloud Platform) | Hosting infrastructure, including compute, storage, database, messaging, encryption-key management, and logging. Also provides AI inference on Vertex AI (Mistral models) in the EU. | Customer document content, identifiers, authentication tokens, session data, logs, encryption keys, AI prompts and completions. | European Union (Belgium) by default. Another Google Cloud region on request, as agreed in the customer's contract. | Intra-EU by default, no transfer mechanism required. For a region outside the EU, the transfer mechanism is set out in the customer's contract. | All |
| Google LLC (Gemini API) | AI inference when a customer's environment uses Google Gemini models. | Document text excerpts, policy prompts, extracted compliance fields. | United States / global | EU Standard Contractual Clauses. | All |
| Google LLC (push notifications) | Push notification delivery to Android and web users. | Device registration tokens, user identifiers, notification title and body, event metadata. | United States | EU Standard Contractual Clauses, plus supplementary safeguards. | All |
| Apple Distribution International Ltd | Push notification delivery to iOS users. | Device tokens, notification title and body, event metadata. | Ireland and United States | Intra-EU for the Apple contracting entity. EU Standard Contractual Clauses cover any onward transfer to the United States. | All |
| Twilio SendGrid Inc. | Transactional email delivery, including invitations, document share links, recovery emails, and one-time passcodes. | Recipient email addresses and names, invitation tokens, portal and organisation names, email body content. | United States | EU Standard Contractual Clauses, plus supplementary safeguards. | All |
| Stripe Payments Europe Ltd | Payment processing and billing. | Customer email, billing name, payment-method metadata (last four digits, card brand, expiry; full card number never reaches Fidify), transaction amounts, subscription identifiers. | Ireland, with onward processing in the United States for payment-network routing. | Intra-EU primary. EU Standard Contractual Clauses for onward transfer to the United States. | All |
| Functional Software, Inc. (Sentry) | Error monitoring across the Fidify Enterprise portal, the Fidify Business web app, platform services, and the mobile app. | Stack traces, user identifiers, IP addresses, browser and device fingerprints, application event trails. Personal data is scrubbed before submission. | European Union | Intra-EU. No transfer mechanism required. | All |
| OpenAI Ireland Ltd | AI inference for risk assessment, compliance narrative generation, and document analysis when a customer's AI policy selects OpenAI as the provider. | Document text excerpts, policy prompts, extracted compliance fields. Content is not used to train OpenAI models. | United States | EU Standard Contractual Clauses, plus the OpenAI data-processing agreement. | All |
| Anthropic Ireland, Limited | AI inference when a customer's AI policy selects Anthropic as the provider. | Document text excerpts, policy prompts, extracted compliance fields. Content is not used to train Anthropic models. | United States | EU Standard Contractual Clauses, plus the Anthropic data-processing agreement. | All |
| LangChain, Inc. (LangSmith) | AI observability and tracing. | AI prompts and responses. | European Union | EU Standard Contractual Clauses. | All |
| Tavily AI Inc. | Web search context retrieval for AI workflows, including compliance research and entity enrichment. | Search queries, including entity and person names used as search terms. | United States | EU Standard Contractual Clauses. | All |
Fidify Mauritius Ltd
- Purpose
- Customer support and operational administration, including remote access to EEA-hosted data by Fidify personnel in Mauritius.
- Data categories
- Platform data accessed for support, on a need-to-know basis.
- Location
- Mauritius (remote access to EEA-hosted data).
- Transfer mechanism
- EU Standard Contractual Clauses, Module 3 (processor-to-processor), intra-group, plus transfer impact assessment and supplementary measures.
- Region it serves
- All
Google Ireland Limited (Google Cloud Platform)
- Purpose
- Hosting infrastructure, including compute, storage, database, messaging, encryption-key management, and logging. Also provides AI inference on Vertex AI (Mistral models) in the EU.
- Data categories
- Customer document content, identifiers, authentication tokens, session data, logs, encryption keys, AI prompts and completions.
- Location
- European Union (Belgium) by default. Another Google Cloud region on request, as agreed in the customer's contract.
- Transfer mechanism
- Intra-EU by default, no transfer mechanism required. For a region outside the EU, the transfer mechanism is set out in the customer's contract.
- Region it serves
- All
Google LLC (Gemini API)
- Purpose
- AI inference when a customer's environment uses Google Gemini models.
- Data categories
- Document text excerpts, policy prompts, extracted compliance fields.
- Location
- United States / global
- Transfer mechanism
- EU Standard Contractual Clauses.
- Region it serves
- All
Google LLC (push notifications)
- Purpose
- Push notification delivery to Android and web users.
- Data categories
- Device registration tokens, user identifiers, notification title and body, event metadata.
- Location
- United States
- Transfer mechanism
- EU Standard Contractual Clauses, plus supplementary safeguards.
- Region it serves
- All
Apple Distribution International Ltd
- Purpose
- Push notification delivery to iOS users.
- Data categories
- Device tokens, notification title and body, event metadata.
- Location
- Ireland and United States
- Transfer mechanism
- Intra-EU for the Apple contracting entity. EU Standard Contractual Clauses cover any onward transfer to the United States.
- Region it serves
- All
Twilio SendGrid Inc.
- Purpose
- Transactional email delivery, including invitations, document share links, recovery emails, and one-time passcodes.
- Data categories
- Recipient email addresses and names, invitation tokens, portal and organisation names, email body content.
- Location
- United States
- Transfer mechanism
- EU Standard Contractual Clauses, plus supplementary safeguards.
- Region it serves
- All
Stripe Payments Europe Ltd
- Purpose
- Payment processing and billing.
- Data categories
- Customer email, billing name, payment-method metadata (last four digits, card brand, expiry; full card number never reaches Fidify), transaction amounts, subscription identifiers.
- Location
- Ireland, with onward processing in the United States for payment-network routing.
- Transfer mechanism
- Intra-EU primary. EU Standard Contractual Clauses for onward transfer to the United States.
- Region it serves
- All
Functional Software, Inc. (Sentry)
- Purpose
- Error monitoring across the Fidify Enterprise portal, the Fidify Business web app, platform services, and the mobile app.
- Data categories
- Stack traces, user identifiers, IP addresses, browser and device fingerprints, application event trails. Personal data is scrubbed before submission.
- Location
- European Union
- Transfer mechanism
- Intra-EU. No transfer mechanism required.
- Region it serves
- All
OpenAI Ireland Ltd
- Purpose
- AI inference for risk assessment, compliance narrative generation, and document analysis when a customer's AI policy selects OpenAI as the provider.
- Data categories
- Document text excerpts, policy prompts, extracted compliance fields. Content is not used to train OpenAI models.
- Location
- United States
- Transfer mechanism
- EU Standard Contractual Clauses, plus the OpenAI data-processing agreement.
- Region it serves
- All
Anthropic Ireland, Limited
- Purpose
- AI inference when a customer's AI policy selects Anthropic as the provider.
- Data categories
- Document text excerpts, policy prompts, extracted compliance fields. Content is not used to train Anthropic models.
- Location
- United States
- Transfer mechanism
- EU Standard Contractual Clauses, plus the Anthropic data-processing agreement.
- Region it serves
- All
LangChain, Inc. (LangSmith)
- Purpose
- AI observability and tracing.
- Data categories
- AI prompts and responses.
- Location
- European Union
- Transfer mechanism
- EU Standard Contractual Clauses.
- Region it serves
- All
Tavily AI Inc.
- Purpose
- Web search context retrieval for AI workflows, including compliance research and entity enrichment.
- Data categories
- Search queries, including entity and person names used as search terms.
- Location
- United States
- Transfer mechanism
- EU Standard Contractual Clauses.
- Region it serves
- All
Notification of changes
Before engaging a new sub-processor or replacing an existing one, Fidify notifies customers in line with section 5.2 of our Data Processing Agreement. Customers have fourteen (14) days from notice to object in writing.
Questions
For questions about this list or to request the signed records of processing activities, email dpo@fidify.se.
Related documents
- Data Processing Agreement: full contractual terms governing sub-processor use.
- Technical and Organisational Measures: security controls applied across Fidify and our sub-processors.
- Privacy Policy: how Fidify processes personal data overall.
- Trust and Security: certifications, audits, and controls summary.