Sub-processors
Last updated 19 August 2026
In einfachen Worten
Running Twirl needs other companies. This page names every one of them that could touch personal data, what they do, and where the data sits. Your photos and your event data are both in Frankfurt, Germany.
Auf dieser Seite
02Current subprocessors
Provider
OVH SAS
(OVHcloud)
(OVHcloud)
Purpose
Object storage for photographs, videos and voice memos
Personal data involved
All uploaded media, including embedded file metadata such as timestamps, device information and any location data
Location
EU, Germany (Frankfurt)
Agreement
DPA in place. EEA processing, no transfer mechanism required. [VERIFY]
Provider
Supabase Inc.
Purpose
Database, organizer authentication, storage of event configuration and RSVP data
Personal data involved
Organizer accounts, event configuration, guest names, RSVP responses, media metadata
Location
EU, Germany (Frankfurt, eu-central-1)
Agreement
DPA in place. EU SCCs for any US access. [VERIFY]
Provider
Vercel Inc.
(Vercel EU entity where applicable)
(Vercel EU entity where applicable)
Purpose
Application hosting, content delivery, serverless function execution
Personal data involved
All data passing through the application. Server logs including IP addresses.
Location
EU regions. Incorporated in the United States.
Agreement
DPA in place. EU SCCs (2021/914) and Data Privacy Framework for any US access. [VERIFY]
Provider
Stripe Payments Europe Ltd
(and Stripe group entities)
(and Stripe group entities)
Purpose
Payment processing, VAT and sales tax calculation, invoicing, fraud prevention
Personal data involved
Organizer billing name, email, billing address, country, card data (held by Stripe, never by Twirl), transaction records
Location
Ireland, with group entities in the US and elsewhere
Agreement
Stripe DPA. EU SCCs and Data Privacy Framework for onward transfers.
Provider
Sendinblue SAS, trading as Brevo
Purpose
Transactional and lifecycle email delivery from hello@twirl.photos
Personal data involved
Organizer email address, email content, delivery and bounce status. Open tracking and click tracking are disabled, so no engagement data is collected.
Location
EU, France
Agreement
DPA in place. No transfer outside the EEA in normal operation.
Provider
Functional Software Inc., trading as Sentry
Purpose
Error and crash diagnostics
Personal data involved
Technical error context: stack traces, browser and device type, IP address, user identifier where present. Configured to exclude media content. Session Replay disabled.
Location
EU region (confirmed). Incorporated in the United States.
Agreement
DPA in place. EU SCCs and Data Privacy Framework.
Provider
Google Ireland Ltd
(Google Workspace)
(Google Workspace)
Purpose
Business email for hello@twirl.photos and privacy@twirl.photos
Personal data involved
Anything an organizer or guest chooses to send us by email, including rights requests and support correspondence
Location
EU, with Google group entities elsewhere
Agreement
Google Workspace DPA. EU SCCs and Data Privacy Framework.
Provider
[TOOL]
Purpose
Counting visits to the public marketing site only. Not used inside the product.
Personal data involved
None. The tool sets no cookies, stores nothing on the device and does not identify visitors. It produces aggregate counts only.
Location
EU
Agreement
EEA processing. No transfer mechanism required.
| Provider | Purpose | Personal data involved | Location | Agreement |
|---|---|---|---|---|
| OVH SAS (OVHcloud) | Object storage for photographs, videos and voice memos | All uploaded media, including embedded file metadata such as timestamps, device information and any location data | EU, Germany (Frankfurt) | DPA in place. EEA processing, no transfer mechanism required. [VERIFY] |
| Supabase Inc. | Database, organizer authentication, storage of event configuration and RSVP data | Organizer accounts, event configuration, guest names, RSVP responses, media metadata | EU, Germany (Frankfurt, eu-central-1) | DPA in place. EU SCCs for any US access. [VERIFY] |
| Vercel Inc. (Vercel EU entity where applicable) | Application hosting, content delivery, serverless function execution | All data passing through the application. Server logs including IP addresses. | EU regions. Incorporated in the United States. | DPA in place. EU SCCs (2021/914) and Data Privacy Framework for any US access. [VERIFY] |
| Stripe Payments Europe Ltd (and Stripe group entities) | Payment processing, VAT and sales tax calculation, invoicing, fraud prevention | Organizer billing name, email, billing address, country, card data (held by Stripe, never by Twirl), transaction records | Ireland, with group entities in the US and elsewhere | Stripe DPA. EU SCCs and Data Privacy Framework for onward transfers. |
| Sendinblue SAS, trading as Brevo | Transactional and lifecycle email delivery from hello@twirl.photos | Organizer email address, email content, delivery and bounce status. Open tracking and click tracking are disabled, so no engagement data is collected. | EU, France | DPA in place. No transfer outside the EEA in normal operation. |
| Functional Software Inc., trading as Sentry | Error and crash diagnostics | Technical error context: stack traces, browser and device type, IP address, user identifier where present. Configured to exclude media content. Session Replay disabled. | EU region (confirmed). Incorporated in the United States. | DPA in place. EU SCCs and Data Privacy Framework. |
| Google Ireland Ltd (Google Workspace) | Business email for hello@twirl.photos and privacy@twirl.photos | Anything an organizer or guest chooses to send us by email, including rights requests and support correspondence | EU, with Google group entities elsewhere | Google Workspace DPA. EU SCCs and Data Privacy Framework. |
| [TOOL] | Counting visits to the public marketing site only. Not used inside the product. | None. The tool sets no cookies, stores nothing on the device and does not identify visitors. It produces aggregate counts only. | EU | EEA processing. No transfer mechanism required. |
03Common commitments
Every provider above is bound by a written agreement meeting Article 28 of the GDPR, under which they:
- Process personal data only on our documented instructions.
- Keep it confidential and restrict access to those who need it.
- Maintain appropriate technical and organisational security measures.
- Assist us in responding to data subject rights requests.
- Notify us of personal data breaches without undue delay.
- Delete or return data at the end of the relationship.
- Do not use customer data to train machine learning or artificial intelligence models. [TO VERIFY AGAINST EACH PROVIDER'S CURRENT TERMS]
04Deliberately not listed
Provider
Namecheap
Role
Domain registration and DNS
Why it is not a subprocessor
Resolves domain names. Does not receive, store or process personal data from the service.
Provider
GitHub
Role
Source code hosting
Why it is not a subprocessor
Holds application code, not customer data. Production data is never committed to the repository.
Provider
CDN edge providers used by Vercel
Role
Content delivery
Why it is not a subprocessor
Covered within the Vercel entry rather than listed separately. [VERIFY whether a separate listing is warranted.]
| Provider | Role | Why it is not a subprocessor |
|---|---|---|
| Namecheap | Domain registration and DNS | Resolves domain names. Does not receive, store or process personal data from the service. |
| GitHub | Source code hosting | Holds application code, not customer data. Production data is never committed to the repository. |
| CDN edge providers used by Vercel | Content delivery | Covered within the Vercel entry rather than listed separately. [VERIFY whether a separate listing is warranted.] |
If any of these ever begins processing personal data, it moves into section 2 and the notice in section 5 applies.
05Changes to this list
- We give at least 30 days' notice before adding or replacing a subprocessor.
- Notice is given by email to organizers with an active event, and by updating this page.
- Organizers can object on reasonable data protection grounds within 30 days, under section 7.4 of the Data Processing Agreement. If we cannot resolve the objection, the organizer can terminate and receive a pro rata refund of the unused window.
- Where a change is urgent and necessary for security, we may act first and notify as soon as possible. The objection right still applies afterwards.
- We will not move media storage outside the European Economic Area. That is a commitment, not a current arrangement that might quietly change. To be notified of changes, email privacy@twirl.photos with "subprocessor notifications" in the subject line.
06Contact
Questions about anyone on this list, or requests for a copy of a transfer mechanism: privacy@twirl.photos. Commercial terms may be redacted from any document we send.
Ciceroni VOF, KVK 76619176, Franklinstraat 161, 2562 CD Den Haag, the Netherlands.
