Sub-processors

Last updated 19 August 2026

En termes simples

Running Twirl needs other companies. This page names every one of them that could touch personal data, what they do, and where the data sits. Your photos and your event data are both in Frankfurt, Germany.

Sur cette page

02Current subprocessors

Provider
OVH SAS
(OVHcloud)
Purpose
Object storage for photographs, videos and voice memos
Personal data involved
All uploaded media, including embedded file metadata such as timestamps, device information and any location data
Location
EU, Germany (Frankfurt)
Agreement
DPA in place. EEA processing, no transfer mechanism required. [VERIFY]
Provider
Supabase Inc.
Purpose
Database, organizer authentication, storage of event configuration and RSVP data
Personal data involved
Organizer accounts, event configuration, guest names, RSVP responses, media metadata
Location
EU, Germany (Frankfurt, eu-central-1)
Agreement
DPA in place. EU SCCs for any US access. [VERIFY]
Provider
Vercel Inc.
(Vercel EU entity where applicable)
Purpose
Application hosting, content delivery, serverless function execution
Personal data involved
All data passing through the application. Server logs including IP addresses.
Location
EU regions. Incorporated in the United States.
Agreement
DPA in place. EU SCCs (2021/914) and Data Privacy Framework for any US access. [VERIFY]
Provider
Stripe Payments Europe Ltd
(and Stripe group entities)
Purpose
Payment processing, VAT and sales tax calculation, invoicing, fraud prevention
Personal data involved
Organizer billing name, email, billing address, country, card data (held by Stripe, never by Twirl), transaction records
Location
Ireland, with group entities in the US and elsewhere
Agreement
Stripe DPA. EU SCCs and Data Privacy Framework for onward transfers.
Provider
Sendinblue SAS, trading as Brevo
Purpose
Transactional and lifecycle email delivery from hello@twirl.photos
Personal data involved
Organizer email address, email content, delivery and bounce status. Open tracking and click tracking are disabled, so no engagement data is collected.
Location
EU, France
Agreement
DPA in place. No transfer outside the EEA in normal operation.
Provider
Functional Software Inc., trading as Sentry
Purpose
Error and crash diagnostics
Personal data involved
Technical error context: stack traces, browser and device type, IP address, user identifier where present. Configured to exclude media content. Session Replay disabled.
Location
EU region (confirmed). Incorporated in the United States.
Agreement
DPA in place. EU SCCs and Data Privacy Framework.
Provider
Google Ireland Ltd
(Google Workspace)
Purpose
Personal data involved
Anything an organizer or guest chooses to send us by email, including rights requests and support correspondence
Location
EU, with Google group entities elsewhere
Agreement
Google Workspace DPA. EU SCCs and Data Privacy Framework.
Provider
[TOOL]
Purpose
Counting visits to the public marketing site only. Not used inside the product.
Personal data involved
None. The tool sets no cookies, stores nothing on the device and does not identify visitors. It produces aggregate counts only.
Location
EU
Agreement
EEA processing. No transfer mechanism required.

03Common commitments

Every provider above is bound by a written agreement meeting Article 28 of the GDPR, under which they:

  • Process personal data only on our documented instructions.
  • Keep it confidential and restrict access to those who need it.
  • Maintain appropriate technical and organisational security measures.
  • Assist us in responding to data subject rights requests.
  • Notify us of personal data breaches without undue delay.
  • Delete or return data at the end of the relationship.
  • Do not use customer data to train machine learning or artificial intelligence models. [TO VERIFY AGAINST EACH PROVIDER'S CURRENT TERMS]

04Deliberately not listed

Provider
Namecheap
Role
Domain registration and DNS
Why it is not a subprocessor
Resolves domain names. Does not receive, store or process personal data from the service.
Provider
GitHub
Role
Source code hosting
Why it is not a subprocessor
Holds application code, not customer data. Production data is never committed to the repository.
Provider
CDN edge providers used by Vercel
Role
Content delivery
Why it is not a subprocessor
Covered within the Vercel entry rather than listed separately. [VERIFY whether a separate listing is warranted.]

If any of these ever begins processing personal data, it moves into section 2 and the notice in section 5 applies.

05Changes to this list

  • We give at least 30 days' notice before adding or replacing a subprocessor.
  • Notice is given by email to organizers with an active event, and by updating this page.
  • Organizers can object on reasonable data protection grounds within 30 days, under section 7.4 of the Data Processing Agreement. If we cannot resolve the objection, the organizer can terminate and receive a pro rata refund of the unused window.
  • Where a change is urgent and necessary for security, we may act first and notify as soon as possible. The objection right still applies afterwards.
  • We will not move media storage outside the European Economic Area. That is a commitment, not a current arrangement that might quietly change. To be notified of changes, email privacy@twirl.photos with "subprocessor notifications" in the subject line.

06Contact

Questions about anyone on this list, or requests for a copy of a transfer mechanism: privacy@twirl.photos. Commercial terms may be redacted from any document we send.

Ciceroni VOF, KVK 76619176, Franklinstraat 161, 2562 CD Den Haag, the Netherlands.