Legal · Annex III

Sub-processors

Last reviewed: 24 September 2026

A stable using Equidentity is the controller of its members' data. Equidentity is its processor. Every company Equidentity uses that touches that data is a sub-processor. This page lists them, as required by GDPR art. 28(2)/(4), so a stable (or anyone it answers to, such as a federation or sport authority) can see who else has access.

This page is Annex III of Equidentity's Data Processing Agreement (DPA). Under DPA §7.1/§7.2 and GDPR art. 28(2), it is updated at least 30 days before any new sub-processor goes live, giving every stable time to object on reasonable data-protection grounds.

Current sub-processors

Sub-processor Service Personal data Processing location Used when Transfer safeguard
Google Ireland Ltd.
(Google Cloud / Firebase)
Firestore database (eur3 = Belgium + Netherlands), Cloud Functions (europe-west1, Belgium; one Storage trigger in us-east1), App Hosting SSR (europe-west4, Netherlands), Cloud Storage for uploaded files (us-east1, USA), Firebase Authentication, Cloud Messaging (push), Cloud Logging All platform data EU, except uploaded files (photos, horse/member documents, invoice PDFs) → USA. Google support/SRE may access from outside the EU Always Google Cloud DPA (CDPA) + SCCs; Google LLC is certified under the EU-US Data Privacy Framework (DPF)
Google Ireland Ltd.
(reCAPTCHA Enterprise / Firebase App Check)
Bot and abuse detection on login and forms IP address, browser signals Global Only in signed-in areas, on the login page and shared document links, and once a visitor starts filling in a form; never while an anonymous visitor reads public pages CDPA + SCCs / DPF
Google Ireland Ltd.
(Vertex AI: Gemini 2.5 Flash, text-embedding-004)
Support assistant, AI passport scan Chat text (may contain name, email, phone), passport images (owner name/address) EU (europe-west1, Belgium) Only when the stable enables Support chatbot or AI passport scan CDPA. Google does not train on customer data (Vertex AI terms)
Cloudflare, Inc. DNS, TLS, CDN, WAF, bot protection in front of every tenant domain IP address, request metadata; pages in transit (TLS terminated at the edge) Global edge network Always (proxied tenants) Cloudflare DPA + SCCs; DPF certified
Resend
(Plus Five Five, Inc.)
Transactional email: account invitations, password resets, invoices, payment reminders, admin digests Recipient name + email, email content (may include invoice data) USA Always EU-U.S. DPF (active, verified 25 September 2026) + Resend DPA with SCCs, binding on all plans via the Terms of Service
GitHub, Inc.
(Microsoft)
Issue tracker for bug reports filed by stable admins from the support assistant Admin's report text + up to 6 recent chat messages (emails and phone numbers redacted; other free text may contain names). The submitter is not recorded USA Only with Support chatbot, only when an admin confirms filing a bug GitHub DPA + SCCs; DPF certified
Billit NV Accounting sync + Peppol e-invoicing Customer name, address, VAT number, invoice lines Belgium Only if the stable connects Billit Within EU
Yuki
(Visma)
Accounting sync Customer name, address, VAT number, invoice lines Netherlands / EU Only if the stable connects Yuki Within EU

International transfers

Structured data is stored in the EU (Firestore eur3, Cloud Functions in Belgium, SSR in the Netherlands). Transfers outside the EEA happen in these cases:

Flow Destination Safeguard Risk note
Uploaded files in the Cloud Storage bucket (US-EAST1), plus the document-processing trigger that must run next to it USA Google CDPA with SCCs; Google LLC DPF certified Largest transfer. Photos, X-rays, export certificates, passports and member documents can show owner names and addresses. Encrypted at rest and in transit. Accepted and disclosed as of 24 September 2026, not migrated. Revisited if the DPF is invalidated or a customer requires EU-only hosting
Transactional email via Resend USA DPF (active, non-HR data, re-certification due 3 March 2027); SCCs (module 3) in Resend's DPA as fallback Content is limited to what the email says. Encrypted in transit (TLS). Low sensitivity
Admin bug reports to GitHub USA GitHub DPA, SCCs, DPF Admin-initiated only, capped at 6 context messages with contact details redacted, no submitter identity, 10 reports/tenant/month. Low volume
Cloudflare edge Nearest PoP (mostly EU for Belgian visitors) Cloudflare DPA, SCCs, DPF Transit only, no storage of content
Google support/SRE access, reCAPTCHA Possibly USA Google CDPA, SCCs, DPF Access is exceptional and logged by Google (Access Transparency available on paid support tiers)

The EU-US Data Privacy Framework has an adequacy decision (July 2023). For certified US recipients this is the legal basis, with the Standard Contractual Clauses remaining as a fallback if the framework is struck down. This page is re-checked if a court invalidates the DPF.