Legal · Annex III
Sub-processors
Last reviewed: 24 September 2026
A stable using Equidentity is the controller of its members' data. Equidentity is its processor. Every company Equidentity uses that touches that data is a sub-processor. This page lists them, as required by GDPR art. 28(2)/(4), so a stable (or anyone it answers to, such as a federation or sport authority) can see who else has access.
This page is Annex III of Equidentity's Data Processing Agreement (DPA). Under DPA §7.1/§7.2 and GDPR art. 28(2), it is updated at least 30 days before any new sub-processor goes live, giving every stable time to object on reasonable data-protection grounds.
Current sub-processors
| Sub-processor | Service | Personal data | Processing location | Used when | Transfer safeguard |
|---|---|---|---|---|---|
| Google Ireland Ltd. (Google Cloud / Firebase) |
Firestore database (eur3 = Belgium + Netherlands), Cloud Functions (europe-west1, Belgium; one Storage trigger in us-east1), App Hosting SSR (europe-west4, Netherlands), Cloud Storage for uploaded files (us-east1, USA), Firebase Authentication, Cloud Messaging (push), Cloud Logging |
All platform data | EU, except uploaded files (photos, horse/member documents, invoice PDFs) → USA. Google support/SRE may access from outside the EU | Always | Google Cloud DPA (CDPA) + SCCs; Google LLC is certified under the EU-US Data Privacy Framework (DPF) |
| Google Ireland Ltd. (reCAPTCHA Enterprise / Firebase App Check) |
Bot and abuse detection on login and forms | IP address, browser signals | Global | Only in signed-in areas, on the login page and shared document links, and once a visitor starts filling in a form; never while an anonymous visitor reads public pages | CDPA + SCCs / DPF |
| Google Ireland Ltd. (Vertex AI: Gemini 2.5 Flash, text-embedding-004) |
Support assistant, AI passport scan | Chat text (may contain name, email, phone), passport images (owner name/address) | EU (europe-west1, Belgium) |
Only when the stable enables Support chatbot or AI passport scan | CDPA. Google does not train on customer data (Vertex AI terms) |
| Cloudflare, Inc. | DNS, TLS, CDN, WAF, bot protection in front of every tenant domain | IP address, request metadata; pages in transit (TLS terminated at the edge) | Global edge network | Always (proxied tenants) | Cloudflare DPA + SCCs; DPF certified |
| Resend (Plus Five Five, Inc.) |
Transactional email: account invitations, password resets, invoices, payment reminders, admin digests | Recipient name + email, email content (may include invoice data) | USA | Always | EU-U.S. DPF (active, verified 25 September 2026) + Resend DPA with SCCs, binding on all plans via the Terms of Service |
| GitHub, Inc. (Microsoft) |
Issue tracker for bug reports filed by stable admins from the support assistant | Admin's report text + up to 6 recent chat messages (emails and phone numbers redacted; other free text may contain names). The submitter is not recorded | USA | Only with Support chatbot, only when an admin confirms filing a bug | GitHub DPA + SCCs; DPF certified |
| Billit NV | Accounting sync + Peppol e-invoicing | Customer name, address, VAT number, invoice lines | Belgium | Only if the stable connects Billit | Within EU |
| Yuki (Visma) |
Accounting sync | Customer name, address, VAT number, invoice lines | Netherlands / EU | Only if the stable connects Yuki | Within EU |
International transfers
Structured data is stored in the EU (Firestore eur3, Cloud Functions in Belgium, SSR in the Netherlands). Transfers outside the EEA happen in these cases:
| Flow | Destination | Safeguard | Risk note |
|---|---|---|---|
| Uploaded files in the Cloud Storage bucket (US-EAST1), plus the document-processing trigger that must run next to it | USA | Google CDPA with SCCs; Google LLC DPF certified | Largest transfer. Photos, X-rays, export certificates, passports and member documents can show owner names and addresses. Encrypted at rest and in transit. Accepted and disclosed as of 24 September 2026, not migrated. Revisited if the DPF is invalidated or a customer requires EU-only hosting |
| Transactional email via Resend | USA | DPF (active, non-HR data, re-certification due 3 March 2027); SCCs (module 3) in Resend's DPA as fallback | Content is limited to what the email says. Encrypted in transit (TLS). Low sensitivity |
| Admin bug reports to GitHub | USA | GitHub DPA, SCCs, DPF | Admin-initiated only, capped at 6 context messages with contact details redacted, no submitter identity, 10 reports/tenant/month. Low volume |
| Cloudflare edge | Nearest PoP (mostly EU for Belgian visitors) | Cloudflare DPA, SCCs, DPF | Transit only, no storage of content |
| Google support/SRE access, reCAPTCHA | Possibly USA | Google CDPA, SCCs, DPF | Access is exceptional and logged by Google (Access Transparency available on paid support tiers) |
The EU-US Data Privacy Framework has an adequacy decision (July 2023). For certified US recipients this is the legal basis, with the Standard Contractual Clauses remaining as a fallback if the framework is struck down. This page is re-checked if a court invalidates the DPF.