Contents
- Article 1 - Purpose
- Article 2 - Summary
- Article 3 - Details by provider
- Article 4 - Transfer framework
- Article 5 - Other recipients
- Article 6 - Use of new providers
- Article 7 - Contractual safeguards
This register lists the providers (sub-processors and recipients) that process personal data on behalf of Evorax Technologies, or are recipients of such data, in connection with the Noryo service. It is published in accordance with the transparency requirement of the GDPR and supplements the Privacy Policy.
Article 1 - Purpose
The purpose of this register is to inform the User of the identity, role and location of the providers used by the Publisher, as well as of the framework governing any transfers outside the European Union.
Article 2 - Summary
| Provider | Role | Location | Transfer framework |
|---|---|---|---|
| Supabase Inc. | database, authentication, application storage | European Union (Frankfurt) | European Union |
| Scaleway SAS | storage of documents and files | France (Paris) | European Union |
| Vercel Inc. | hosting of the website and interfaces | United States | standard contractual clauses |
| Twilio SendGrid | sending and receiving emails | United States | standard contractual clauses |
| Mistral AI | intelligent assistant and document recognition | European Union | European Union |
| Stripe Payments Europe, Ltd. | card payment (website) | Ireland (EU) | European Union |
| Apple Inc. | in-app purchases and iOS notifications | United States | standard contractual clauses |
| sign-in via Google (at the User's choice) | United States / EU | standard contractual clauses | |
| The ID Co. Limited (atto.co) | bank aggregation (PSD2), separate data controller | United Kingdom | adequacy decision |
Article 3 - Details by provider
3.1 Supabase
Provides the database, authentication and application storage. Data concerned: account, structured financial data, associated content. Location: European Union (Frankfurt).
3.2 Scaleway
Provides the storage of uploaded documents and files. Data concerned: documents, receipts, files. Location: France (Paris).
3.3 Vercel
Provides the hosting of the website and interfaces as well as the execution of application processing. Data concerned: technical operating data. Location: United States and European Union, under standard contractual clauses.
3.4 SendGrid
Provides the sending and receiving of service and support emails. Data concerned: email address, message content. Location: United States, under standard contractual clauses.
3.5 Mistral AI
Provides the intelligent assistant and document recognition. Data concerned: information useful to the response, transmitted in a limited manner. Location: European Union.
3.6 Stripe
Provides the processing of card payments made on the website. Data concerned: billing data, payment identifiers (without the full card number). Location: Ireland (European Union).
3.7 Apple
Provides in-app purchases and notifications on iOS. Data concerned: subscription identifiers, notification token. Location: United States, under standard contractual clauses.
3.8 Google
Enables sign-in via Google, at the User's choice. Data concerned: authentication data. Location: United States and European Union, under standard contractual clauses.
3.9 The ID Co. Limited (atto.co)
Provides bank aggregation (PSD2), as a separate data controller. Data concerned: account information, balances, transactions. Location: United Kingdom, under an adequacy decision.
Article 4 - Transfer framework
Transfers to the United States are governed by the standard contractual clauses adopted by the European Commission, supplemented where appropriate by additional measures. Transfers to the United Kingdom benefit from the adequacy decision. Processing carried out within the European Union does not constitute a transfer outside the Union.
Article 5 - Other recipients
Data may be disclosed to the competent administrative or judicial authorities where required by law, as well as to the Publisher's advisers bound by professional secrecy, to the strict extent necessary.
Article 6 - Use of new providers
This list is subject to change. Substantial changes are brought to the attention of Users by an appropriate means, enabling them, where applicable, to exercise their rights, in particular their right to object where it applies.
Article 7 - Contractual safeguards
Each sub-processor is bound by contractual commitments imposing appropriate safeguards in terms of security, confidentiality and data protection, in accordance with Article 28 of the GDPR.