Subprocessor List
Draft — not yet in force. These documents are shared for transparency and are pending legal review. They are not the final, binding terms until published at launch.
DRAFT for legal review — not final, not in force. See 00-README. This is the authoritative subprocessor list referenced by the Privacy Policy and the DPA (it populates DPA Annex IV / SCC Annex III). `` = lawyer to verify.
Controller/Processor: CIQRA OÜ, registry code 16465907, Tallinn, Estonia · privacy@ciqra.com Version: 1.0-draft · Last updated: 2026-07-08 · Change notice: additions/replacements announced ≥30 days in advance with a Merchant objection right (DPA §5).
1. How to read this list
- CIQRA engages the third parties below to process personal data on its behalf (as subprocessors where CIQRA is a processor for Merchant data, or as processors where CIQRA is a controller for its own data).
- Core processing is EU-native. All hosting, compute, database, storage and secrets run on Microsoft Azure in Germany (Germany West Central / Germany North). For those, there is no transfer of personal data outside the EU/EEA for core processing.
- SCCs are only needed for the non-EEA-touching providers (e.g. Stripe's US flows, OpenAI/Anthropic US inference, Cloudflare's US parent). Those rows are marked “SCCs”.
- Stripe is listed for completeness but acts largely as an independent controller/processor for payment data under its own terms, not merely as CIQRA's subprocessor.
- Consent-based recipients (ad/analytics platforms) and Merchant-opted-in recipients (marketplace channels) process personal data only where the relevant Merchant/end-user has enabled them; for those, the Merchant is typically the controller (CIQRA provides the integration + consent gating).
- "SCCs" = EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), plus UK IDTA/Addendum for UK transfers and Swiss amendments where relevant; CIQRA maintains a Transfer Impact Assessment for restricted transfers (DPA §11.2).
2. Core platform subprocessors (always engaged)
| # | Subprocessor (legal entity) | Purpose / service | Personal data | Location | Transfer basis |
|---|---|---|---|---|---|
| 1 | Microsoft Azure (Microsoft Ireland Operations Ltd / Microsoft Corp.) — Azure Container Apps (compute), Azure Database for PostgreSQL Flexible Server (data), Azure Blob Storage (media), Azure Key Vault (secrets/keys) | Hosting, compute, database, media storage, secrets/key management | All hosted platform data | EU — Germany West Central (Frankfurt), primary; Germany North, paired DR | Intra-EEA (no core-processing transfer outside EU); SCCs only for any US-parent support access `` |
| 2 | Cloudflare, Inc. | CDN, DNS, WAF, DDoS mitigation, bot protection | Traffic metadata, IP, request headers | Global edge; EU data-localization applied to EU traffic | SCCs (US entity) `` |
| 3 | Microsoft — Azure Communication Services (ACS) Email | Transactional email delivery (primary) | Recipient email, name, message content | EU (Germany/EU region) | Intra-EEA; SCCs only for any US-parent access `` |
| 4 | Amazon Web Services — SES (Amazon Web Services EMEA SARL) | Transactional email delivery (fallback only) | Recipient email, name, message content | EU region | Intra-EEA; SCCs for any US-parent access `` |
| 5 | Grafana Labs — Grafana Cloud (EU) | Observability — metrics, logs, traces (OpenTelemetry) | Telemetry, limited PII (IP, user/tenant id) | EU region | Intra-EEA; SCCs if US access `` |
| 6 | Functional Software, Inc. — Sentry (EU region) | Error monitoring / crash diagnostics | Error/diagnostic data, limited PII | EU data residency (Sentry EU) | Intra-EEA; SCCs if US access `` |
Search (Typesense) runs self-hosted on CIQRA's Azure infrastructure in Germany and is an internal component, not a separate subprocessor — search index/query data does not leave the EU or reach a third party.
3. Payments (independent controller/processor)
| # | Party | Purpose | Personal data | Location | Basis |
|---|---|---|---|---|---|
| 7 | Stripe (Stripe Payments Europe, Ltd. — Ireland; Stripe, Inc. — US) | Payment processing, Stripe Connect, KYC/KYB, fraud, payouts | Payment/transaction data, KYC/beneficial-owner data (no raw PAN on CIQRA — SAQ A; PCI shifted to Stripe) | EU + US | Stripe's own terms + SCCs for US flows; Stripe is largely an independent controller/processor `` |
4. AI subprocessors (feature-triggered; zero-retention / no-training)
| # | Party | Purpose | Personal data | Location | Basis |
|---|---|---|---|---|---|
| 8 | OpenAI (OpenAI Ireland Ltd / OpenAI, L.L.C.) | LLM inference for AI features | Minimised feature inputs/outputs | EU/US | No-training-on-customer-data by default (business/API terms) + SCCs for US inference `` |
| 9 | Anthropic (Anthropic Ireland, Ltd / Anthropic, PBC) | LLM inference for AI features | Minimised feature inputs/outputs | EU/US | No-training-on-customer-data (Commercial Terms) + SCCs for US inference `` |
AI subprocessors receive data only when a Merchant/user invokes an AI feature, and only the minimised input needed. AI routing/guardrails run through a self-hosted gateway on Azure. See the AI Terms.
5. Consent-based & Merchant-opt-in recipients (not default subprocessors)
Process personal data only where enabled by the relevant Merchant/end-user; the Merchant is typically the controller.
| # | Party | Purpose | Trigger | Basis |
|---|---|---|---|---|
| 10 | Google (Ireland Ltd) — GA4 / Tag Manager / Google Ads | Analytics & advertising | Cookie/ad consent | Consent + SCCs `` |
| 11 | Meta Platforms (Ireland Ltd) — Pixel & Conversions API | Advertising measurement (incl. server-side) | Cookie/ad consent | Consent + SCCs; possible joint controllership (Fashion ID) `` |
| 12 | TikTok (Technology Ltd, Ireland) | Advertising measurement | Cookie/ad consent | Consent + SCCs `` |
| 13 | Marketplace channels (as connected by the Merchant) | Channel listing & order sync | Merchant opt-in connection | Per channel; transfer safeguards `` |
6. Professional & occasional recipients
Auditors, legal/financial advisers, and authorities — only where legally required or to establish/defend legal claims; and an acquirer/successor in a corporate transaction (subject to confidentiality). Not ongoing subprocessors.
7. Change management
- CIQRA notifies Controllers of intended additions or replacements ≥30 days in advance (subprocessor page + email/subscription), with a reasonable-grounds objection right (DPA §5.2) and an emergency-addition carve-out for security/continuity (DPA §5.3).
- `` before launch: confirm each entity's exact legal name, contracting entity, current DPA/SCC execution, and data location against the production stack.
End of Subprocessor List (draft). Referenced by: Privacy Policy · DPA (Annex IV / SCC Annex III).