Skip to content
CIQRA
All legal documents

Subprocessor List

Draft — not yet in force. These documents are shared for transparency and are pending legal review. They are not the final, binding terms until published at launch.


DRAFT for legal review — not final, not in force. See 00-README. This is the authoritative subprocessor list referenced by the Privacy Policy and the DPA (it populates DPA Annex IV / SCC Annex III). `` = lawyer to verify.

Controller/Processor: CIQRA OÜ, registry code 16465907, Tallinn, Estonia · privacy@ciqra.com Version: 1.0-draft · Last updated: 2026-07-08 · Change notice: additions/replacements announced ≥30 days in advance with a Merchant objection right (DPA §5).


1. How to read this list

  • CIQRA engages the third parties below to process personal data on its behalf (as subprocessors where CIQRA is a processor for Merchant data, or as processors where CIQRA is a controller for its own data).
  • Core processing is EU-native. All hosting, compute, database, storage and secrets run on Microsoft Azure in Germany (Germany West Central / Germany North). For those, there is no transfer of personal data outside the EU/EEA for core processing.
  • SCCs are only needed for the non-EEA-touching providers (e.g. Stripe's US flows, OpenAI/Anthropic US inference, Cloudflare's US parent). Those rows are marked “SCCs”.
  • Stripe is listed for completeness but acts largely as an independent controller/processor for payment data under its own terms, not merely as CIQRA's subprocessor.
  • Consent-based recipients (ad/analytics platforms) and Merchant-opted-in recipients (marketplace channels) process personal data only where the relevant Merchant/end-user has enabled them; for those, the Merchant is typically the controller (CIQRA provides the integration + consent gating).
  • "SCCs" = EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), plus UK IDTA/Addendum for UK transfers and Swiss amendments where relevant; CIQRA maintains a Transfer Impact Assessment for restricted transfers (DPA §11.2).

2. Core platform subprocessors (always engaged)

#Subprocessor (legal entity)Purpose / servicePersonal dataLocationTransfer basis
1Microsoft Azure (Microsoft Ireland Operations Ltd / Microsoft Corp.) — Azure Container Apps (compute), Azure Database for PostgreSQL Flexible Server (data), Azure Blob Storage (media), Azure Key Vault (secrets/keys)Hosting, compute, database, media storage, secrets/key managementAll hosted platform dataEU — Germany West Central (Frankfurt), primary; Germany North, paired DRIntra-EEA (no core-processing transfer outside EU); SCCs only for any US-parent support access ``
2Cloudflare, Inc.CDN, DNS, WAF, DDoS mitigation, bot protectionTraffic metadata, IP, request headersGlobal edge; EU data-localization applied to EU trafficSCCs (US entity) ``
3Microsoft — Azure Communication Services (ACS) EmailTransactional email delivery (primary)Recipient email, name, message contentEU (Germany/EU region)Intra-EEA; SCCs only for any US-parent access ``
4Amazon Web Services — SES (Amazon Web Services EMEA SARL)Transactional email delivery (fallback only)Recipient email, name, message contentEU regionIntra-EEA; SCCs for any US-parent access ``
5Grafana Labs — Grafana Cloud (EU)Observability — metrics, logs, traces (OpenTelemetry)Telemetry, limited PII (IP, user/tenant id)EU regionIntra-EEA; SCCs if US access ``
6Functional Software, Inc. — Sentry (EU region)Error monitoring / crash diagnosticsError/diagnostic data, limited PIIEU data residency (Sentry EU)Intra-EEA; SCCs if US access ``

Search (Typesense) runs self-hosted on CIQRA's Azure infrastructure in Germany and is an internal component, not a separate subprocessor — search index/query data does not leave the EU or reach a third party.

3. Payments (independent controller/processor)

#PartyPurposePersonal dataLocationBasis
7Stripe (Stripe Payments Europe, Ltd. — Ireland; Stripe, Inc. — US)Payment processing, Stripe Connect, KYC/KYB, fraud, payoutsPayment/transaction data, KYC/beneficial-owner data (no raw PAN on CIQRA — SAQ A; PCI shifted to Stripe)EU + USStripe's own terms + SCCs for US flows; Stripe is largely an independent controller/processor ``

4. AI subprocessors (feature-triggered; zero-retention / no-training)

#PartyPurposePersonal dataLocationBasis
8OpenAI (OpenAI Ireland Ltd / OpenAI, L.L.C.)LLM inference for AI featuresMinimised feature inputs/outputsEU/USNo-training-on-customer-data by default (business/API terms) + SCCs for US inference ``
9Anthropic (Anthropic Ireland, Ltd / Anthropic, PBC)LLM inference for AI featuresMinimised feature inputs/outputsEU/USNo-training-on-customer-data (Commercial Terms) + SCCs for US inference ``

AI subprocessors receive data only when a Merchant/user invokes an AI feature, and only the minimised input needed. AI routing/guardrails run through a self-hosted gateway on Azure. See the AI Terms.

5. Consent-based & Merchant-opt-in recipients (not default subprocessors)

Process personal data only where enabled by the relevant Merchant/end-user; the Merchant is typically the controller.

#PartyPurposeTriggerBasis
10Google (Ireland Ltd) — GA4 / Tag Manager / Google AdsAnalytics & advertisingCookie/ad consentConsent + SCCs ``
11Meta Platforms (Ireland Ltd) — Pixel & Conversions APIAdvertising measurement (incl. server-side)Cookie/ad consentConsent + SCCs; possible joint controllership (Fashion ID) ``
12TikTok (Technology Ltd, Ireland)Advertising measurementCookie/ad consentConsent + SCCs ``
13Marketplace channels (as connected by the Merchant)Channel listing & order syncMerchant opt-in connectionPer channel; transfer safeguards ``

6. Professional & occasional recipients

Auditors, legal/financial advisers, and authorities — only where legally required or to establish/defend legal claims; and an acquirer/successor in a corporate transaction (subject to confidentiality). Not ongoing subprocessors.


7. Change management

  • CIQRA notifies Controllers of intended additions or replacements ≥30 days in advance (subprocessor page + email/subscription), with a reasonable-grounds objection right (DPA §5.2) and an emergency-addition carve-out for security/continuity (DPA §5.3).
  • `` before launch: confirm each entity's exact legal name, contracting entity, current DPA/SCC execution, and data location against the production stack.

End of Subprocessor List (draft). Referenced by: Privacy Policy · DPA (Annex IV / SCC Annex III).