ExactFlow p.s.a. Subprocessor List

All third-party processors engaged by ExactFlow p.s.a. to process personal data on behalf of Platform Clients

Effective Date: 1 April 2026   |   Version 1.0   |   Review Cycle: Quarterly   |   Governing Instrument: GDPR Article 28(2)–(4)

Data ControllerExactFlow p.s.a. — acting as Data Processor for Platform Clients
Purpose of this ListGDPR Article 28(2) requires ExactFlow to inform Clients of sub-processors and obtain general or specific Client consent before engaging new sub-processors
Consent ModelGeneral prior authorisation — Clients consent to sub-processors listed here at contract inception. Clients will receive 30 days' advance notice of new or changed sub-processors and may object per Section 4
Data Contactprivacy@exactflow.com
DPA ReferenceExactFlow Data Processing Agreement, Annex 3

This list reflects sub-processors engaged by ExactFlow as of the Effective Date above. ExactFlow reviews this list quarterly. Clients subscribed to sub-processor change notifications will receive email alerts automatically. All sub-processors are bound by Data Processing Agreements (DPAs) incorporating Standard Contractual Clauses (SCCs) where required for international transfers.

1. Infrastructure and Cloud Hosting

Sub-ProcessorService ProvidedData Categories ProcessedProcessing LocationTransfer MechanismCertifications
EU-based Cloud Provider (Tier 1)Primary cloud infrastructure — compute, storage, databases, networking for all Platform servicesAll personal data categories hosted on the PlatformEU / EEA (Poland / Germany)EEA — no transferISO 27001; SOC 2 Type II; PCI-DSS
Content Delivery Network (CDN)Global content delivery for static assets and mediaAnonymised request metadata, IP addresses (transient)EU PoPs primary; global edge nodesSCCs (EU–US)ISO 27001
Backup and Disaster Recovery ProviderEncrypted data backup and geo-redundant replicationAll Platform data categories (encrypted at rest)EU / EEAEEA — no transferISO 27001; SOC 2 Type II

2. Payment Processing

Sub-ProcessorService ProvidedData Categories ProcessedProcessing LocationTransfer MechanismCertifications
Primary Payment GatewayCard payment authorisation, 3DS authentication, transaction processingPayment method type, tokenized card references, billing address, transaction amount and referenceEU / EEAEEA — no transferPCI-DSS Level 1; ISO 27001
Alternative Payment Methods ProviderProcessing of BLIK, bank transfer, and local EU payment methodsPayment method identifiers, bank references, transaction dataEU / EEAEEA — no transferPCI-DSS; applicable national payment regulation
Escrow Services ProviderHolding Transaction funds pending delivery confirmation and withdrawal period expiryTransaction identifiers, seller and buyer account references, amountsEU / EEAEEA — no transferISO 27001; regulated payment institution
Fraud Scoring ServiceReal-time transaction risk assessment and fraud signal analysisIP address, device fingerprint, transaction velocity signals, pseudonymized user identifierEU / EEA + USSCCs (EU–US); adequacy where applicableSOC 2 Type II; PCI-DSS

3. Communications and Customer Support

Sub-ProcessorService ProvidedData Categories ProcessedProcessing LocationTransfer MechanismCertifications
Transactional Email ProviderSending order confirmations, system notifications, account alerts, password resetsEmail address, name, message content, delivery metadataEU / EEAEEA — no transferISO 27001; SOC 2 Type II
Marketing Email PlatformSending opt-in marketing communications and newsletters (consent-gated only)Email address, name, consent preferences, campaign interaction dataEU / EEAEEA — no transferISO 27001; GDPR-compliant DPA
Help Desk / Support PlatformManaging customer support tickets, chat, and knowledge baseName, email, support ticket content, account identifiersEU / EEAEEA — no transferISO 27001; SOC 2 Type II
SMS / Notification ProviderSending SMS order updates and two-factor authentication codesMobile telephone number, message content (OTP codes)EU / EEAEEA — no transferISO 27001
Video Conferencing (Client Success)Onboarding calls, training sessions, support screen-shares with Client teamsName, email, video/audio session data (not recorded without consent)EU / EEAEEA — no transferISO 27001; SOC 2 Type II

4. Analytics and Monitoring

Sub-ProcessorService ProvidedData Categories ProcessedProcessing LocationTransfer MechanismCertifications
Web Analytics PlatformAnonymized website and Platform usage analytics (consent-gated for non-essential cookies)Anonymized/pseudonymized behavioural and technical data; IP addresses anonymized within 24hEU / EEAEEA — no transferISO 27001; GDPR Mode enabled
Application Performance MonitoringReal-time Platform uptime, error rate, and latency monitoringAnonymized request metadata, error logs (no personal data in standard configuration)EU / EEAEEA — no transferISO 27001; SOC 2 Type II
Security Information & Event Management (SIEM)24/7 security monitoring, anomaly detection, audit log managementAccess logs, IP addresses, session identifiers, security event dataEU / EEAEEA — no transferISO 27001
A/B Testing and Feature FlaggingControlled rollout of new features and UX experiments (consent-gated)Pseudonymized user identifiers, feature interaction dataEU / EEAEEA — no transferGDPR-compliant DPA

5. Identity Verification and Compliance

Sub-ProcessorService ProvidedData Categories ProcessedProcessing LocationTransfer MechanismCertifications
KYB / Business Verification ProviderKnow Your Business verification for Seller onboarding — company registration, director identity, AML screeningBusiness name, registration number, director names, beneficial ownership data, sanctions screening dataEU / EEAEEA — no transferISO 27001; AML Act compliance; regulated entity
Sanctions and PEP ScreeningOngoing screening of Sellers and Buyers against EU, UN, OFAC sanctions lists and PEP databasesBusiness identity, director names, jurisdictionsEU / EEA + USSCCs (EU–US)ISO 27001; regulated compliance service
Electronic Signature ProviderDigital signing of Platform agreements and DPAs by Client administratorsName, email address, signature metadata, IP address, timestampEU / EEAEEA — no transfereIDAS compliant; ISO 27001

6. Logistics and Integrations

Sub-ProcessorService ProvidedData Categories ProcessedProcessing LocationTransfer MechanismCertifications
Logistics and Carrier API AggregatorIntegration layer connecting Platform to shipping carriers for label generation and trackingRecipient name, delivery address, Order reference, package detailsEU / EEAEEA — no transferISO 27001
Third-Party Marketplace Connectors (Amazon, eBay, Allegro, Shopify, etc.)API integrations enabling Clients to sync inventory, orders, and listings across sales channelsProduct data, Order data, account credentials (encrypted)Varies by platform — EU and non-EUSCCs where non-EEAPer platform certification
ERP / Warehouse Management Integration MiddlewareMiddleware enabling Clients to connect own ERP or WMS systems to ExactFlowInventory, Order, and supplier data as configured by ClientEU / EEA (middleware layer)EEA — no transferISO 27001

7. AI Agent Infrastructure

Sub-ProcessorService ProvidedData Categories ProcessedProcessing LocationTransfer MechanismCertifications
AI Model Inference ProviderHosting and serving the underlying language model inference for ExactFlow's AI AgentsPseudonymized query data and context passed to model for inference; no persistent storage of personal data by inference layerEU / EEAEEA — no transferISO 27001; SOC 2 Type II; EU AI Act compliance documentation maintained
AI Training Data InfrastructureSecure storage and processing environment for ExactFlow AI model training and fine-tuning (no personal data from production)Anonymized and synthetic training datasets only — no production personal dataEU / EEAEEA — no transferISO 27001

8. Sub-Processor Change Procedure

ExactFlow will notify Clients of any intended addition or replacement of a sub-processor by:

  • Updating this Subprocessor List on the ExactFlow website and in the Platform's legal documentation section
  • Sending an email notification to the Client's registered Data Protection Contact or Account Administrator at least 30 calendar days before the change takes effect
  • Publishing a changelog entry in the Platform dashboard

Clients who have a legitimate data protection objection to a new or changed sub-processor may notify ExactFlow in writing at privacy@exactflow.com within 14 calendar days of the notification. ExactFlow will work with the Client to resolve the objection. If the objection cannot be resolved, either party may terminate the affected services with 30 days' written notice without penalty.

All sub-processors listed in this document have been assessed by ExactFlow's Data Protection Officer and are bound by GDPR Article 28-compliant Data Processing Agreements incorporating Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) where required for international transfers. Transfer Impact Assessments (TIAs) are maintained for all non-EEA transfers.

— END OF SUBPROCESSOR LIST — EXACTFLOW P.S.A. —

ExactFlow Subprocessor List