Naar inhoud

Who processes data on our behalf

To run OwndUp we use a small number of carefully chosen service providers. Here is who they are, what we use them for, and where they process data. We conclude a data processing agreement with each of them, and where that is not yet in place we say so.

TransIP

Hosting of the application, the database and the backups, and management of our domain names. This is the party where your list data physically sits.

Location: The Netherlands. TransIP is a Dutch company and the servers sit in Dutch data centres.

Data handling: Stores your data for as long as your account is active; exportable at any time and removed on request. We make a full copy of the database every day, kept for 14 days, and a weekly copy kept for 120 days.

HostingU2

Sending transactional email such as sign-in links, reminders and the weekly digest. HostingU2 provides our mail environment, through the mailplatform.eu platform. Because the sign-in links pass through here, this party can see those emails go by.

Location: Within the EU. The mail runs over the servers of mailplatform.eu.

Data handling: Processes the recipient address and message content only to deliver the email. A subject line may contain the name of a row.

Stripe

Payment processing for paid subscriptions. OwndUp never sees your full card details.

Location: Ireland (Stripe Payments Europe), with safeguards for any transfer outside the EU.

Data handling: Handles billing and payment data for as long as needed to run and account for your subscription.

Mistral AI

Document extraction. When you read a row from a PDF, the file is sent to Mistral to pull the fields out. The feature is available on Business and Continuity, and an administrator can switch it off for the whole organisation.

Location: France (Paris), within the EU.

Data handling: We do not store the file ourselves. Mistral keeps it for at most 30 days (rolling) for abuse monitoring, and does not use it to train models.

Sentry

Receiving technical error reports, so we can find and fix an outage. Errors only, no usage statistics.

Location: Sentry is a US company and offers both an EU and a US region. We will state here which region our project runs in as soon as that is recorded.

Data handling: The integration is configured so that no email addresses and no IP addresses are sent along. What does go across is the type of error, the stack trace and the environment. The text of an error may unintentionally contain data.

We keep this list current. If we add or change a subprocessor, we update this page, and where our agreement with you requires it, we let you know at least 30 days in advance, with a right to object. Questions about how we handle data are covered in our privacy statement.