Sub-processors

Version 1.0 — last updated: 1 October 2026

opexONE is operated by plusRS OÜ. To deliver the service, we engage the third-party sub-processors below to process customer (tenant) personal data on our behalf. They are technical infrastructure and service providers that do not process customer data for their own purposes. Each works under its own data-processing agreement and security standards, and we bind each to obligations no less protective than those in our Data Processing Agreement. We announce any intended addition or replacement on this page at least 30 days before it takes effect, as set out in the DPA.

Sub-processorStatusPurposeLocationTransfer safeguard

Amazon Web Services

Amazon Web Services, Inc. / Amazon Web Services EMEA SARL

Active

Cloud hosting, application delivery, file storage, and transactional email (SES).

EU (Frankfurt, eu-central-1) by default; primary storage of customer data remains in the EU/EEA.

Covered under the Amazon.com, Inc. EU–US Data Privacy Framework certification; EU Standard Contractual Clauses as the fallback.

Supabase

Supabase Pte. Ltd., 65 Chulia Street #38-02/03, OCBC Centre, Singapore

Active

Managed database, authentication, file storage, and serverless functions — the core data platform.

Hosted on AWS in the region configured for the deployment (EU by default).

EU Standard Contractual Clauses under the Supabase Data Processing Addendum (Schedule 2); data held in the configured region.

Stripe

Stripe Payments Europe, Ltd. (Ireland)

Active

Subscription billing and payment processing. Card data goes directly to Stripe; plusRS never receives it.

EEA (Ireland), with onward transfers within the Stripe group.

EEA contracting entity + EU Standard Contractual Clauses for onward transfers.

Microsoft 365

Microsoft Ireland Operations Limited (Microsoft Corporation)

Active

Support and business email correspondence — Exchange Online, OneDrive, SharePoint (processes customer data only where the customer or its users send it to plusRS by email, e.g. in support requests).

EU/global, per Microsoft 365 configuration.

Microsoft Corporation is EU–US Data Privacy Framework certified; EU Standard Contractual Clauses as the fallback.

Bird (MessageBird)

Bird B.V. (formerly MessageBird B.V.), Keizersgracht 268, Amsterdam, Netherlands — KvK 51874474

Active

SMS delivery for login and phone-number verification codes (one-time passcodes). Bird receives the recipient phone number and the code text; the code itself is generated and verified by our authentication platform, never by Bird.

EU region (eu1): our Bird organization is region-pinned, so message and recipient data is stored and processed in the EU and never replicated across regions. SMS termination via telecom carriers in the recipient’s country.

EEA contracting entity (Bird B.V., Netherlands governing law); Bird DPA with EU Standard Contractual Clauses for onward transfers; Bird’s US affiliate (Bird.com Inc.) is EU–US Data Privacy Framework certified. ISO/IEC 27001:2022 and SOC 2 Type 2 attested.

KLIPY

KLIPY (klipy.com)

Active

GIF and sticker search inside in-app discussions. The search is proxied through our backend (the Klipy API key stays server-side); Klipy receives the typed search term, not message content. Selected GIFs and previews are then loaded by your browser directly from the Klipy CDN — see the "Third-party embeds" section below. Per-tenant admins can disable GIFs/stickers entirely.

Global content-delivery network.

EU Standard Contractual Clauses where applicable; only search terms are sent, no customer records are stored by the search.

GitHub

GitHub, Inc. (United States)

Active

Processing of the product-feedback reports users submit in the app, in our vendor-hosted issue tracker, as plusRS’s own (controller) processing under DPA § 1.2 and Terms of Use § 33.4; listed for transparency only. The report text and technical context are transmitted; email addresses are automatically redacted before transmission. Attachments are not transmitted — they stay stored in the EU and are referenced by expiring links.

United States (github.com offers no EU residency option).

EU–US Data Privacy Framework and EU Standard Contractual Clauses under the GitHub Data Protection Agreement.

Apple Push Notification service

Apple Inc. (United States)

Active

Delivery of push notifications to the iOS app — device push tokens and a short alert with a link to the record; no record content.

United States.

Apple Inc. is EU–US Data Privacy Framework certified; EU Standard Contractual Clauses as the fallback.

Google Firebase Cloud Messaging

Google Ireland Limited (Google LLC)

Active

Delivery of push notifications to the Android app — device push tokens and a short alert with a link to the record; no record content.

EEA contracting entity; Google LLC (United States) as part of the service.

Google LLC is EU–US Data Privacy Framework certified; EU Standard Contractual Clauses as the fallback.

Amazon Web Services (Bedrock)

Amazon Web Services EMEA SARL (Amazon Web Services, Inc.)

Active

AI inference for the opexONE AI features — transient processing of the prompts and workspace content submitted by the requesting user; no data retention and no model training by the model service.

EU regions only.

Covered under the Amazon.com, Inc. EU–US Data Privacy Framework certification; EU Standard Contractual Clauses as the fallback.

Third-party embeds

The parties below are not sub-processors: they do not process customer data on our behalf, and we have no data-processing agreement with them. They are listed because your browser contacts them directly when it renders part of the application, which means they observe your IP address. Since an IP address is personal data, we disclose them in full. The application enforces a Content-Security-Policy allow-list, so no third-party host can appear in the application without appearing here.

EmbedWhat it isWhat they receiveWhen it loadsLocation

OpenStreetMap

OpenStreetMap Foundation (a non-profit company registered in England & Wales)

The map showing the approximate location of a sign-in, in Account → Security. It is an embedded map frame served by OpenStreetMap; we use it so that no map data or account information has to be sent to a commercial mapping provider.

The viewer’s IP address and browser user-agent (as with any web request), and the approximate coordinates of the map view being displayed — i.e. the rough location of the sign-in being looked at. No account identifier, name, email, or other tenant data is sent.

Only on the Account → Security page, and only for sessions whose location could be estimated. The map for the device you are currently using is expanded by default, so it loads when you open that page; maps for your other devices load only if you expand them. Users who never open Account → Security never contact OpenStreetMap.

United Kingdom, plus OpenStreetMap’s content-delivery network.

Cloudflare Turnstile

Cloudflare, Inc. (United States — EU–US Data Privacy Framework certified)

The bot-protection challenge on the sign-in page. It distinguishes humans from automated abuse before authentication — a strictly-necessary security function of the login.

The viewer’s IP address, browser user-agent, and the technical browser signals the challenge evaluates. No credentials (the challenge runs before and separately from password entry), no account identifier, and no tenant data.

On every sign-in page load. Signing in is not possible without it — it is part of protecting all tenants’ accounts against automated attacks.

Cloudflare’s global anycast network.

Klipy media delivery

KLIPY (klipy.com)

Delivery of GIF/sticker media in discussions. The search itself is proxied through our backend (see the sub-processor entry above), but media previews and selected GIFs are fetched by your browser directly from the Klipy CDN.

The viewer’s IP address and browser user-agent when GIF content renders. Klipy does not receive message content, account identifiers, or tenant data through media delivery.

Only in discussions where GIF/sticker content appears, and only if your organisation has GIFs/stickers enabled (per-tenant admins can disable them entirely).

Global content-delivery network.

Questions about our sub-processors, or want to subscribe to change notifications? Email privacy@plusrs.com. See also our privacy policy and Data Processing Agreement.