Sub-processors and recipients
Every third party that can touch personal data, what it does, where it is, and whether it acts on our instructions or its own. The whole list, not a representative sample.
In force since
Who you are contracting with
- Company
- IRUKA DIGITAL spółka z ograniczoną odpowiedzialnością
- Registered office
- ul. Szczęsna 26, 02-454 Warszawa, Poland
- Registry court
- Sąd Rejonowy dla m.st. Warszawy w Warszawie, Wydział Gospodarczy Krajowego Rejestru Sądowego
- KRS
- 0000980870
- NIP
- 5223230254
- REGON
- 522516722
- EU VAT
- PL5223230254
- Share capital
- 5 000,00 PLN
- [email protected]
- Phone
- +48 690 164 776
What this page is for
Two obligations meet here. Article 13(1)(e) GDPR makes us tell you who receives personal data. Article 28(2) makes us tell our customers before we let a new sub-processor near the data they entrust to us. One published register satisfies both, and it means neither you nor a procurement team has to ask us for a list.
This page is Annex 3 of the data processing agreement. It is the same register, rendered from the same source.
How to read the two roles
Processor — acts only on our documented instructions, under a written contract that passes on every obligation we owe you, including the security measures and the transfer safeguards. We stay fully liable for what it does. These are sub-processors in the Article 28(4) sense.
Separate controller — receives personal data but decides its own purposes for at least part of what it does, so it is not our sub-processor and we cannot instruct it. Tpay is the case that matters: to execute and settle a payment, and to meet its own duties under payment-services law, anti-money-laundering law, accounting law and the card-scheme rules, Tpay decides for itself. It publishes its own privacy notice and you have the full set of GDPR rights against it directly, in addition to your rights against us. Describing Tpay as our processor would be convenient and wrong.
The rules we hold ourselves to
- We keep the list short. Every provider is a place data can go wrong, so a new one has to earn its place. The whole register is short enough to read in a minute; that is deliberate.
- 30 days notice before a change. Before we add or replace a sub-processor, customers are told at least 30 days in advance, by email or in the product.
- You can object. On reasonable data protection grounds, within those 30 days. If we cannot find an alternative that works, you may terminate the affected subscription without penalty and get the unused prepaid period back. Objecting is not a breach of contract and we will not treat it as one.
- Same obligations, all the way down. Each contract imposes the obligations in the DPA, including Annex 2’s security measures and the Standard Contractual Clauses where a transfer needs them.
- No training on your data. The AI provider is contractually barred from using your inputs or outputs to train its models.
- We publish what is in use, not what we might use. A provider that is configured but switched off does not appear here; when we turn it on, it appears with notice first.
Transfers outside the EEA
Rows marked with an asterisk involve a transfer to, or access from, a third country. The transfer tool is Article 46(2)(c) GDPR — the European Commission’s Standard Contractual Clauses, concluded with each provider as part of its data processing agreement, backed by a transfer impact assessment and by the encryption, access control and minimisation measures in Annex 2. Where a provider also holds an EU–US Data Privacy Framework certification, that applies in addition; we do not lean on it alone.
Ask us for the clauses covering a specific provider and we will send them: [email protected].
Who else can see personal data, outside this register
Not every recipient is a technology provider, so for completeness: our accountant and tax adviser, our bank, and — where we need to establish or defend a legal claim — lawyers, auditors or insurers. Public authorities receive data only where a legal provision obliges us to hand it over, and we check the basis before answering a request rather than treating an informal one as an order. The privacy policy covers all of this.
The register
Current as of the date at the top of this page.
| Provider | What it does for us | Where | Role |
|---|---|---|---|
| Cloudflare Cloudflare, Inc. / Cloudflare Ltd. | Hosting, CDN, DNS, WAF and edge compute for the websites and applications | EU edge locations; United States * | Processor |
| Supabase Supabase, Inc. | Managed PostgreSQL database and account authentication | Per product: Paris (eu-west-3) and Stockholm (eu-north-1) in the EU; London (eu-west-2) in the UK, under the adequacy decision of 19 December 2025; and — for CarPanel only — N. Virginia (us-east-1) in the United States. Company established in the United States. * | Processor |
| Anthropic (Claude) Anthropic PBC | The AI features described in the privacy policy — document analysis, matching and drafting. Inputs are not used to train the provider's models. | United States * | Processor |
| Resend Resend, Inc. | Delivery of transactional and service email (receipts, alerts, account notices) | United States * | Processor |
| Google Analytics 4 Google Ireland Ltd. / Google LLC | Audience measurement on the marketing site. Loaded only after consent; never on the product applications. | Ireland; United States * | Processor |
| Tpay Krajowy Integrator Płatności S.A., plac Władysława Andersa 3, 61-894 Poznań, KRS 0000412357 | Execution, settlement and security of payments; statutory payment-services, AML, accounting and chargeback obligations. Tpay decides these purposes itself and is a separate controller, not our sub-processor. | Poland (EEA) | Separate controller |
| Mailbox hosting (MySecureCloudHost) WHG Hosting Services Ltd, Norwich, United Kingdom (company no. 14644356) | Hosts the [email protected] mailbox — support correspondence, complaints, withdrawal notices and data subject requests | Servers in Frankfurt, Germany (EEA); provider established in the United Kingdom, covered by the Commission's adequacy decision of 19 December 2025 | Processor |
* Transfer outside the EEA on the Commission's Standard Contractual Clauses (art. 46(2)(c) GDPR)