Translation. This is a translation provided for convenience. In case of any conflict between language versions, the Swedish version prevails. Swedish version →

Annex C, Appendix 2 — Subprocessor List

The providers that help us run Vepino, and where they are located.

Introduction

Appendix to the Data Processing Agreement Human Syntax AB

This Appendix lists the Subprocessors engaged by the Supplier to process Personal Data on behalf of the Customer, in accordance with §8 of the Data Processing Agreement (Annex C).

Current subprocessors

1Oderland Webbhotell AB

Field Value
Company name Oderland Webbhotell AB
Registration number 556680-8746
Domicile Sweden
Place of processing Sweden
Service Hosting and operation of the Service (servers, databases, backup)
Categories of personal data All categories specified in Appendix 1A
Third country transfer No
Governing agreement Oderland’s Data Processing Agreement (DPA) as in force from time to time, published at oderland.se

2AC PM LLC (Postmark)

Field Value
Company name AC PM LLC (operator of Postmark, subsidiary of ActiveCampaign)
Domicile USA
Place of processing USA
Service Sending of email on behalf of the Customer
Categories of personal data Recipient data (name, email address, possibly related fields), content of campaigns, engagement data (opens, clicks, bounces, unsubscribes)
Third country transfer Yes, USA
Transfer mechanism EU-U.S. Data Privacy Framework (primary) and Standard Contractual Clauses (Module 3) as backup
DPF status AC PM LLC is certified under the EU-U.S. Data Privacy Framework, UK Extension and Swiss-U.S. Data Privacy Framework. Current certification status can be verified at dataprivacyframework.gov.
Governing agreement AC PM LLC’s Data Processing Addendum as in force from time to time, published at postmarkapp.com/dpa

3Amazon Web Services EMEA SARL (Amazon SES)

Field Value
Company name Amazon Web Services EMEA SARL
Domicile Luxembourg
Place of processing EU (Stockholm region, eu-north-1); certain support flows and diagnostic data may be processed globally, including in the USA
Service Sending of email on behalf of the Customer
Categories of personal data Recipient data (name, email address, possibly related fields), content of campaigns, engagement data (opens, clicks, bounces, unsubscribes)
Third country transfer To a limited extent, USA (support flows and diagnostic data)
Transfer mechanism EU-U.S. Data Privacy Framework (primary) and Standard Contractual Clauses (Module 3) as backup
DPF status Amazon.com, Inc. is certified under the EU-U.S. Data Privacy Framework, UK Extension and Swiss-U.S. Data Privacy Framework. Current certification status can be verified at dataprivacyframework.gov.
Governing agreement AWS’s Data Processing Addendum as in force from time to time, published at aws.amazon.com/service-terms/dataprivacy

4Microsoft Ireland Operations Limited (Microsoft 365)

Field Value
Company name Microsoft Ireland Operations Limited
Domicile Ireland
Place of processing EU (core content under Microsoft’s “EU Data Boundary”); certain support flows and diagnostic data may be processed globally, including in the USA
Service Office tools used by the Supplier for support cases and customer correspondence (Exchange/Outlook) and file storage (OneDrive/SharePoint), where personal data from the Service may occur
Categories of personal data Correspondence with the Customer’s contact persons in support cases, any export files or attachments from the Service that the Customer shares with the Supplier
Third country transfer To a limited extent, USA (support flows and diagnostic data)
Transfer mechanism EU-U.S. Data Privacy Framework (primary) and Standard Contractual Clauses (Module 3) as backup
DPF status Microsoft Corporation is certified under the EU-U.S. Data Privacy Framework. Current certification status can be verified at dataprivacyframework.gov.
Governing agreement Microsoft’s Data Protection Addendum (DPA) as in force from time to time, within Microsoft Product Terms
Comment Microsoft Ireland Operations Limited also appears as an independent data controller for SSO login — see the SSO section below.

Other recipients of personal data (not subprocessors)

The following actors receive personal data from the Service in roles other than as Subprocessors. They are independent data controllers for the data they process and are not governed by this DPA.

46elks AB

Field Value
Company name 46elks AB
Registration number 556838-8184
Domicile Sweden
Place of processing Sweden (own servers)
Service SMS delivery from the Service
Categories of personal data Recipients’ mobile numbers, content of SMS
Role Independent data controller (telecommunications operator)
Legal basis EU Directive 2002/58/EC (ePrivacy), Swedish Electronic Communications Act (LEK 2022:482), PTS regulations
Third country transfer No
Governing agreement No Data Processing Agreement (46elks is an independent data controller). 46elks’ privacy policy at 46elks.se governs their processing.
Comment As a registered telecommunications operator under LEK, 46elks is subject to the same obligations as other Swedish telecommunications operators (Telia, Tele2 and others). A separate Data Processing Agreement is not required according to 46elks’ own GDPR policy.

Identity providers for SSO login

Where the Customer chooses federated login (Single Sign-On), the following identity providers handle authentication data as independent data controllers, not as Subprocessors to the Supplier:

  • Google Ireland Limited (Sign in with Google)
  • Microsoft Ireland Operations Limited (Sign in with Microsoft)
  • Apple Distribution International Ltd. (Sign in with Apple — available in beta)

For EU-based end users, each Irish company is the data controller in accordance with the provider’s terms. Processing takes place within the EU/EEA — no third country transfer occurs via the SSO mechanism.

Data the Service receives from the identity provider (after the user’s authorisation):

  • Verified email address
  • Display name (first and last name where available)
  • Unique identifier ID from the identity provider (for matching user account on future logins)
  • OAuth token to verify the authenticated session

What the Service does with the data:

  • Creates or matches a user account based on email address and IdP ID
  • Establishes an authenticated session in the Service
  • Stores IdP ID for future logins

What the Service does not receive or process:

  • Passwords (never shared with the Service)
  • Account content from the identity provider (contacts, calendar, files, etc.)
  • Data outside the OAuth scope authorised by the user