Annex C, Appendix 2 — Subprocessor List
The providers that help us run Vepino, and where they are located.
Introduction
Appendix to the Data Processing Agreement Human Syntax AB
This Appendix lists the Subprocessors engaged by the Supplier to process Personal Data on behalf of the Customer, in accordance with §8 of the Data Processing Agreement (Annex C).
Current subprocessors
1Oderland Webbhotell AB
| Field | Value |
|---|---|
| Company name | Oderland Webbhotell AB |
| Registration number | 556680-8746 |
| Domicile | Sweden |
| Place of processing | Sweden |
| Service | Hosting and operation of the Service (servers, databases, backup) |
| Categories of personal data | All categories specified in Appendix 1A |
| Third country transfer | No |
| Governing agreement | Oderland’s Data Processing Agreement (DPA) as in force from time to time, published at oderland.se |
2AC PM LLC (Postmark)
| Field | Value |
|---|---|
| Company name | AC PM LLC (operator of Postmark, subsidiary of ActiveCampaign) |
| Domicile | USA |
| Place of processing | USA |
| Service | Sending of email on behalf of the Customer |
| Categories of personal data | Recipient data (name, email address, possibly related fields), content of campaigns, engagement data (opens, clicks, bounces, unsubscribes) |
| Third country transfer | Yes, USA |
| Transfer mechanism | EU-U.S. Data Privacy Framework (primary) and Standard Contractual Clauses (Module 3) as backup |
| DPF status | AC PM LLC is certified under the EU-U.S. Data Privacy Framework, UK Extension and Swiss-U.S. Data Privacy Framework. Current certification status can be verified at dataprivacyframework.gov. |
| Governing agreement | AC PM LLC’s Data Processing Addendum as in force from time to time, published at postmarkapp.com/dpa |
3Amazon Web Services EMEA SARL (Amazon SES)
| Field | Value |
|---|---|
| Company name | Amazon Web Services EMEA SARL |
| Domicile | Luxembourg |
| Place of processing | EU (Stockholm region, eu-north-1); certain support flows and diagnostic data may be processed globally, including in the USA |
| Service | Sending of email on behalf of the Customer |
| Categories of personal data | Recipient data (name, email address, possibly related fields), content of campaigns, engagement data (opens, clicks, bounces, unsubscribes) |
| Third country transfer | To a limited extent, USA (support flows and diagnostic data) |
| Transfer mechanism | EU-U.S. Data Privacy Framework (primary) and Standard Contractual Clauses (Module 3) as backup |
| DPF status | Amazon.com, Inc. is certified under the EU-U.S. Data Privacy Framework, UK Extension and Swiss-U.S. Data Privacy Framework. Current certification status can be verified at dataprivacyframework.gov. |
| Governing agreement | AWS’s Data Processing Addendum as in force from time to time, published at aws.amazon.com/service-terms/dataprivacy |
4Microsoft Ireland Operations Limited (Microsoft 365)
| Field | Value |
|---|---|
| Company name | Microsoft Ireland Operations Limited |
| Domicile | Ireland |
| Place of processing | EU (core content under Microsoft’s “EU Data Boundary”); certain support flows and diagnostic data may be processed globally, including in the USA |
| Service | Office tools used by the Supplier for support cases and customer correspondence (Exchange/Outlook) and file storage (OneDrive/SharePoint), where personal data from the Service may occur |
| Categories of personal data | Correspondence with the Customer’s contact persons in support cases, any export files or attachments from the Service that the Customer shares with the Supplier |
| Third country transfer | To a limited extent, USA (support flows and diagnostic data) |
| Transfer mechanism | EU-U.S. Data Privacy Framework (primary) and Standard Contractual Clauses (Module 3) as backup |
| DPF status | Microsoft Corporation is certified under the EU-U.S. Data Privacy Framework. Current certification status can be verified at dataprivacyframework.gov. |
| Governing agreement | Microsoft’s Data Protection Addendum (DPA) as in force from time to time, within Microsoft Product Terms |
| Comment | Microsoft Ireland Operations Limited also appears as an independent data controller for SSO login — see the SSO section below. |
Other recipients of personal data (not subprocessors)
The following actors receive personal data from the Service in roles other than as Subprocessors. They are independent data controllers for the data they process and are not governed by this DPA.
46elks AB
| Field | Value |
|---|---|
| Company name | 46elks AB |
| Registration number | 556838-8184 |
| Domicile | Sweden |
| Place of processing | Sweden (own servers) |
| Service | SMS delivery from the Service |
| Categories of personal data | Recipients’ mobile numbers, content of SMS |
| Role | Independent data controller (telecommunications operator) |
| Legal basis | EU Directive 2002/58/EC (ePrivacy), Swedish Electronic Communications Act (LEK 2022:482), PTS regulations |
| Third country transfer | No |
| Governing agreement | No Data Processing Agreement (46elks is an independent data controller). 46elks’ privacy policy at 46elks.se governs their processing. |
| Comment | As a registered telecommunications operator under LEK, 46elks is subject to the same obligations as other Swedish telecommunications operators (Telia, Tele2 and others). A separate Data Processing Agreement is not required according to 46elks’ own GDPR policy. |
Identity providers for SSO login
Where the Customer chooses federated login (Single Sign-On), the following identity providers handle authentication data as independent data controllers, not as Subprocessors to the Supplier:
- Google Ireland Limited (Sign in with Google)
- Microsoft Ireland Operations Limited (Sign in with Microsoft)
- Apple Distribution International Ltd. (Sign in with Apple — available in beta)
For EU-based end users, each Irish company is the data controller in accordance with the provider’s terms. Processing takes place within the EU/EEA — no third country transfer occurs via the SSO mechanism.
Data the Service receives from the identity provider (after the user’s authorisation):
- Verified email address
- Display name (first and last name where available)
- Unique identifier ID from the identity provider (for matching user account on future logins)
- OAuth token to verify the authenticated session
What the Service does with the data:
- Creates or matches a user account based on email address and IdP ID
- Establishes an authenticated session in the Service
- Stores IdP ID for future logins
What the Service does not receive or process:
- Passwords (never shared with the Service)
- Account content from the identity provider (contacts, calendar, files, etc.)
- Data outside the OAuth scope authorised by the user