Sub-processors
Last updated: 19 September 2026
Pinly Limited uses the providers below to run the Pinly service. Each one processes customer personal data only on our instructions and under a written data processing agreement, except the browser push services, which receive only an encrypted message they cannot read. This list is also Annex IV of the Pinly Data Processing Agreement.
| Provider | What it does for Pinly | Personal data involved | Where it is processed, and transfer safeguards |
|---|---|---|---|
| Google Cloud (Google Cloud EMEA Limited, Ireland) | Hosting, databases, file storage, backups, secrets, system logs | All customer data | Database, files and backups in the EU (region europe-west1, Belgium; backups in Google's EU multi-region). System logs are held in Google's global logging service, which is not pinned to the EU. Google's Cloud Data Processing Addendum applies; where Google transfers data outside the EU it relies on the EU-US Data Privacy Framework (Google LLC is certified) and standard contractual clauses. |
| Google Vertex AI (same Google Cloud contract) | AI features: draft daily plans, in-app assistant, summaries, analytics | Operational data with staff names and email addresses replaced by placeholders before sending; text a user types to the assistant. A person's leave reaches it only as “on leave”, never the type | EU, region europe-west1. Google does not use the data to train models. Google may cache data in memory for up to 24 hours and may log prompts for abuse monitoring, as its terms describe; any such logging outside the EU is covered by the safeguards above. |
| Google Firebase Cloud Messaging (Google LLC, United States) | Delivering push notifications to the iOS and Android apps | Device push token; notification title and text, which can include a colleague's name and a task or machine name, never leave information | United States. Firebase Data Processing and Security Terms; EU-US Data Privacy Framework (Google LLC is certified) and standard contractual clauses. |
| Apple Push Notification service (Apple Inc., United States) | Final delivery of push notifications to iPhones and iPads, passed on by Firebase | Device token; the same notification title and text | United States, under Apple's developer terms. Apple is not a Data Privacy Framework participant; its transfers rest on standard contractual clauses. |
| Browser push services: Google (Chrome), Mozilla (Firefox), Apple (Safari), Microsoft (Edge) | Delivering push notifications to the web app | The browser's push address and an encrypted message. Messages are encrypted end to end (RFC 8291), so the push service cannot read the title or text | Global. The service sees no readable personal data beyond the push address. |
| Resend (Resend, Inc., United States) | Sending service emails: invitations, password resets, alerts | Recipient name and email address, email content | Sent from Resend's EU region (Ireland, eu-west-1). Resend is a United States company, so account administration and support access may involve the United States, under the EU-US Data Privacy Framework (Resend is certified) and the standard contractual clauses in Resend's data processing agreement. |
Not sub-processors
- Google Maps Platform supplies the satellite map in the app. Google receives the viewing device's IP address and the map area requested, and acts as an independent controller for that service under its own terms.
- Weather data providers receive only the course's coordinates, never personal data.
- Umami provides cookieless visitor statistics for this website only. It receives no customer data from the app.
Changes to this list
We give customers at least 30 days' notice by email before adding or replacing a sub-processor, so they can object as the Data Processing Agreement describes.
Contact
Pinly is operated by Pinly Limited, a company registered in Ireland (company number 822399). Questions about this list: hello@pinlyai.com.