A public list of every third-party service that processes personal data on our behalf, why they touch it, where they're based, and the legal mechanism in place for cross-border transfers.
This page is published in compliance with UK GDPR Article 13(1)(f) (information about international transfers), Article 28 (use of processors), and Article 46 (transfer mechanisms), and the equivalent obligations under EU GDPR, PIPEDA, Quebec Law 25 (s.17 cross-border PIA), and Brazil's LGPD. It is the same dataset as our internal Records of Processing Activities - published here so any data subject can audit who touches their data, in one place, without making a Subject Access Request.
| Vendor | Purpose | Jurisdiction | Transfer mechanism |
|---|---|---|---|
| OVHcloud | Primary infrastructure (web servers, databases, application hosting). Beauharnois (Quebec) datacentre. | Canada (QC) | Adequacy decision Within Canada - no cross-border transfer. |
| VerifyMy | Photo-ID age verification. Pass/fail handshake only - we never receive the document, DOB, or biometric. | United Kingdom | UK GDPR domestic ISO 27001 certified. |
| Amazon Web Services | Rekognition (image + video moderation labels, selfie face comparison, and Face Liveness for the live selfie check: a short camera video streamed from the member's device straight to AWS, and one frame from it compared with the member's main approved public profile photo), Transcribe (voice-note and voice-greeting moderation transcription), and S3 (transient biometric processing). Source images never persisted by DateSteady; AWS retention governed by AWS product policy. Our AWS organization is opted out of AWS using this content to improve its AI services. | European Union (Ireland) | Art. 28 DPA signed UK SCC + IDTA execution in progress |
| Microsoft | PhotoDNA hash matching (CSAM detection). Edge Hash SDK locally generates the hash; only the hash is sent to Microsoft. | United States | Art. 28 DPA signed UK SCC + IDTA execution in progress |
| Project Arachnid Shield | CSAM hash matching (Canadian Centre for Child Protection). The hash is generated locally; only a non-reversible image hash (PDQ) is shared - the image is not shared. | Canada (MB) | Adequacy decision Within Canada - no cross-border transfer. |
| Cloudflare | CDN, DDoS mitigation, WAF, R2 object storage for moderation queue and DSAR exports. | United States | Art. 28 DPA signed UK SCC + IDTA execution in progress |
| proxycheck.io | VPN and proxy screening at sign-up. Receives the connecting IP address only. Address logging is turned off on our account. | Canada (stored in region of origin) | Provider processor terms No separate Art. 28 DPA on our current plan. |
| AbuseIPDB | Abuse-report screening at sign-up (AbuseIPDB LLC). Receives the connecting IP address, and only when the connection is not identified as an ordinary home internet connection (for example a VPN, relay or hosting network), when the address already appears on a public abuse list, or when our own lists are temporarily unavailable. | United States | Provider terms No Art. 28 DPA yet. |
| Project Honey Pot | Spam and abuse screening at sign-up through its http:BL lookup (Unspam Technologies, Inc.), under the same conditions as AbuseIPDB. Receives the connecting IPv4 address. The lookup is sent as an unencrypted DNS query, so networks between us and the http:BL servers can see it. | United States, Ireland | Provider terms No Art. 28 DPA yet. |
| Postmark | Transactional email delivery (verification, security alerts, breach notifications, DSAR receipts). | United States | Art. 28 DPA signed UK SCC + IDTA execution in progress |
| Twilio | SMS delivery for phone verification and 2FA. Optional STUN/TURN signalling fallback for video calls (signalling metadata only - call media is peer-to-peer and never traverses Twilio). | United States | Art. 28 DPA signed UK SCC + IDTA execution in progress |
| PayPal | Subscription payment processing (primary for web). PCI-DSS handled by PayPal; we never touch card data. | United States | Art. 28 DPA signed UK SCC + IDTA execution in progress |
| Google Play Billing | Android in-app subscription billing. Payment runs entirely inside Google Play; we receive purchase tokens and entitlement status only - never card data. | United States | Google processes Play purchases under its own Google Play terms; DateSteady receives entitlement data only. |
| Google Vertex AI | Support chatbot inference + Safety Tier 2 grooming-classifier (planned). Hosted in northamerica-northeast1 (Montreal) - data stays in Canada. |
Canada (QC) | Adequacy decision Inference path stays in Canada. |
| Mixpanel | Product analytics, consent-gated (loads only after analytics consent). Session replay is disabled. | United States | Art. 28 DPA available UK SCC + IDTA execution in progress |
| KLIPY (Kikliko, Inc.) | GIF search in messages. Searches are proxied by our own server: KLIPY receives the words typed in the GIF search box, a result count, a paging cursor, an app label naming DateSteady and a "medium" content filter. No name, account ID, device ID or member IP address is sent with the search. The GIF image itself is loaded from KLIPY by the member's device, so KLIPY sees that device's IP address at display time. Replaced Tenor (Google) on 21 July 2026 after Google discontinued the Tenor API. | United States | Provider API terms + KLIPY privacy policy No separate Art. 28 DPA recorded in our contract register at this date; no member identifiers are sent with the search. |
| Google (Ads, Analytics 4) | Advertising conversion measurement and site analytics, consent-gated. Google Consent Mode sets every storage type to denied until you make a cookie choice, and only the products whose category you accepted are loaded. | United States | Google Ads Data Processing Terms / Google Analytics terms Signed-contract status not separately recorded in our contract file. |
| Meta Platforms (Meta Pixel) | Advertising conversion measurement, consent-gated. The pixel is not loaded at all until you accept marketing cookies. | United States | Meta Business Tools terms Signed-contract status not separately recorded in our contract file. |
| Vendor | Purpose (when activated) | Jurisdiction | Status |
|---|---|---|---|
| Apple App Store | iOS in-app subscription billing (when the iOS app launches). Payment would run entirely inside the App Store; we would receive transaction and entitlement status only - never card data. | United States | Pending iOS launch; not currently active. |
| IWF Image Intercept | Complementary CSAM hash matching layer (UK-curated, free for small platforms). Only the locally-computed hash is shared. | United Kingdom | Code scaffolded; awaiting eligibility decision from IWF. |
| Microsoft Clarity | UX session replay (default off; opt-in only). | United States | Covered by Microsoft DPA; not currently active. |
This page is generated from the same source as our internal Records of Processing Activities (Art. 30). The two are kept in lockstep: any sub-processor change requires updating both. The internal RoPA holds full processing-purpose detail per processing activity; this public page collapses that detail per vendor for readability.
Material changes (new vendor onboarded, vendor removed, transfer mechanism changed) are announced via the privacy policy update notification in-app and the privacy@datesteady.com mailing list. To subscribe to that list, email us; opt-in is a single click and you can withdraw at any time.
For any question about a specific sub-processor, transfer mechanism, or to exercise a data subject right (Art. 15–22 / PIPEDA / Law 25 s.8.1 de-indexation / LGPD), email dpo@datesteady.com. We respond within 30 days (15 days for Brazilian residents under LGPD; 20 business days for Mexican residents under LFPDPPP).
You can also contact our EU + UK Article 27 representative (DataRep) once their addresses are published in our privacy policy §15A.