Sub-processors

Version 2.0 — last updated: 13 September 2026

opexONE is operated by plusRS OÜ. To deliver the service, we engage the third-party sub-processors below to process customer (tenant) personal data on our behalf. They are technical infrastructure and service providers that do not process customer data for their own purposes. Each works under its own data-processing agreement and security standards, and we bind each to obligations no less protective than those in our Data Processing Agreement. We announce any intended addition or replacement on this page at least 30 days before it takes effect, as set out in the DPA.

Sub-processorStatusPurposeLocationTransfer safeguard

Amazon Web Services

Amazon Web Services, Inc. / Amazon Web Services EMEA SARL

Active

Cloud hosting, application delivery, file storage, and transactional email (SES).

EU (Frankfurt) by default; other AWS regions where a customer selects regional hosting.

Covered under the Amazon.com, Inc. EU–US Data Privacy Framework certification; EU Standard Contractual Clauses as the fallback.

Supabase

Supabase Pte. Ltd., 65 Chulia Street #38-02/03, OCBC Centre, Singapore

Active

Managed database, authentication, file storage, and serverless functions — the core data platform.

Hosted on AWS in the region configured for the deployment (EU by default).

EU Standard Contractual Clauses under the Supabase Data Processing Addendum (Schedule 2); data held in the configured region.

Stripe

Stripe Payments Europe, Ltd. (Ireland)

Planned — pre-announced

Subscription billing and payment processing.

EEA (Ireland), with onward transfers within the Stripe group.

EEA contracting entity + EU Standard Contractual Clauses for onward transfers.

Microsoft 365

Microsoft Ireland Operations Limited (Microsoft Corporation)

Active

email correspondence — Exchange Online, OneDrive, SharePoint (processes personal data only when you contact us).

EU/global, per Microsoft 365 configuration.

Microsoft Corporation is EU–US Data Privacy Framework certified; EU Standard Contractual Clauses as the fallback.

Bird (MessageBird)

Bird B.V. (formerly MessageBird B.V.), Keizersgracht 268, Amsterdam, Netherlands — KvK 51874474

Active

SMS delivery for login and phone-number verification codes (one-time passcodes). Bird receives the recipient phone number and the code text; the code itself is generated and verified by our authentication platform, never by Bird.

EU region (eu1): our Bird organization is region-pinned, so message and recipient data is stored and processed in the EU and never replicated across regions. SMS termination via telecom carriers in the recipient’s country.

EEA contracting entity (Bird B.V., Netherlands governing law); Bird DPA with EU Standard Contractual Clauses for onward transfers; Bird’s US affiliate (Bird.com Inc.) is EU–US Data Privacy Framework certified. ISO/IEC 27001:2022 and SOC 2 Type 2 attested.

KLIPY

KLIPY (klipy.com)

Active

GIF and sticker search inside in-app discussions. The search is proxied through our backend (the Klipy API key stays server-side); Klipy receives the typed search term, not message content. Selected GIFs and previews are then loaded by your browser directly from the Klipy CDN — see the "Third-party embeds" section below. Per-tenant admins can disable GIFs/stickers entirely.

Global content-delivery network.

EU Standard Contractual Clauses where applicable; only search terms are sent, no customer records are stored by the search.

GitHub

GitHub, Inc. (United States)

Active

Processing of the product-feedback reports users submit in the app, in our vendor-hosted issue tracker. The report text and technical context are transmitted; email addresses are automatically redacted before transmission. Attachments are not transmitted — they stay stored in the EU and are referenced by expiring links.

United States (github.com offers no EU residency option).

EU–US Data Privacy Framework and EU Standard Contractual Clauses under the GitHub Data Protection Agreement.

Sub-processors marked “Planned — pre-announced” are announced under § 6.3 of the DPA and are not yet processing any customer data.

Pre-announced changes

These changes are announced in advance under § 6.3 of the DPA. Each takes effect only when the feature it belongs to launches.

  • AWS Bedrock (AI model inference)When the opexONE AI features launch, our existing AWS engagement extends to AI model inference on AWS Bedrock — EU regions only, with no retention of customer data by the model service and no use of customer data for model training.
  • Apple Inc. and Google LLCWhen the opexONE mobile apps launch, Apple (App Store, APNs) and Google (Google Play, FCM) are added for app distribution and push-notification delivery, limited to device and push tokens.

Third-party embeds

The parties below are not sub-processors: they do not process customer data on our behalf, and we have no data-processing agreement with them. They are listed because your browser contacts them directly when it renders part of the application, which means they observe your IP address. Since an IP address is personal data, we disclose them in full. The application enforces a Content-Security-Policy allow-list, so no third-party host can appear in the application without appearing here.

EmbedWhat it isWhat they receiveWhen it loadsLocation

OpenStreetMap

OpenStreetMap Foundation (a non-profit company registered in England & Wales)

The map showing the approximate location of a sign-in, in Account → Security. It is an embedded map frame served by OpenStreetMap; we use it so that no map data or account information has to be sent to a commercial mapping provider.

The viewer’s IP address and browser user-agent (as with any web request), and the approximate coordinates of the map view being displayed — i.e. the rough location of the sign-in being looked at. No account identifier, name, email, or other tenant data is sent.

Only on the Account → Security page, and only for sessions whose location could be estimated. The map for the device you are currently using is expanded by default, so it loads when you open that page; maps for your other devices load only if you expand them. Users who never open Account → Security never contact OpenStreetMap.

United Kingdom, plus OpenStreetMap’s content-delivery network.

Cloudflare Turnstile

Cloudflare, Inc. (United States — EU–US Data Privacy Framework certified)

The bot-protection challenge on the sign-in page. It distinguishes humans from automated abuse before authentication — a strictly-necessary security function of the login.

The viewer’s IP address, browser user-agent, and the technical browser signals the challenge evaluates. No credentials (the challenge runs before and separately from password entry), no account identifier, and no tenant data.

On every sign-in page load. Signing in is not possible without it — it is part of protecting all tenants’ accounts against automated attacks.

Cloudflare’s global anycast network.

Klipy media delivery

KLIPY (klipy.com)

Delivery of GIF/sticker media in discussions. The search itself is proxied through our backend (see the sub-processor entry above), but media previews and selected GIFs are fetched by your browser directly from the Klipy CDN.

The viewer’s IP address and browser user-agent when GIF content renders. Klipy does not receive message content, account identifiers, or tenant data through media delivery.

Only in discussions where GIF/sticker content appears, and only if your organisation has GIFs/stickers enabled (per-tenant admins can disable them entirely).

Global content-delivery network.

Questions about our sub-processors, or want to subscribe to change notifications? Email privacy@plusrs.com. See also our privacy policy and Data Processing Agreement.