Sub-processors
Version 1.3 — last updated: 10 July 2026
opexONE is operated by plusRS OÜ. To deliver the service, we engage the third-party sub-processors below to process customer (tenant) personal data on our behalf. Each is bound by a data-processing agreement with obligations no less protective than those in our Data Processing Agreement. We maintain this list and notify customers in advance of changes as set out in the DPA.
| Sub-processor | Status | Purpose | Location | Transfer safeguard |
|---|---|---|---|---|
Amazon Web Services Amazon Web Services, Inc. / Amazon Web Services EMEA SARL | Active | Cloud hosting, application delivery, file storage, and transactional email (SES). | EU (Frankfurt) by default; other AWS regions where a customer selects regional hosting. | Covered under the Amazon.com, Inc. EU–US Data Privacy Framework certification; EU Standard Contractual Clauses as the fallback. |
Supabase Supabase, Inc. | Active | Managed database, authentication, file storage, and serverless functions — the core data platform. | Hosted on AWS in the region configured for the deployment (EU by default). | EU Standard Contractual Clauses; data held in the configured region. |
Stripe Stripe Payments Europe, Ltd. (Ireland) | Planned | Subscription billing and payment processing. | EEA (Ireland), with onward transfers within the Stripe group. | EEA contracting entity + EU Standard Contractual Clauses for onward transfers. |
Microsoft 365 Microsoft Ireland Operations Limited (Microsoft Corporation) | Active | email correspondence — Exchange Online, OneDrive, SharePoint (processes personal data only when you contact us). | EU/global, per Microsoft 365 configuration. | Microsoft Corporation is EU–US Data Privacy Framework certified; EU Standard Contractual Clauses as the fallback. |
Bird (MessageBird) Bird B.V. (formerly MessageBird B.V.), Keizersgracht 268, Amsterdam, Netherlands — KvK 51874474 | Active | SMS delivery for login and phone-number verification codes (one-time passcodes). Bird receives the recipient phone number and the code text; the code itself is generated and verified by our authentication platform, never by Bird. | EU region (eu1): our Bird organization is region-pinned, so message and recipient data is stored and processed in the EU and never replicated across regions. SMS termination via telecom carriers in the recipient’s country. | EEA contracting entity (Bird B.V., Netherlands governing law); Bird DPA with EU Standard Contractual Clauses for onward transfers; Bird’s US affiliate (Bird.com Inc.) is EU–US Data Privacy Framework certified. ISO/IEC 27001:2022 and SOC 2 Type 2 attested. |
KLIPY KLIPY (klipy.com) | Active | GIF and sticker search inside in-app discussions. The search is proxied through our backend (the Klipy API key stays server-side); Klipy receives only the typed search term, not message content. Per-tenant admins can disable GIFs/stickers entirely. | Global content-delivery network. | EU Standard Contractual Clauses where applicable; only search terms are sent, no customer records are stored by the search. |
Sub-processors marked “Planned” are not yet processing any customer data.
Changelog — Version 1.3 (10 July 2026): Bird (MessageBird B.V.) added — SMS delivery of login and phone-verification codes (receives recipient phone numbers). Version 1.2 (28 June 2026): Stripe marked as planned; transfer safeguards clarified for AWS and Microsoft; Microsoft 365 entity corrected. To receive change notifications, email privacy@plusrs.com.
Questions about our sub-processors, or want to be notified of changes? Contact privacy@plusrs.com. See also our privacy policy and Data Processing Agreement.