Sub-processors
Every company that processes personal data on our behalf: what for, what data, where in the world, and under what safeguard — and which only apply once a firm switches an integration on.
| Sub-processor | Purpose | Data | Location | Transfer safeguard | When |
|---|---|---|---|---|---|
| Stripe Payments Europe, Limited | Billing subscribing firms for their Veilux plan | Firm billing details, subscription and invoice records. Card numbers go directly to Stripe and never reach Veilux. | European Economic Area (Stripe’s EU entity), with onward processing by Stripe, Inc. in the United States | EU Standard Contractual Clauses / UK International Data Transfer Addendum, per Stripe’s own data processing agreement | Always |
| Stripe (the firm’s own connected account) | Lets a firm’s customers pay its invoices online | The firm’s customer’s name, email and payment details, on the firm’s own Stripe account | Wherever the firm’s own Stripe account is based | Governed by the firm’s own agreement with Stripe, not by Veilux — Veilux only passes the payment request through | Only if the firm connects its own Stripe account |
| Zoom Video Communications, Inc. | Creates a meeting link when a booking asks for a video call | Meeting time, title, and attendee names | United States, with data centres in multiple regions Zoom selects | EU Standard Contractual Clauses / UK International Data Transfer Addendum, per Zoom’s own data processing agreement | Only if the firm connects Zoom |
| Jitsi (meet.jit.si, or a server the firm runs itself) | Provides a video meeting room | Only a generated room name — no account is created and no attendee detail is shared | meet.jit.si is operated by 8x8, Inc. in the United States; a firm may instead point this at a server it controls itself, in a location of its own choosing | EU Standard Contractual Clauses / UK International Data Transfer Addendum for meet.jit.si; not applicable when a firm runs its own server | Only if the firm turns Jitsi on |
| Twilio Inc. | Sends SMS notifications | Recipient phone number and the text of the message | United States | EU Standard Contractual Clauses / UK International Data Transfer Addendum, per Twilio’s own data processing agreement | Only if the firm connects Twilio |
Fully named vendors are bound by their own data processing agreement, referenced from the data processing agreement. A provider is added to this list the day it actually starts processing data, never before.
01How to read this list
A row marked "Always" processes data for every firm on Veilux, because the base product depends on it. A row marked otherwise processes data only for a firm that has deliberately switched that integration on, in Setup → Integrations; a firm that never connects Zoom, Twilio or its own Stripe account is never in that provider’s systems at all.
This list only names a processor once code in the product actually sends it data. Google, Microsoft and Cal.com appear in the integrations registry but have no working connection yet, so they are not sub-processors and are not listed here; they will be added the day a real connection ships, not before.
02Notice of a new sub-processor
We will email the account owner of every firm at least 30 days before a new sub-processor starts processing Customer Personal Data, or before an existing one starts processing a materially different category of it. This is the same notice period the data processing agreement commits to, stated here in the same words so the two cannot drift apart.
If a firm has a reasonable data-protection objection to a new sub-processor, it can raise it with us within that notice period at [email protected]. Where we cannot reasonably address the objection, the firm may end the affected part of the agreement and receive a refund of any pre-paid, unused fees for that period, as the data processing agreement sets out in full.
03Questions
For anything about this list, or about a specific sub-processor’s own data processing agreement: [email protected]. The security measures each of these companies is required to meet, and the ones Veilux itself keeps, are on the security page; the underlying obligations are in the data processing agreement.
Questions about this document: [email protected].