Every third-party service that processes personal data on Pistaclub's behalf, with the purpose, jurisdiction, and safeguards for each. Required by GDPR Article 28(2).
Last updated: 2026-07-16
When Pistaclub relies on a third-party service to store or process personal data — cloud hosting, payment processing, transactional email — that service is a sub-processor under GDPR Article 28. This page lists every current sub-processor, the purpose of the processing, the jurisdiction, the categories of data reaching them, and the safeguards in place. It is the same information the Organizer Data Processing Agreement §6 references, published openly so any user — rider or organizer — can review it without asking.
When we add or replace a sub-processor, organizers receive at least 30 days' prior notice via the organizer dashboard and, where subscribed, by email. The Organizer DPA §6 gives the organizer the right to object on reasonable data-protection grounds. Cosmetic edits (typo fix, updated corporate name) do not trigger a notice period. Every material change bumps the "Last updated" date at the top of this page.
Application hosting, database, authentication, storage, and integrations backend. Runs the platform code, stores all entity data, and serves user requests.
Location: European Union / United States
Transfer safeguard: EU Standard Contractual Clauses (Decision 2021/914) for any US-side transfers.
Data categories reaching this sub-processor:
Safeguards:
Card-payment processing for in-app event bookings (destination charges to the organizer’s Stripe Connect account) and Premium subscription billing.
Location: Ireland (EU)
Transfer safeguard: EU Standard Contractual Clauses for any US infrastructure fallback.
Data categories reaching this sub-processor:
Safeguards:
Underlying cloud infrastructure and object storage for platform data; Google Gemini API for AI-assisted content translation.
Location: European Union
Transfer safeguard: EU regions selected; SCC-covered where any US management-plane fallback is engaged.
Data categories reaching this sub-processor:
Safeguards:
Sending booking confirmations, reminders, moderation notifications, organizer team invites, and other operational email.
Location: European Union
Transfer safeguard: EU-region delivery infrastructure; SCC-covered for any US management-plane operations.
Data categories reaching this sub-processor:
Safeguards:
Where a sub-processor stores or accesses personal data outside the European Economic Area, the transfer is covered by either the European Commission's Standard Contractual Clauses (Decision 2021/914) or an adequacy decision. The "Transfer safeguard" line on each row above states which mechanism applies. UK GDPR-covered data uses the UK Addendum to the SCCs; Swiss FDPIC data uses the Swiss FDPIC-approved SCC variant.
Under the Organizer DPA, Pistaclub imposes on every sub-processor written data-protection obligations that provide sufficient guarantees to meet GDPR Art. 28(3) and remains fully liable to the organizer (as controller) for the sub-processor's performance of those obligations. Rider-facing controller/processor breakdown is set out in the Privacy Policy.
Data-protection queries: privacy@pistaclub.app
Data Protection Officer: dpo@pistaclub.app
Contract / legal: legal@pistaclub.app
The full list of controllers, processors, and their roles for each data category on the platform is in the Privacy Policy — Controller / processor split.