Back to Pistaclub

Sub-processors

Every third-party service that processes personal data on Pistaclub's behalf, with the purpose, jurisdiction, and safeguards for each. Required by GDPR Article 28(2).

Last updated: 2026-07-16

When Pistaclub relies on a third-party service to store or process personal data — cloud hosting, payment processing, transactional email — that service is a sub-processor under GDPR Article 28. This page lists every current sub-processor, the purpose of the processing, the jurisdiction, the categories of data reaching them, and the safeguards in place. It is the same information the Organizer Data Processing Agreement §6 references, published openly so any user — rider or organizer — can review it without asking.

How changes work

When we add or replace a sub-processor, organizers receive at least 30 days' prior notice via the organizer dashboard and, where subscribed, by email. The Organizer DPA §6 gives the organizer the right to object on reasonable data-protection grounds. Cosmetic edits (typo fix, updated corporate name) do not trigger a notice period. Every material change bumps the "Last updated" date at the top of this page.

Current sub-processors

Base44 (Wix.com Ltd. group)

Application hosting, database, authentication, storage, and integrations backend. Runs the platform code, stores all entity data, and serves user requests.

Location: European Union / United States

Transfer safeguard: EU Standard Contractual Clauses (Decision 2021/914) for any US-side transfers.

Data categories reaching this sub-processor:

  • Account data (name, email, profile)
  • Rider profile + motorcycles + laptimes
  • Event registrations + bookings
  • Marketplace listings + messages
  • Forum posts + reactions
  • Uploaded media (photos, avatars)

Safeguards:

  • Encryption at rest on managed storage
  • TLS 1.2+ in transit
  • Role-based access control on the admin plane
  • Audit-log ledger for admin data access

https://base44.com

Stripe Payments Europe, Ltd.

Card-payment processing for in-app event bookings (destination charges to the organizer’s Stripe Connect account) and Premium subscription billing.

Location: Ireland (EU)

Transfer safeguard: EU Standard Contractual Clauses for any US infrastructure fallback.

Data categories reaching this sub-processor:

  • Payer name + email
  • Card details (tokenized — Pistaclub never sees the PAN)
  • Billing address + country
  • Amount, currency, event / subscription reference

Safeguards:

  • PCI-DSS Level 1 attestation
  • Card details tokenized before touching Pistaclub
  • Independent SOC 1 + SOC 2 audits
  • Webhook signature verification on every callback

https://stripe.com/privacy

Google Cloud Platform (EU regions — via Base44)

Underlying cloud infrastructure and object storage for platform data; Google Gemini API for AI-assisted content translation.

Location: European Union

Transfer safeguard: EU regions selected; SCC-covered where any US management-plane fallback is engaged.

Data categories reaching this sub-processor:

  • All platform data stored via Base44 infrastructure
  • User-authored text passed to translation (event descriptions, listings, organizer bios, forum posts) — NOT policy or legal text

Safeguards:

  • ISO 27001 + SOC 2 attestations
  • Data residency in EU regions
  • Encryption at rest + in transit
  • Translation content sent without user identifiers where feasible

https://cloud.google.com/security/gdpr

Transactional email provider (Base44-integrated)

Sending booking confirmations, reminders, moderation notifications, organizer team invites, and other operational email.

Location: European Union

Transfer safeguard: EU-region delivery infrastructure; SCC-covered for any US management-plane operations.

Data categories reaching this sub-processor:

  • Recipient email address
  • Recipient name
  • Message content (booking references, event details, moderation outcomes)

Safeguards:

  • TLS enforced on SMTP relay
  • DKIM + SPF + DMARC on outbound
  • Message content retained only for delivery + bounce diagnostics

https://base44.com

International transfers

Where a sub-processor stores or accesses personal data outside the European Economic Area, the transfer is covered by either the European Commission's Standard Contractual Clauses (Decision 2021/914) or an adequacy decision. The "Transfer safeguard" line on each row above states which mechanism applies. UK GDPR-covered data uses the UK Addendum to the SCCs; Swiss FDPIC data uses the Swiss FDPIC-approved SCC variant.

Pistaclub's role

Under the Organizer DPA, Pistaclub imposes on every sub-processor written data-protection obligations that provide sufficient guarantees to meet GDPR Art. 28(3) and remains fully liable to the organizer (as controller) for the sub-processor's performance of those obligations. Rider-facing controller/processor breakdown is set out in the Privacy Policy.

Questions

Data-protection queries: privacy@pistaclub.app
Data Protection Officer: dpo@pistaclub.app
Contract / legal: legal@pistaclub.app

The full list of controllers, processors, and their roles for each data category on the platform is in the Privacy Policy — Controller / processor split.