Aopy Platform
Sub-Processors
Last updated: 22 July 2026
About This Register
When you use the Aopy platform to store your contacts and send them email or SMS messages, you act as the data controller of that Contact Data, and Easy Life Tech SRL ("Aopy", "we", "us") acts as your data processor, as set out in our Data Processing Agreement (the "DPA").
A sub-processor is a third-party service provider that Aopy engages to process personal data on behalf of our customers in order to deliver the Service — for example, cloud infrastructure, email delivery or error monitoring. Under Article 28(2) and 28(4) GDPR, we may use sub-processors only with your authorisation and under a written contract that imposes data-protection obligations equivalent to those we owe you.
This page is the canonical register of the sub-processors we use. Under the DPA, customers grant a general written authorisation for the sub-processors listed here. We give advance notice of intended additions or replacements, and you may object through the mechanism described in the DPA.
Sub-Processor Register
The table below lists each sub-processor, the purpose for which we engage it, the categories of personal data it processes, its processing location and the transfer safeguard that applies.
| Sub-processor | Purpose | Personal data processed | Location / region | Transfer safeguard |
|---|---|---|---|---|
| Amazon Web Services (SES, SQS, Lambda) | Email delivery and message-queue infrastructure | Contact email addresses, message content, engagement events | EU (eu-west-1, Ireland) | Processing within the EEA |
| Twilio SendGrid | Email delivery failover | Contact email addresses, message content | USA | Standard Contractual Clauses (SCCs) |
| Supabase | Database and authentication | All platform data | EU (eu-west-1) | Processing within the EEA |
| Vercel | Application hosting and CDN | Request metadata, IP addresses, user-agent | EU edge + US control plane | SCCs |
| Stripe | Payments and subscriptions | Billing identity and payment references (we store only Stripe reference identifiers and masked card details — brand and last four digits; we never store card numbers) | EU / USA | SCCs |
| Upstash | Rate limiting (Redis) | Transient request keys | EU (eu-west-1) | Processing within the EEA |
| Sentry | Error monitoring | Error traces, partial request metadata | USA | SCCs |
| SMSO.ro | SMS delivery (Romania) | Phone numbers, SMS message content, delivery receipts | Romania (EU) | Processing within the EEA |
| Google (Gemini) | AI image generation (optional feature; disabled when your organisation's US-AI processing setting is off) | Image-generation prompts — no Contact Data | USA | SCCs |
| OpenAI | AI image generation (optional feature; controlled by the same organisation-level setting) | Image-generation prompts — no Contact Data | USA | SCCs |
| remove.bg | Image background removal (optional feature) | Uploaded images | EU / global — under confirmation (see note below) | Under confirmation (see note below) |
| ANAF e-Factura | Mandatory Romanian electronic invoicing (when billing is active) | Invoice and fiscal data | Romania (state authority) | Legal obligation — independent public-authority recipient (see note below) |
| Meta, TikTok, Google Ads/GA4, Shopify, WooCommerce | Optional integrations that you connect; data flows only on your instruction | Advertising audiences, product and order data — depending on the integration | Per provider | Customer-directed transfers (see "Customer-Directed Integrations" below) |
Note on remove.bg: we are confirming the contracting entity, processing region and transfer safeguard for this optional feature. This entry will be updated as soon as the confirmation is complete.
Note on ANAF: ANAF (the Romanian tax authority) receives invoice data because Romanian law obliges us to transmit it. Strictly speaking, ANAF acts as an independent recipient — a public authority — rather than a sub-processor within the meaning of Article 28 GDPR. It is listed here for transparency, and this transmission is not subject to the objection mechanism.
International Transfers
Our primary infrastructure is located in the European Union (AWS and Supabase in the eu-west-1 region, Ireland). Where a sub-processor processes personal data in the United States or otherwise outside the European Economic Area, the transfer is safeguarded by the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914) or another valid transfer mechanism under Chapter V GDPR.
Control over US AI processing. AI image generation (Google Gemini and OpenAI) is an optional feature. An organisation-level setting lets each customer disable all AI image generation through US providers; when that setting is off, no data is sent to these providers. Only image-generation prompts are transmitted for this feature — never Contact Data.
To request a copy of the transfer safeguard applicable to a specific sub-processor, contact privacy@aopy.com.
Customer-Directed Integrations
The Service offers optional integrations with Meta, TikTok, Google Ads/GA4, Shopify and WooCommerce. These providers are not sub-processors engaged at our initiative: personal data flows to or from them only when you, the Customer, connect and configure the relevant integration. Those flows take place on your documented instruction, and each provider processes the data under its own terms.
The data involved depends on the integration — for example, advertising audiences for ad platforms, and product or order data for e-commerce platforms. Before connecting an integration, you should satisfy yourself that you have a lawful basis for the resulting transfer and review the provider's own privacy documentation. Practical guidance is available in our Data Processing Guidelines.
Separately from the customer-directed integrations above, Aopy uses Google Analytics, the Meta Pixel and the TikTok Pixel on its own public marketing website (aopy.com) for its own analytics and advertising, as an independent controller of site-visitor data. This does not involve Customer platform data and is not sub-processing under this register; see our Cookie Policy for details.
Changes to This Register
This page is the authoritative, current version of our sub-processor register. Each revision updates the "Last updated" date shown on this page.
Before we add or replace a sub-processor that will process personal data on your behalf, we will give you advance notice in accordance with the DPA, so that you can object within the window stated there. To receive change notifications by email, write to privacy@aopy.com with the subject line "Sub-processor notifications".
Contact
Questions about this register or our sub-processing arrangements can be addressed to our Privacy Team at privacy@aopy.com.
Easy Life Tech SRL, CUI 54742254, Trade Register No. J2026033503008, registered office: Șos. București-Ploiești, Nr. 15, Imobilul 2 - Spațiu Comercial, Etaj 5, Sector 1, București, Romania. See also our Privacy Policy and Data Processing Agreement.
Language
This register is published in English and Romanian. In the event of any inconsistency between the two versions, the English version prevails.