What this page is
A sub-processor is a company XEX uses that may process personal data in the course of providing the platform. This page is the operative list referred to by the Data Processing Addendum: a change here is the notice, and an operator may object to an addition on the terms set out in that addendum.
Each row states what the vendor actually does in this platform. Where the contracting entity, the processing location or the transfer mechanism is not settled, it is marked rather than guessed.
The list
| Provider | What it does here | Personal data it may see | Entity and location |
|---|---|---|---|
| Microsoft Azure | Hosting and compute for the platform and its database. | All data stored by the platform, at rest and in transit through the hosting layer. | [[ To be supplied — contracting entity, region and transfer mechanism ]] |
| Azure Communication Services | Transactional and operator-initiated email (sign-in, notifications, broadcasts). | Recipient email address and the content of the message sent. | [[ To be supplied — contracting entity, region and transfer mechanism ]] |
| Google Firebase Authentication | Sign-in for the operator console and for member web sign-in where the programme uses it. | Email address, authentication events and device/browser metadata generated by the sign-in. | [[ To be supplied — contracting entity, region and transfer mechanism ]] |
| Didit | Identity verification, where a programme uses it. XEX receives a decision and a non-reversible handle — never a document. | Whatever you submit directly to the provider during verification, under its own notice; XEX receives only the outcome. | [[ To be supplied — contracting entity, region and transfer mechanism ]] |
| Stripe | The platform's own go-live setup fee, charged by XEX to an operator. | Operator billing contact and payment metadata. Card details are entered with the provider, not with XEX. | [[ To be supplied — contracting entity, region and transfer mechanism ]] |
| NOWPayments | The alternative crypto route for the platform's own go-live setup fee. | Operator billing metadata and the invoice reference. | [[ To be supplied — contracting entity, region and transfer mechanism ]] |
Related third parties that are not XEX sub-processors
These are named because leaving them out would give a misleading picture, and including them in the table above would give a false one.
- An operator’s own payment providers. Members pay the operator on the operator’s own accounts — its card processor, its crypto invoice account, its bank, its wallet, its settlement host. Those are the operator’s processors, not XEX’s. The platform holds no credential of its own on those rails.
- An operator’s own verification account. Where a programme brings its own identity-verification account, that provider is engaged by the operator.
- An operator’s own analytics and advertising destinations. A programme may configure its own analytics property, tag manager, or advertising conversions. Those are the operator’s, subject to the consent gate described in Cookie Policy.
- ip-api.com. An optional IP-enrichment source for detecting proxies and datacentre ranges. It is disabled by default and is not enabled on this deployment; with it disabled, no address is sent anywhere for enrichment. If it is ever enabled, this page changes first, because at that point an IP address does leave the platform. The country decision itself never uses it: countries are resolved from an address-range table in our own database.
- The Tor Project exit list. The platform downloads a published list of exit-node addresses. Nothing about a visitor is sent in order to fetch it, so it is not a processor of anyone’s data.
- Google Analytics. Not currently loaded by this website at all — see Cookie Policy. If and when it is, it operates under consent, and this page will list it.
How changes are notified
The change is the notice. When a sub-processor is added, removed or replaced, this page is updated, operators are notified, and the change log below records it. The notice period and the objection route are in the Data Processing Addendum.
A notification channel and a subscription mechanism have not been built. Until they are, “operators are notified” means a message to the address on the workspace record, sent by hand. That is a commitment this platform can currently keep; an automated feed is not.
Change log
This list has not changed since it was first drafted, so there is nothing to record. Entries will be added here, each stating what changed and when it took effect. An empty log is the honest state of a document that has never been published; it will not be back-filled with invented history.
Questions
Questions about this list, or an objection to a proposed sub-processor, go to [[ To be supplied — privacy contact address ]]. Include the workspace name and, for an objection, the data-protection ground you rely on — see Sub-processors in the Data Processing Addendum.