Arcanix BV | BTW BE 1028.247.312 · Coupure 88, 9000 Ghent, Belgium · support@arcanix.ai
Pursuant to the Agreement, Arcanix provides the Platform and the Services (both as defined below) to the Customer (as defined below). The provision of the Platform and the Services leads to the collection and processing of Personal Data (as defined below) by Arcanix, in its capacity as a data processor, on behalf of the Customer. Therefore, Arcanix provides the Customer with this Data Processing Policy ("DPP") which sets out (i) how Arcanix shall manage, process and secure the Personal Data, as well as (ii) all parties' obligations to comply with the Privacy Legislation (as defined below).
By concluding an Agreement with Arcanix, the Customer has indicated that it has read, understands and accepts the terms and conditions of this DPP, which forms an integral part of said Agreement. Capitalised terms in this DPP shall have the same meaning as in the Agreement.
This DPP may be updated from time to time by Arcanix, in which case Arcanix shall notify the Customer through its Website (as defined below) or the Platform. In any event, the latest version of this DPP can always be accessed on the Website, as well as on the Platform.
1. Definitions
1.1 Capitalised terms shall have the meaning as set out below.
- Arcanix: The company Arcanix BV, incorporated and existing under the laws of Belgium, with registered office at Coupure 88, 9000 Ghent, with VAT/company number BE-1028.247.312;
- Assignment: All activities, performed by Arcanix for the Customer, and any other form of cooperation whereby Arcanix Processes Personal Data for the Customer, regardless of the legal nature of the agreement under which this Processing takes place;
- Controller: The entity, which determines the purposes and means of the Processing of Personal Data, meaning the Customer as defined in the Agreement;
- Data Subject: An identified or identifiable natural person where an identifiable natural person should be considered one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
- Personal Data Breach: Unauthorised disclosure, access, abuse, loss, theft or accidental or unlawful destruction of Personal Data, which are processed by Arcanix on behalf of the Customer;
- Personal Data: Any information relating to an identified or identifiable natural person (i.e. Data Subject);
- Platform: The LiveOps strategy platform for video games developed by Arcanix, provided as a software-as-a-service solution.
- Privacy Legislation: The (supra)national privacy legislation applicable to the processing of personal data by the Customer or Arcanix within the scope of the Agreement, such as, but not limited to: (i) the General Data Protection Regulation 2016/679 of April 27, 2016 ("GDPR"); (ii) United Kingdom (UK) Data Protection Act 2018 ("UK GDPR"); (iii) the Belgian Privacy Law of 30 July 2018; (iv) the ePrivacy Directive 2002/58/EC of 12 July 2002, including future amendments and revisions thereof; and/or (v) (future) national legislation regarding the implementation of the GDPR;
- Process/Processing: Any operation or set of operations which is performed upon Personal Data or sets of Personal Data, including but not limited to: collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction of Personal Data;
- Processor: The entity which Processes Personal Data on behalf of the Controller;
- Services: All services, provided by Arcanix to the Customer with respect to the Platform (such as but not limited to support and maintenance);
- Sub-processor: Any Processor engaged by Arcanix.
1.2 The Policy includes the following annexes:
- Annex I: Overview of (i) the Personal Data, which parties expect to be subject of the Processing, (ii) the categories of Data Subjects, which parties expect to be subject of the Processing, the (iii) retention period for each Processing; and (iv) the use (i.e. the way(s) of Processing) of the Personal Data, the purpose and means of such Processing;
- Annex II: Overview and description of the security measures taken by Arcanix; and,
- Annex III: List of Sub-processors engaged by Arcanix.
1.3 The (uncapitalised) terms "(data) controller"; "personal data"; "personal data breach"; "process"; "processing"; "(data) processor" shall have the meaning attributed to them in the Privacy Legislation.
2. Roles of the Parties
2.1 Parties acknowledge and agree that with regard to the Processing of Personal Data as instructed by the Customer, the Customer shall be considered 'Controller' and Arcanix 'Processor'. Further, Arcanix is allowed to engage Sub-processor(s) pursuant to the requirements set forth in Article 7.
2.2 Each party shall comply with its respective obligations under the Privacy Legislation with respect to the processing of the Personal Data.
3. Use of the Application and/or the Services
3.1 The Customer acknowledges explicitly that:
- Arcanix purely acts as a facilitator of the Platform and/or the Services. Hence, the Customer shall be solely responsible on how and to what extent he/she makes use of the Platform and/or the Services as well as for all Personal Data collected through the Platform;
- It is responsible for all acts and omissions of Authorised Users (i.e. in case the Authorised User does (not) take sufficient measures to protect its Account on the Platform);
- As a result of using the Platform, connections will be established between the Customer's technological infrastructure and the Platform. However, data will only be uploaded upon approval of the Customer;
- It is responsible for the material and/or data provided by the Data Subject. The Customer is, as Controller, thus responsible for complying with the Privacy Legislation and/or any other regulations with regard to aforementioned material and/or data; and,
- It shall comply with all laws and regulations (such as, but not limited to: with regard to the retention period or rights of the Data Subject) imposed on it by making use of the Services.
3.2 The Customer shall avoid any misuse of the Platform and/or the Services. In case of misuse by the Customer of the Platform and/or the Services, the Customer agrees that Arcanix can never be held liable in this respect nor for any damage that would occur from such misuse.
3.3 The Customer therefore undertakes to safeguard Arcanix when such misuse would occur as well as for any claim from a Data Subject and/or third party due to such misuse.
4. Object
4.1 Customer acknowledges that as a consequence of making use of the Platform and/or the Services of Arcanix, the latter shall Process Personal Data as collected by the Customer. The nature and purpose of said processing, as well as a description of the Personal Data and categories of Data Subjects processed under the Agreement are further specified in Annex I.
4.2 Arcanix shall always Process the Personal Data in a proper and careful way and in accordance with the Privacy Legislation and other applicable rules concerning the Processing of Personal Data.
4.3 More specifically, Arcanix shall:
- during the performance of the Assignment – provide all its know-how in order to perform the Assignment according to the rules of art, as it fits a specialized and 'good' processor; and,
- shall adopt, to the best of its abilities, the necessary security measures (cfr. Annex II) and provide all its know-how in order to perform the Services in accordance with the rules of art.
4.4 The Customer keeps full control concerning the following: (i) how the Personal Data must be processed by Arcanix; (ii) the types of Personal Data processed; (iii) the categories of Data Subjects whose Personal Data is subjected to the processing; (iv) the purpose of the processing; and (v) the fact whether such processing is proportionate.
4.5 This DPP is without prejudice to the provisions of the Agreement with regard to 'Data Protection'.
5. Instructions from / Responsibility of the Customer
5.1 Instructions: Arcanix shall only process the Personal Data upon the Customer's request and in accordance with the Customer's lawful instructions in Annex I, unless any legal obligation states otherwise. Arcanix shall inform the Customer, if in its opinion, the instructions infringe the Privacy Legislation. If the Customer subsequently cannot guarantee the validity or legality of the instruction or fails or refuses to change the unlawful instruction so that it no longer violates the Privacy Legislation, Arcanix shall be entitled to (i) suspend/refuse the performance of said instruction and (ii) at its discretion, to either continue to process the Personal Data in accordance with previously provided instructions or to stop the processing altogether, until the Customer has revised its instruction so that it no longer violates the Privacy Legislation.
5.2 Responsibilities: Furthermore, the Customer acknowledges that it is responsible for:
- the accuracy, quality and legality of (the collection and transfer of) the Personal Data;
- compliance with all transparency and lawfulness requirements under the Privacy Legislation for the collection and processing of the Personal Data and the transfer thereof to Arcanix; and,
- ensuring compliance of its instructions (cfr. Annex I) with the Privacy Legislation.
5.3 Customer shall inform Arcanix without undue delay if it is not able to comply with its responsibilities under this Section or the Privacy Legislation.
6. Security of Processing
6.1 Arcanix takes the security of the Processing activities very seriously. Arcanix shall at least implement the technical and organisational measures specified in Annex II to ensure the security of the Personal Data. This includes protecting the data against a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access to the data (Personal Data Breach). In assessing the appropriate level of security, Arcanix and the Customer shall take due account of the state of the art, the costs of implementation, the nature, scope, context and purposes of Processing and the risks involved for the Data Subjects.
7. Sub-processors
7.1 Approval of Sub-processor list
7.1.1 The Customer acknowledges and agrees that Arcanix may engage Sub-processors in connection with provision of the Services (and the performance of the Agreement). In such case, Arcanix shall ensure that the Sub-processors are at least bound by the same obligations by which Arcanix is bound under this DPP.
7.1.2 Arcanix has currently appointed as Sub-processors its Affiliates and other third parties as listed in Annex III.
7.1.3 Arcanix shall be liable for the acts and omissions of its Sub-processors to the same extent as if it would be performing the Services/Processing of the Personal Data itself, directly under the terms of this DPP.
7.2 Update of the Sub-processor list
7.2.1 Arcanix shall:
- update the list whenever a Sub-processor changes (e.g. a new Sub-processor was added, a Sub-processor was substituted, etc.);
- clearly indicate the changes in the list; and,
- add a timestamp (i) when the list was updated, and (ii) when the change of the Sub-processor went or will go into effect.
7.2.2 Arcanix shall notify the Customer (e.g. on the Website or through the Platform) when changes to the list are made.
7.3 Objection
7.3.1 If the Customer wishes to exercise its right to object to a new Sub-processor, it shall notify Arcanix in writing (cfr. Article 15) and based on reasonable grounds by the latest within thirty (30) days after the notification. If the Customer fails to object within the aforementioned timeframe it shall be deemed to have waived its right to object and to have authorised Arcanix to engage the new Sub-processor.
7.3.2 In the event aforementioned objection is not found unreasonable by Arcanix, parties will discuss the Customer's concerns with a view to achieving a reasonable solution. Such solution may include, at Arcanix's discretion, to (i) make available to the Customer a change in the Services; or (ii) recommend a commercially reasonable change to the Customer's use of the Services to avoid the processing of the Personal Data by the objected new Sub-processor without unreasonably burdening the Customer.
7.3.3 If the parties are, however, unable to come to a solution within a reasonable period of time (which shall not exceed thirty (30) days following the objection of the Customer), the Customer may terminate the Services (in whole or partly) if:
- the Services/Platform cannot be used by the Customer without appealing to the objected new Sub-processor; or,
- such termination solely concerns that part of the Services which cannot be provided by Arcanix without appealing to the objected new Sub-processor;
and this by providing written notice thereof to Arcanix (cfr. Article 15) within a reasonable time.
7.3.4 Termination of the Services within the meaning of Article 7.3.3 shall be without liability to either party (but without prejudice to any fees incurred by the Customer prior to suspension or termination of the Services).
8. Transfer of Personal Data outside the EEA
8.1 The Personal Data shall be processed within the European Economic Area ("EEA").
8.2 However, the Customer recognizes that Arcanix is entitled to transfer and store the Personal Data to countries outside the EEA for the purpose of providing the Services and fulfilling its obligations under the Agreement, and provided that such transfer/storage is done in accordance with the Privacy Legislation regarding additional safeguards. In particular, any transfer of Personal Data outside the EEA by Arcanix to a third party whose domicile or registered office is in a country which does not fall under an adequacy decision enacted by the European Commission, shall be additionally subject to one or more of the listed EU-approved safeguards:
- European Commission Adequacy decision;
- closing a data transfer agreement: with the third country recipient, which shall contain the standard contractual clauses, as referred to in the 'European Commission implementing decision of 4 June 2021 (Decision (EU) 2021/914) on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council', including the performance of a transfer impact assessment. Before the transfer takes place, the recipient of the Personal Data/Sub-processor of Arcanix in the third country has to guarantee Arcanix that an adequate level of privacy compliance is ensured in this third party country;
- binding corporate rules: As it is the case for standard contractual clauses, the recipient of Personal Data/Sub-processor of Arcanix in the third country has to guarantee Arcanix that an adequate level of privacy compliance is ensured in the third party country; and/or,
- certification mechanisms.
8.3 In the event the transfer (or disclosure) of the Personal Data to a third country is required by EU law or EU member state law to which Arcanix is subject to, Arcanix shall inform the Customer of that legal requirement before the transfer/disclosure, unless that law prohibits such information on important grounds of public interest.
9. Confidentiality
9.1 Arcanix shall maintain the Personal Data confidential and thus not disclose nor transfer any Personal Data to third parties, without the prior permission of the Customer, unless when such disclosure and/or announcement is required by law or by a court or other government decision (of any kind). In such case Arcanix shall, prior to any disclosure and/or announcement, inform you in full transparency on the scope and manner thereof.
9.2 Arcanix shall ensure that its personnel, engaged in the performance of the Agreement, are informed of the confidential nature of the Personal Data, have received appropriate training on their responsibilities and have executed written confidentiality agreements. Arcanix shall ensure that such confidentiality obligations survive the termination of the personnel engagement.
9.3 Arcanix shall ensure that its access to Personal Data is limited to such personnel performing the Assignment in accordance with the Policy.
9.4 The Customer acknowledges the login information to be strictly personal and ensures not to share this information with any third parties.
10. Notification
10.1 Notification. Arcanix shall use its best efforts to inform the Customer as soon as reasonably possible when it:
- receives a request for information, a subpoena or a request for inspection or audit from a competent public authority (incl. supervisory authority) in relation to the processing of the Personal Data;
- receives a request from a Data Subject invoking its privacy rights under the Privacy Legislation (cfr. Article 10.3);
- has the intention to disclose Personal Data to a competent public authority (incl. supervisory authority); or,
- determines or reasonably suspects a personal data breach has occurred in relation to the Personal Data.
10.2 Personal data breach. In case of a personal data breach, Arcanix:
- shall notify the Customer without undue delay after becoming aware of this personal data breach and, to the extent possible, provide the information as required by Privacy Legislation (e.g. Article 33.3 GDPR). Upon request of the Customer, Arcanix shall provide – to the extent possible – assistance with respect to the Customer's reporting obligation under the Privacy Legislation;
- undertakes – as soon as reasonably possible – to take appropriate remedial actions to make an end to the personal data breach (if such has occurred under its responsibility) and to prevent and/or limit any future personal data breaches.
10.3 Rights of Data Subjects
10.3.1 Arcanix shall promptly notify the Customer if it receives a request from a Data Subject invoking its privacy rights under the Privacy Legislation. Arcanix shall not respond to any such Data Subject request without the Customer's prior written consent, except to confirm that the request relates to the Customer to which the Customer hereby agrees.
10.3.2 If a Data Subject requests to exercise his/her/their rights, it is the Customer's responsibility to assist the Data Subject in its request. Only if the Customer does not have the ability to correct, amend, block or delete the Personal Data (as required by Privacy Legislation), Arcanix shall assist the Customer (as long as commercially reasonable and in line with applicable regulations).
10.3.3 Notwithstanding the foregoing, the Customer remains responsible for compliance of such Data Subject requests.
10.4 Data Protection Impact Assessment. Taking into account the nature of the processing and to the extent that (i) a data protection impact assessment is required under Privacy Legislation and (ii) the required information is reasonable available to Arcanix and the Customer does not otherwise have access to said information, Arcanix shall – upon request of the Customer – provide reasonable assistance to the Customer with the execution of a data protection impact assessment and possible prior consultation with the competent supervisory authorities. To the extent permitted by the Privacy Legislation, the Customer shall be responsible for any costs arising from Arcanix' provisions of such assistance.
11. Liability
11.1 Both parties are solely liable for all damage, claims and/or fines of third parties, competent supervisory authorities or Data Subjects that are the result of their own breach of or non-compliance with (i) the provisions of this DPP, and (ii) the Privacy Legislation or other applicable rules concerning Personal Data. Each party shall indemnify the other party in this regard.
11.2 In case of breach/non-compliance as described in Article 11.1 the infringing party is liable to the other party and must reimburse the latter for all damages and costs, including reasonable attorney's fees, (legal) expenses and damage resulting from such a breach/non-compliance.
11.3 In case of a proven breach by Arcanix of its obligations under this DPP or under the Privacy Legislation, Arcanix shall:
- be liable for the proven direct damages incurred by the Customer;
- not be liable for indirect, immaterial and/or consequential damages, including (but not limited to:) loss of profit, loss of opportunities, loss of and/or damage to data, loss of reputation, sanctions and/or fines, and unforeseeable damages.
11.4 Arcanix's liability towards the Customer shall in any case be limited to the total amount paid by the Customer to Arcanix during the last twelve (12) months under the Agreement.
11.5 The provisions in this Section shall be without prejudices to any other liabilities as agreed upon in the Agreement.
12. Term
12.1 The total term of this DPP shall be the term of the Agreement. If no term is determined, this DPP shall remain in force as long as the Services has not come to an end.
13. Return and Deletion of Personal Data
13.1 Arcanix shall only retain the Personal Data as long as needed to provide the Services or for the term of the Agreement (cfr. Article 12). The Customer accepts that Arcanix may create back-ups of the Personal Data stored on the Platform.
13.2 Upon termination of the Services or the Agreement, the following shall apply:
- the Services and Platform shall be deactivated. Any Personal Data, stored on the Platform shall as from that moment no longer be available to the Customer;
- the Customer may request the Personal Data to be returned ('export') within thirty (30) days following the end of the Agreement or the Services, upon which Arcanix shall assess whether such export is possible from a technical perspective. In any event, Arcanix may, at its sole discretion, determine the format of the export. Arcanix reserves the right to charge any costs relating to such exports to the Customer;
- after said thirty (30) days-period, the Personal Data on the Arcanix Platform shall be deleted within one (1) month, unless it is required by applicable law to retain the Personal Data; and,
- the Personal Data may be present on back-ups. The Personal Data shall be deleted once the last back-up containing the Personal Data is rotated.
13.3 Please note that data or material provided to or submitted to Arcanix by the Customer during the use of the Services may be further stored and processed by Arcanix for further optimisation of the product and services following the termination of the Agreement or the Services. Arcanix will never sell your data to third parties.
14. Compliance / Inspections
14.1 Compliance. Upon the Customer's request, Arcanix shall make available to the Customer all information necessary and to the extent as requested by law to demonstrate its compliance with its obligations under this DPP.
14.2 Inspections
14.2.1 Arcanix shall allow the Customer (or a third party on its behalf) to carry out inspections – such as, but not limited to: an audit – and shall provide the necessary assistance thereto.
14.2.2 However, the Customer shall limit its initiatives to perform an inspection to a maximum of once a year. The Customer must notify Arcanix at least thirty (30) working days in advance. The performance of inspections may in any case not cause any delay in the performance of the Services by Arcanix.
14.2.3 The Customer shall impose sufficient confidentiality obligations on its (internal/external) auditors. As to ensure the confidentiality of other Customers, Arcanix has the right to require from the Customer and its auditors to sign a non-disclosure agreement before the start of the inspection and to limit the scope of the inspection or the access of the Customers to certain premises.
14.2.4 All inspection costs are exclusively borne by the Customer, except if (and to the extent that) a severe security incident/personal data breach (at Arcanix/under Arcanix's responsibility) or a violation of this DPP is determined during the inspection.
15. Notification / Contact Arcanix
15.1 Notifications by the Customer under this DPP and/or any questions or concerns with regard to the provisions of this DPP must be directed at support@arcanix.ai.
16. Miscellaneous
16.1 If one or more provisions of this agreement are found to be invalid, illegal or unenforceable, in whole or in part, the remainder of that provision and of this agreement shall remain in full force and effect as if such invalid, illegal or unenforceable provision had never been contained herein. Moreover, in such event, Parties shall negotiate to replace the invalid provision by an equivalent provision in accordance with the spirit of this agreement. If Parties do not reach an agreement, then the competent court may mitigate the invalid provision to what is (legally) permitted.
16.2 Deviations, alterations and/or additions to this Policy shall only be valid and binding to the extent that they have been accepted in writing by both parties.
16.3 This Policy and the corresponding rights and obligations that exist in respect of the Parties, cannot be transferred, directly or indirectly, without the prior written consent of the other party.
16.4 (Repeatedly) non-enforcement by a party or by both parties of any right or provision of this Policy, can only be regarded as a toleration of a certain state, and does not lead to forfeiture.
16.5 This Policy prevails to any other agreement between the parties.
17. Governing Law & Jurisdiction
17.1 This DPP, including its Annexes, shall be governed by the law and subject to the jurisdiction clause as provided in the Agreement.
Annex I – Instructions of the Controller
I. Description of the Processing Activities
Purpose: Correct operation and support of the Service and provision of analytics regarding game performance (managing accounts, rights, providing analytics to customer)
- Data Subjects: Gamers (users of the game marketed by Customer)
- Personal Data: IP Address; Account ID
- Retention: 12 months
Purpose: Correct performance of Services for the Customer's employees
- Data Subjects: Employees of Customer
- Personal Data: Professional e-mail address; Job title; Name; IP address
- Retention: 24 months
II. The Use (= way(s) of Processing) of the Personal Data and the Purposes and Means of Processing
Use of Personal Data — Ways of processing:
- Collect and store
- Align, combine and create
- Structure and analyse
- Transfer
- Retrieve
- Update
- Consult
- Erase and destroy
Means of processing:
- Platform
- Electronic communication
- Third party software (Sub-processors)
- Services
Annex II – Technical and Organisational Security Measures
This document entails the technical and organisational security measures implemented by Arcanix in support of its (Processing) activities, as set forth by the Privacy Legislation.
Arcanix designs its systems and processes according to the principles of Data Minimisation and Privacy by Design. The Arcanix platform and associated services are architected to operate without requiring the collection or long-term storage of Personal Data.
In limited cases where customers choose to provide Personal Data as part of a pilot, integration, or data-analysis engagement, Arcanix only accesses and temporarily stores such data for the specific, agreed-upon purpose and under the customer's explicit instruction.
1. Data Minimisation and Retention
- Arcanix does not require or proactively collect Personal Data for normal platform operation.
- When a customer provides Personal Data, it is stored securely for the minimum duration necessary to perform the agreed task or analysis.
- Once processing is complete, the data is securely deleted or returned to the customer, and any residual copies (e.g. cached or local files) are also removed.
- Retention periods are short and governed by internal procedures ensuring timely deletion.
2. Roles and Responsibilities
- Arcanix acts solely as a data processor under the documented instructions of the customer (data controller).
- The customer remains responsible for ensuring that any data shared with Arcanix complies with applicable data-protection legislation.
- All Arcanix personnel with potential access to customer data are bound by confidentiality obligations (NDAs or equivalent clauses) and follow internal guidance on appropriate handling and secure deletion of such data.
3. Access Control and Authentication
- Access to customer-provided data is restricted to authorised personnel directly involved in the relevant project or pilot.
- Access is granted on a temporary, least-privilege basis and revoked immediately after completion.
- Company systems use secure authentication methods and password-management practices consistent with industry norms.
4. Storage, Transmission, and Infrastructure
- Customer-provided data is stored only in secure, access-controlled environments managed by Arcanix for the duration of the engagement.
- Where data is accessed through online services or collaboration tools, Arcanix uses reputable, ISO 27001-certified cloud and productivity providers.
- The method of data transfer from the customer to Arcanix (e.g. via email, file-share, or other channels) is determined and controlled by the customer. Arcanix encourages customers to use secure transfer methods but cannot enforce them.
- No customer data is transferred to personal devices or non-approved systems.
5. Incident Response and Data Deletion
- In the unlikely event of a suspected or actual security incident affecting customer data, Arcanix will notify the customer without undue delay and cooperate fully in investigation and remediation.
- Upon completion of processing or upon the customer's request, Arcanix deletes all copies of the customer-provided data and confirms deletion in writing if requested.
6. Continuous Improvement and Governance
- Arcanix periodically reviews its data-handling and security practices to ensure alignment with GDPR principles and good industry practice.
- Internal procedures emphasise data minimisation, controlled access, and prompt deletion as the primary protective measures.
Summary
Arcanix's core approach to data protection is to avoid the processing of Personal Data wherever possible. Where temporary storage or access is necessary for agreed purposes, such data is kept securely, limited to authorised personnel, and deleted immediately once no longer needed.
Annex III – Sub-processors
Arcanix engages the following Sub-processors to assist in providing the Platform and Services:
| Name | Nature of processing | Territory | Safeguard (if applicable) |
|---|---|---|---|
| Microsoft Corporation | Cloud-based productivity and collaboration tools (Office 365), business intelligence and analytics (Power BI), cloud computing services (Azure) | United States (EU data centers available) | EU Standard Contractual Clauses, EU-US Data Privacy Framework certification |
| Google LLC | Cloud-based email, storage, and collaboration tools (Gmail, Google Drive, Google Sheets), cloud computing platform (Google Cloud Platform) | United States (EU data centers available) | EU Standard Contractual Clauses, EU-US Data Privacy Framework certification |
| Notion Labs Inc. | Cloud-based workspace and documentation platform | United States | EU Standard Contractual Clauses |
| Amazon Web Services, Inc. | Cloud computing and infrastructure services | United States (EU data centers available) | EU Standard Contractual Clauses, EU-US Data Privacy Framework certification |
| Augment Computing, Inc. | AI-powered code completion and development tools | United States | EU Standard Contractual Clauses |
| Supabase Inc. | Cloud-based backend-as-a-service platform (database hosting, authentication, storage) | United States (EU data centers available) | EU Standard Contractual Clauses |