B
BizBrew

Sub-processors

BizBrew UG (haftungsbeschränkt) i.G. uses the following service providers to run BizBrew. When a business stores its customers' data in BizBrew, these providers act as sub-processors (Art. 28(4) GDPR).

The terms for engaging them are part of the Data Processing Agreement

ProviderPurposePersonal dataLocationTransfer safeguard
Hetzner OnlineServer hosting for the application, database (self-hosted Supabase/PostgreSQL), file storage and cacheAll platform dataNOT CONFIGURED: LEGAL_SUBPROCESSORS_JSON → locationNOT CONFIGURED: LEGAL_SUBPROCESSORS_JSON → safeguard
CloudflareDNS, CDN and TLS proxy, Turnstile bot protection, Web Analytics (cookieless) on the marketing site, R2 storage for database backupsIP address, request metadata; database backupsNOT CONFIGURED: LEGAL_SUBPROCESSORS_JSON → locationNOT CONFIGURED: LEGAL_SUBPROCESSORS_JSON → safeguard
StripePayment processing for subscriptions and for tenants' customer payments (Stripe Connect)Name, e-mail, billing details, payment and transaction dataNOT CONFIGURED: LEGAL_SUBPROCESSORS_JSON → locationNOT CONFIGURED: LEGAL_SUBPROCESSORS_JSON → safeguard
ResendTransactional e-mail to business account holders (sign-up, verification, billing)E-mail address, name, e-mail contentNOT CONFIGURED: LEGAL_SUBPROCESSORS_JSON → locationNOT CONFIGURED: LEGAL_SUBPROCESSORS_JSON → safeguard
HostingerSMTP e-mail delivery to tenants' customers (booking confirmations, reminders, portal e-mails)E-mail address, name, e-mail contentNOT CONFIGURED: LEGAL_SUBPROCESSORS_JSON → locationNOT CONFIGURED: LEGAL_SUBPROCESSORS_JSON → safeguard
Bird (MessageBird)SMS and WhatsApp messages (phone verification, portal sign-in codes, reminders)Only when SMS/WhatsApp messaging is usedPhone number, message contentNOT CONFIGURED: LEGAL_SUBPROCESSORS_JSON → locationNOT CONFIGURED: LEGAL_SUBPROCESSORS_JSON → safeguard
Sentry (Functional Software)Error monitoring for the marketing website and the admin and customer portal applicationsTechnical error data, which can include IP address and user identifiersNOT CONFIGURED: LEGAL_SUBPROCESSORS_JSON → locationNOT CONFIGURED: LEGAL_SUBPROCESSORS_JSON → safeguard
Google (Firebase Cloud Messaging, Google Calendar API)Push notifications to the mobile apps; Google sign-in (OAuth) when a business connects a Google CalendarOnly when push notifications or a Google Calendar connection are usedDevice push token, notification content; calendar access tokenNOT CONFIGURED: LEGAL_SUBPROCESSORS_JSON → locationNOT CONFIGURED: LEGAL_SUBPROCESSORS_JSON → safeguard

Changes to this list are published on this page. Questions or objections: [email protected]