PoiGeo← Map

Legal · B2B

Sub-processors

Last updated: · v2026.05.17

1. About this list

This page lists the sub-processors [Şirket — kuruluş aşamasında] engages to support the Service. We require each sub-processor to provide at least the same level of data protection as we commit to under our Data Processing Addendum and the GDPR Article 28.

2. Current sub-processors

VendorServiceDataRegionTransferDPA
Supabase Inc.Auth, Postgres database, storageAccount data, usage data, ReportsUnited States (EU region available)SCCs (2021/914) + UK Addendumlink
Vercel Inc.Application hosting, edge runtimeAccess logs, request metadataUnited States (multi-region)SCCs + UK Addendumlink
Lemon Squeezy LLC (Merchant of Record)Subscription billing, payment processing, fraud screening, tax handlingBilling identity, payment method (tokenised), invoicesUnited StatesSCCs + UK Addendumlink
Google LLCGemini AI (Vertex AI), Google Maps Platform (Places, Routes)AI prompt: lat/lng + POI list (no personal data unless user adds it)United StatesSCCs + UK Addendumlink
Upstash Inc.Serverless Redis (rate-limit, cache)Hashed IP, hashed fingerprint, cached H3 cells (no personal data)United States (multi-region)SCCslink
Cloudflare Inc.DNS, CDN, bot management on poigeo.appIP address, request metadataGlobal (multi-region)SCCs + UK Addendumlink
Resend Inc. (or successor)Transactional email deliveryEmail address, message content/headersUnited StatesSCCslink

3. Data-source vendors

The following vendors provide point-of-interest data we consume. We do not transmit identifiable customer data to them — queries contain only the coordinates of the area being analysed.

VendorServiceDataRegionTransferDPA
OpenStreetMap FoundationPOI data (read-only Overpass / Nominatim queries)Query: lat/lng (not linked to user)United KingdomPublic data; no personal data sharedlink
Foursquare Labs Inc.POI / venue data APIQuery: lat/lng (not linked to user)United StatesSCCslink
BestTime AIFoot-traffic estimates (optional)Query: venue IDs (no personal data)United StatesSCCslink

4. Transfer safeguards

Where personal data is transferred outside the EEA, the UK, Switzerland, or Türkiye, we rely on the European Commission's Standard Contractual Clauses (Commission Implementing Decision 2021/914), the UK International Data Transfer Addendum, the Swiss FDPIC SCC supplement, and KVKK Article 9 contractual undertakings as appropriate. We also apply supplementary technical measures: TLS in transit, AES-256 at rest, scoped access, audit logging, and provider-side regional pinning where available.

5. Notification of new sub-processors

Business customers may subscribe to advance notice of new or changed sub-processors by emailing privacy@poigeo.app. We will give at least 30 days' written notice before a new sub-processor begins processing personal data (except in emergencies, where the notice will be as soon as reasonably practicable).

6. Objecting to a sub-processor

A business customer who reasonably objects to a new sub-processor on documented data-protection grounds may notify us in writing within fifteen (15) days of our notice. We will work in good faith to address the objection. If we cannot, the customer may terminate the subscription for the affected portion of the Service and receive a pro-rata refund of pre-paid fees for the unused period.