Annex C Authorized subprocessors
Terms and Notices — Sellforte Solutions Oy — 2026-09
EU/rest of the world (excluding the US). The contracting entity in the Order Form determines the applicable terms.
Annex C Authorized subprocessors
Version 2026-09-22
The Customer authorizes the following subprocessors for the stated functions when used to provide its Services. The agreed primary hosting region does not exclude the other processing or remote-access locations described below. Only processing necessary for the authorized functions is permitted, subject to DPA Section 13 (International transfers) and Annex D. Additions or replacements follow DPA Section 7.2 (List and changes). Supplier disclosures describe their processing arrangements and do not independently expand this authorization.
|
Entity |
Function |
Location and use |
|---|---|---|
|
Amazon Web Services EMEA SARL and Amazon Web Services, Inc. |
Hosting, backups, and Bedrock inference |
EU, ordinarily Ireland, by default. Another supported primary region may be agreed in the Order Form. Processing outside the selected region may occur where needed for requested services, including support when data is shared with AWS, or for legally required disclosures subject to Annex D. Bedrock inference follows the authorized region or inference-profile configuration. AWS DPA; AWS subprocessors. |
|
Google Cloud EMEA Limited |
Alternative hosting and infrastructure |
EU primary hosting by default; another supported region if agreed in the Order Form. Service-specific location commitments apply to the selected services. Google and its authorized subprocessors may process data elsewhere for support and service operations, subject to those commitments and Annex D. Google Cloud DPA; Google Cloud subprocessors. |
|
Fivetran Inc. |
Data connectors and ingestion |
EU pipeline processing region by default; another supported region if agreed in the Order Form. Authorized personnel and downstream providers may process data outside the EEA for support, development, and service operations, including in the United States and India. Applicable locations depend on the services and support used. Fivetran DPA; Fivetran subprocessors. |
|
Microsoft Ireland Operations Limited |
Microsoft 365 communications and collaboration containing Customer Personal Data |
Applicable Microsoft 365 residency and EU Data Boundary commitments govern storage and processing; the boundary includes the EU and EFTA. Documented exceptions include limited overseas support and operational access, security processing, and customer-enabled features or communications. Overseas processing is not limited to legal disclosures. Microsoft DPA; Microsoft EU Data Boundary disclosures. |
|
HubSpot Ireland Limited |
Support and ticket management containing Customer Personal Data |
EU primary hosting. HubSpot affiliates and downstream providers may process data outside the EEA for service and support, global content delivery and security, and enabled features. Locations include the United States; the relevant downstream locations depend on the features used. HubSpot DPA; HubSpot subprocessors. |
|
Sellforte, Inc. |
Authorized engineering, support, and service delivery for Oy Customers |
United States. Authorized personnel may work on Oy Customer Services through access to the agreed service environments under the intragroup processing agreement and applicable transfer safeguards. Customer Personal Data must not be downloaded, copied locally, or retained by Inc. beyond the access session. |
|
Sellforte Solutions GmbH |
Authorized engineering, support, and service delivery for Oy Customers |
Germany. Authorized personnel may work on Oy Customer Services under the intragroup processing agreement. |
|
Sellforte Solutions UK Ltd |
Authorized engineering, support, and service delivery for Oy Customers |
United Kingdom. Authorized personnel may work on Oy Customer Services under the intragroup processing agreement and applicable transfer safeguards. |
The listed Sellforte Affiliates may assist with these functions whether or not currently involved in a Customer's Services. Sellforte remains responsible and ensures confidentiality, processing, and applicable transfer safeguards before access. Changes beyond this authorization follow DPA Section 7.2 (List and changes). Sellforte will proactively provide current identities, addresses, contacts, functions, and processing countries for relevant processors and downstream subprocessors through a customer-accessible register or direct communication. Linked supplier registers support this information; their updates do not waive the DPA's notice and objection requirements.
