Draft — not yet in force

This list is part of a document suite under legal review. Sub-processor names, purposes and processing locations are final; the basis for transfer outside the Kingdom has not yet been executed.

Sub-processors

We disclose every third party that processes our customers' data on our behalf, why it is engaged, and exactly what it can access. Any addition to this list is notified to customers before it goes live.

Engaged and planned sub-processors

Sub-processorPurposeWhat it can accessProcessing locationTransfer basis
Oracle Cloud InfrastructureHosting of the whole platform: database, authentication, web application, attachments and backupsAll categories of data stored in the platformSaudi Arabia — Riyadh and JeddahNot required — processed inside the Kingdom
SentryError monitoring and fault tracingTechnical data stripped of personal data before transmission — no names, national IDs or salariesEuropean UnionNot yet determined
ResendSending operational notification emails (request approvals and rejections) and account-recovery linksDisplay name, email address, event type and outcome only — no salaries, national IDs or rejection reasons, and no stored linksUnited States (log storage) — sending from IrelandNot yet determined

What we do not use

We state these explicitly because their absence is information an enterprise buyer needs, and each is verifiable in the product's own behaviour:

  • No SMS provider — second-factor authentication uses an authenticator app (TOTP) only, so no code is sent to a mobile number.
  • No third-party support ticketing system to date.
  • No payment gateway — billing happens outside the platform and no payment data passes through it.

This page mirrors Annex 3 of the Data Processing Agreement and is generated from the same source. Any change to this list is notified to our customers directly before it takes effect — publishing this page alone does not constitute notice.