Draft — not yet in force
This list is part of a document suite under legal review. Sub-processor names, purposes and processing locations are final; the basis for transfer outside the Kingdom has not yet been executed.
Sub-processors
We disclose every third party that processes our customers' data on our behalf, why it is engaged, and exactly what it can access. Any addition to this list is notified to customers before it goes live.
Engaged and planned sub-processors
| Sub-processor | Purpose | What it can access | Processing location | Transfer basis |
|---|---|---|---|---|
| Oracle Cloud Infrastructure | Hosting of the whole platform: database, authentication, web application, attachments and backups | All categories of data stored in the platform | Saudi Arabia — Riyadh and Jeddah | Not required — processed inside the Kingdom |
| Sentry | Error monitoring and fault tracing | Technical data stripped of personal data before transmission — no names, national IDs or salaries | European Union | Not yet determined |
| Resend | Sending operational notification emails (request approvals and rejections) and account-recovery links | Display name, email address, event type and outcome only — no salaries, national IDs or rejection reasons, and no stored links | United States (log storage) — sending from Ireland | Not yet determined |
What we do not use
We state these explicitly because their absence is information an enterprise buyer needs, and each is verifiable in the product's own behaviour:
- No SMS provider — second-factor authentication uses an authenticator app (TOTP) only, so no code is sent to a mobile number.
- No third-party support ticketing system to date.
- No payment gateway — billing happens outside the platform and no payment data passes through it.
This page mirrors Annex 3 of the Data Processing Agreement and is generated from the same source. Any change to this list is notified to our customers directly before it takes effect — publishing this page alone does not constitute notice.