1. Purpose
Where Keephy acts as processor, some providers may process Customer Personal Data as subprocessors. The exact data handled depends on architecture and configuration.
2. Current / planned core providers
| Provider | Purpose | Potential data |
|---|---|---|
| DigitalOcean | Application hosting, networking and infrastructure. | Application requests, technical logs and Customer Data processed by hosted components. |
| Google authentication services used for secure user sign-in. | Authentication identifiers and account information required to sign users in. | |
| GitHub | Source control and deployment integration. | Primarily source/deployment metadata; Customer Data should not intentionally be stored in source repositories. |
| PostHog Cloud EU | Consent-based product analytics, web analytics and masked session replay. | Pseudonymous user identifiers, organisation/workspace identifiers, page and product-use events, browser/device metadata and masked replay data where consent is given. |
This list must be reviewed before commercial launch and updated whenever authentication, email, payments, analytics, monitoring, support or other production vendors are added.
3. Changes
Keephy may add or replace providers as Trelyqo evolves. Where the DPA or applicable law requires notice, Keephy will provide notice and an appropriate objection process.
4. International processing
Providers may operate globally. Keephy will assess restricted transfers and use lawful transfer mechanisms where required.