Sub-processors

A sub-processor is a third party we engage to process personal data on our behalf to operate the Service.

Effective date: August 1, 2025

Owner/Controller

AEY GROUP

P.O. Box 5863, Nairobi, Kenya

Contact

hello@aey-group.com

What are Sub-processors?

A sub-processor is a third party we engage to process personal data on our behalf to operate the Service. We require all sub-processors to sign data-processing terms with confidentiality, security, and purpose limitation obligations.

Current Sub-processors

ProviderPurposeTypical LocationsData CategoriesTransfer Safeguards
DigitalOcean, LLCApp hosting, networking, DNSUSA/EUAccount metadata, IPs, uploaded files (encrypted at rest), logsSCCs and/or DPF where applicable
Amazon Web Services, Inc. (AWS)Object storage, compute, backups, queuesUSA/EU (as configured)Uploaded PDFs & derived outputs (encrypted), logs, telemetrySCCs and/or DPF where applicable
Paystack Payments Ltd.Payments processingGlobal (regional processing)Billing details, transaction metadata (no full card numbers stored by us)SCCs/contractual safeguards
Mixpanel, Inc.Product analyticsUSA/EUPseudonymous event telemetry, device/browser dataSCCs and/or DPF where applicable
Google Analytics 4 (Google LLC)Web analyticsGlobalPage analytics, device/browser dataSCCs and/or DPF where applicable
Google Search Console (Google LLC)Search performance diagnosticsGlobalAggregated search/query metrics (site-level)SCCs and/or DPF where applicable
PostHog (Cloud or self-host)Product analytics & funnelsIf Cloud: USA/EU; if self-host: your serversPseudonymous product eventsSCCs/contractual safeguards (Cloud)
Sentry (Functional Software, Inc.)Error & performance monitoringUSA/EUError stack traces, runtime metadata (no uploaded PDFs)SCCs and/or DPF where applicable

Important Notes

Hosting

We primarily host in the United States. Customer uploads are encrypted in transit and at rest.

Payments

All card data is handled by Paystack and its PCI-compliant partners; we do not store full card numbers.

Change-Notification Policy

  • We will post updates to this page for new or replacement sub-processors and, where required, provide email notice ≥30 days before the change becomes effective (except in urgent cases to maintain security or continuity, in which case we will notify as soon as practicable).
  • To receive notices, email hello@aey-group.com with subject "Subscribe: Sub-processor Updates".

Objecting to a New Sub-processor

If you reasonably object to a new sub-processor (for data-protection reasons), contact us within 30 days of notice. We'll work in good faith to provide an alternative. If we cannot, you may terminate the affected Service component without penalty (pro-rata refund where applicable).

Security Baseline

All sub-processors must implement technical and organizational measures appropriate to the risk (e.g., encryption in transit/at rest, access controls, logging, incident response). We assess vendor security posture during onboarding and periodically thereafter.

We maintain transparency about our data processing partners and ensure all sub-processors meet our security and privacy standards.