This document was approved for publication following qualified Irish/EU and Brazilian legal review. Customer-specific Order Forms and negotiated agreements control where expressly stated.
A subprocessor is a provider engaged by kubbeevault to process personal data for a Customer. A provider is relevant only when the Customer uses the related service, page, feature, region, or support workflow. This list distinguishes the core platform from public-website enquiry processing.
1. Core platform and support
- Amazon Web Services, Inc. and relevant AWS affiliates — cloud infrastructure, hosting, storage, networking, backup, and related managed services — location: an available AWS region selected according to the Customer’s requirements and recorded in the Order Form or service schedule, plus limited support locations applicable to the AWS services used — data: Customer Data and service metadata for hosted deployments. For example, an Irish AWS region may be selected when required by the Customer; kubbeevault does not impose one default customer-data region for every deployment.
- KUBBEEVAULT INOVA SIMPLES (I.S.), Brazil — platform engineering, operation, security, and support, including authorised service delivery for European Customers contracted through KUBBEE TECH LIMITED — data: Customer Data and account/support information only as needed for authorised service delivery.
- KUBBEE TECH LIMITED (CRO number 811108), Ireland — European commercial operations and authorised service or support activities for European Customers — data: account, commercial, support, and limited Customer Data only when needed for authorised support.
2. Public website and enquiries
- EmailJS Pte. Ltd. — form-delivery infrastructure for contact-sales and demo requests — processing may include the United States and locations used by EmailJS and its providers — data: submitted business contact and enquiry information, reCAPTCHA response, and delivery metadata. EmailJS is not used to transmit vault secrets.
- Google LLC and relevant affiliates — Google reCAPTCHA v2 for form abuse prevention — processing locations determined by Google — data: IP address, browser/device information, interaction and risk signals, and reCAPTCHA response.
- kubbeevault’s configured business email provider — receipt and storage of website enquiries delivered through EmailJS — data: submitted business contact information, enquiry content, and delivery metadata. Provider-specific processing and transfer terms are supplied to affected Customers on request and reflected in the applicable processing records.
3. Deployment-dependent and Customer-controlled providers
A Customer-selected identity provider, integration, private-cloud provider, on-premises environment, email destination, or other third-party service is not a kubbeevault subprocessor when it is contracted and controlled directly by the Customer. Its data practices are governed by the Customer’s agreement with that provider.
Open-source components such as Kubernetes, Keycloak, and PostgreSQL are not separately listed merely because the software is used in a kubbeevault-managed environment; the infrastructure or service operator that receives personal data must be listed when it acts as a subprocessor.
4. Changes and objections
kubbeevault will keep this list current and provide the advance notice required by the final DPA before a new subprocessor begins processing Customer Personal Data. Customers may submit a reasoned data-protection objection to [email protected] within the notice period. The final publication must provide a change-subscription mechanism or documented customer notification process.