B
Buyervalues.ai
ProductHow it worksGrowth LabBuyer valueUse casesProofPricingBlog
Sign InAnalyse Your Company (free)
Legal

Subprocessor List

This page is provided for convenience and may be updated over time.

Subprocessor List

Last updated: Aug 10, 2026

This list identifies service providers authorized to process personal data for Lingonberry Island Ltd. in connection with Buyervalues.ai. A provider marked feature-dependent processes data only when the related feature is configured and used.

The legal entity shown for a global provider is the expected contracting entity for a Finland-based account; the entity stated in Company's applicable provider agreement controls if different.

Current core subprocessors

SubprocessorService and purposePersonal data concernedPrimary processing locationSafeguards and notes
HD-decor Oy (Tietokettu), FinlandVPS and data-center infrastructure for the backend, workers, private PostgreSQL database, and server logsCustomer Content, Company Database data, account data, audit and operational logsLempäälä, FinlandCurrent production topology uses a Finland-hosted VPS. PostgreSQL is private within the deployment network.
Google Ireland Limited / Google LLC, as applicableFirebase Hosting, Firebase Authentication, Google sign-in, and related security and delivery servicesStatic-site request data, IP/device data, account email, authentication identifiers and tokensEEA and other locations used under Google's termsGoogle provides Firebase data-processing terms and transfer safeguards. Firebase service location varies by product; this list does not claim that all authentication processing remains in the EEA.
OpenAI Ireland Ltd.API model inference, structured generation, embeddings, and enabled web-search processingPublic-page excerpts; prompts; selected Customer Content such as chat, interview, internal-source, and manual text; generated responses; request metadataEEA, United States, and other locations used by OpenAI and its subprocessorsAPI data is not used to train OpenAI models by default. Under default API controls, abuse-monitoring logs and some Responses API state may be retained for up to 30 days unless different approved controls apply or law requires longer. OpenAI's DPA and transfer mechanisms apply.
Google Ireland Limited / Google LLC, as applicableGoogle Workspace for business email, support communications, and limited operational documentsBusiness contact details, support and sales communications, and content deliberately included in operational documentsEEA and other locations used under Google's termsAccess is limited to authorized Company personnel. Customer Content should not be placed in general operational documents unless needed for support and appropriately protected.

Feature-dependent subprocessors

SubprocessorFeature and purposePersonal data concernedPrimary processing locationActivation condition and notes
Stripe Payments Europe, Limited and relevant Stripe affiliatesPayment, subscription, tax-ID collection, invoicing, and billing portalBilling contact, legal entity, address, tax ID, Stripe customer/subscription identifiers, payment method and transaction dataEEA, United States, and other locations used by Stripe and its subprocessorsUsed only when Stripe billing is enabled or Customer pays through Stripe. Stripe receives full card data directly; Company does not store full card numbers. Stripe may act as an independent controller for some regulated payment processing.
Google Ireland Limited / Google LLC, as applicableGoogle Analytics website measurementOnline identifiers, consented usage events, device/browser data, coarse location, and request metadataInitial regional collection and subsequent processing under Google Analytics termsUsed only if a measurement ID is configured and analytics consent has been given where required. Advertising features and Google-signals data sharing are not authorized by this list unless separately disclosed and enabled.

Providers not currently authorized for Customer Personal Data

Code or deployment documentation may support additional optional providers, such as Sentry or an alternative cloud host. A dormant integration is not a current Subprocessor. Company must complete review, update this list, and provide the DPA notice before enabling a new provider to process Customer Personal Data.

Public websites crawled at Customer's request are sources of public information, not subprocessors engaged to process Customer Personal Data on Company's behalf. Customer-enabled third-party integrations may also be separate services chosen by Customer rather than Company subprocessors; their role depends on the applicable integration and contract.

International transfers

Where a Subprocessor transfers personal data from the EEA to a country without an adequacy decision, Company requires an applicable transfer mechanism, such as the European Commission's Standard Contractual Clauses, and supplementary measures where required. Provider-specific frameworks and subprocessors can change; the provider's current DPA and subprocessor list form part of the transfer review.

Change notification and objections

Company will notify the Customer account-administrator email at least 15 days before a new Subprocessor begins processing Customer Personal Data, where practicable. Urgent security, legal, or service-continuity changes may be notified on a shorter timeline.

Customer may object during the notice period on reasonable, documented data-protection grounds. The resolution and termination process in Section 8 of the Data Processing Agreement applies.

© 2026 Lingonberry Island Ltd. · Buyervalues.ai
ContactTermsPrivacyGDPR FAQCookiesDPA