Subprocessor List
This page is provided for convenience and may be updated over time.
Subprocessor List
Last updated: Aug 10, 2026
This list identifies service providers authorized to process personal data for Lingonberry Island Ltd. in connection with Buyervalues.ai. A provider marked feature-dependent processes data only when the related feature is configured and used.
The legal entity shown for a global provider is the expected contracting entity for a Finland-based account; the entity stated in Company's applicable provider agreement controls if different.
Current core subprocessors
| Subprocessor | Service and purpose | Personal data concerned | Primary processing location | Safeguards and notes |
|---|---|---|---|---|
| HD-decor Oy (Tietokettu), Finland | VPS and data-center infrastructure for the backend, workers, private PostgreSQL database, and server logs | Customer Content, Company Database data, account data, audit and operational logs | Lempäälä, Finland | Current production topology uses a Finland-hosted VPS. PostgreSQL is private within the deployment network. |
| Google Ireland Limited / Google LLC, as applicable | Firebase Hosting, Firebase Authentication, Google sign-in, and related security and delivery services | Static-site request data, IP/device data, account email, authentication identifiers and tokens | EEA and other locations used under Google's terms | Google provides Firebase data-processing terms and transfer safeguards. Firebase service location varies by product; this list does not claim that all authentication processing remains in the EEA. |
| OpenAI Ireland Ltd. | API model inference, structured generation, embeddings, and enabled web-search processing | Public-page excerpts; prompts; selected Customer Content such as chat, interview, internal-source, and manual text; generated responses; request metadata | EEA, United States, and other locations used by OpenAI and its subprocessors | API data is not used to train OpenAI models by default. Under default API controls, abuse-monitoring logs and some Responses API state may be retained for up to 30 days unless different approved controls apply or law requires longer. OpenAI's DPA and transfer mechanisms apply. |
| Google Ireland Limited / Google LLC, as applicable | Google Workspace for business email, support communications, and limited operational documents | Business contact details, support and sales communications, and content deliberately included in operational documents | EEA and other locations used under Google's terms | Access is limited to authorized Company personnel. Customer Content should not be placed in general operational documents unless needed for support and appropriately protected. |
Feature-dependent subprocessors
| Subprocessor | Feature and purpose | Personal data concerned | Primary processing location | Activation condition and notes |
|---|---|---|---|---|
| Stripe Payments Europe, Limited and relevant Stripe affiliates | Payment, subscription, tax-ID collection, invoicing, and billing portal | Billing contact, legal entity, address, tax ID, Stripe customer/subscription identifiers, payment method and transaction data | EEA, United States, and other locations used by Stripe and its subprocessors | Used only when Stripe billing is enabled or Customer pays through Stripe. Stripe receives full card data directly; Company does not store full card numbers. Stripe may act as an independent controller for some regulated payment processing. |
| Google Ireland Limited / Google LLC, as applicable | Google Analytics website measurement | Online identifiers, consented usage events, device/browser data, coarse location, and request metadata | Initial regional collection and subsequent processing under Google Analytics terms | Used only if a measurement ID is configured and analytics consent has been given where required. Advertising features and Google-signals data sharing are not authorized by this list unless separately disclosed and enabled. |
Providers not currently authorized for Customer Personal Data
Code or deployment documentation may support additional optional providers, such as Sentry or an alternative cloud host. A dormant integration is not a current Subprocessor. Company must complete review, update this list, and provide the DPA notice before enabling a new provider to process Customer Personal Data.
Public websites crawled at Customer's request are sources of public information, not subprocessors engaged to process Customer Personal Data on Company's behalf. Customer-enabled third-party integrations may also be separate services chosen by Customer rather than Company subprocessors; their role depends on the applicable integration and contract.
International transfers
Where a Subprocessor transfers personal data from the EEA to a country without an adequacy decision, Company requires an applicable transfer mechanism, such as the European Commission's Standard Contractual Clauses, and supplementary measures where required. Provider-specific frameworks and subprocessors can change; the provider's current DPA and subprocessor list form part of the transfer review.
Change notification and objections
Company will notify the Customer account-administrator email at least 15 days before a new Subprocessor begins processing Customer Personal Data, where practicable. Urgent security, legal, or service-continuity changes may be notified on a shorter timeline.
Customer may object during the notice period on reasonable, documented data-protection grounds. The resolution and termination process in Section 8 of the Data Processing Agreement applies.