Subprocessors

Last updated: 21 August 2026

Deuce Creative Limited (trading as Grofomo) uses the providers below to run the platform. This page is the current, canonical list. It is referenced by our Data Processing Addendum as the record of subprocessors we have engaged, and by our Privacy Policy.

Where we process personal data on behalf of an event organiser, these providers are our subprocessors. Where we act as a controller in our own right, they are our processors. The distinction is set out in the Privacy Policy; either way, the list is the same and it is complete.

The three groups below are not interchangeable. Read the note under each heading before treating an entry as something we chose on your behalf.

Platform subprocessors

Engaged by us, and used for every customer. We give notice before adding to this list, and you may object. These are the entries our Data Processing Addendum commits us on.

  • Supabase

    Supabase, Inc.

    Primary database, authentication, and file storage. Every record the platform holds lives here.

    Data it can access
    • Name, email address, phone number
    • Order and ticket records
    • Marketing consent records
    • Uploaded images, video, and documents
    • IP address, device and browser information
    Whose data
    Attendees and ticket buyers, Organiser users, Artists, Volunteers, Suppliers
    Where
    United Kingdom (AWS eu-west-2, London)
    Transfer safeguard
    Not required: processing stays in the UK.
    Their terms
    supabase.com

    Data at rest stays in the United Kingdom.

  • Vercel

    Vercel, Inc.

    Application hosting. Serves every page, runs every API route, and runs the scheduled jobs.

    Data it can access
    • Any personal data contained in a request or response
    • IP address, device and browser information
    • Request logs
    Whose data
    All categories
    Where
    Pages are served from the London edge. Server functions currently execute in the United States (Washington DC).
    Transfer safeguard
    EU-US Data Privacy Framework (UK Extension), and Standard Contractual Clauses with the UK Addendum
    Their terms
    vercel.com

    Function execution is transient. Data is held in memory only for as long as it takes to serve one request, and is written back to the United Kingdom database.

  • Stripe

    Stripe Payments Europe, Ltd. and Stripe, Inc.

    Card payments, payment plans, payouts to organisers and artists, and card readers at the door.

    Data it can access
    • Name, email address
    • Billing address and payment card details
    • Transaction amounts and history
    • Bank and payout details for organisers and artists
    • IP address, device and browser information
    Whose data
    Ticket buyers, Organiser users, Artists, Affiliates
    Where
    Ireland and the United States
    Transfer safeguard
    Standard Contractual Clauses with the UK Addendum
    Their terms
    stripe.com

    Card numbers are captured by Stripe directly in the buyer browser and never reach our servers.

  • Resend

    Resend, Inc.

    Sends every email the platform sends: ticket confirmations, receipts, sign-in links, and marketing broadcasts. Also receives replies to platform addresses.

    Data it can access
    • Name, email address
    • Email content and attachments
    • Delivery, bounce, open, and click events
    Whose data
    Attendees and ticket buyers, Organiser users, Artists, Mailing list subscribers
    Where
    United States
    Transfer safeguard
    Standard Contractual Clauses with the UK Addendum
    Their terms
    resend.com

    Where an organiser connects a Resend audience, a contact list of name and email is held at Resend on an ongoing basis rather than only in transit.

  • Expo

    650 Industries, Inc.

    Delivers push notifications to the Grofomo mobile app, and builds and distributes app releases.

    Data it can access
    • Push notification tokens
    • Notification title and body
    • App and device version
    Whose data
    Mobile app users
    Where
    United States
    Transfer safeguard
    Standard Contractual Clauses with the UK Addendum
    Their terms
    expo.dev

    Expo issues a token scoped to our project. The underlying Apple or Google device token is never exposed to us.

  • Cloudflare

    Cloudflare, Inc.

    Turnstile bot protection on public forms, and content delivery in front of our database provider.

    Data it can access
    • IP address, device and browser information
    • Bot-detection signals
    Whose data
    Anyone submitting a public form
    Where
    Global edge network, processed at the location nearest the visitor
    Transfer safeguard
    Standard Contractual Clauses with the UK Addendum
    Their terms
    cloudflare.com

    IP address is passed to Turnstile deliberately, as an additional signal for telling people apart from bots.

  • Amazon Web Services

    Amazon Web Services EMEA SARL

    Renders promotional video and artwork on demand, and stores the rendered output.

    Data it can access
    • Artist names and likeness contained in supplied artwork
    • Event names and campaign copy
    Whose data
    Artists, Organiser users
    Where
    United Kingdom (eu-west-2, London)
    Transfer safeguard
    Not required: processing stays in the UK.
    Their terms
    aws.amazon.com
  • Twilio

    Twilio Inc.

    Supplies a phone number to organisers who do not have a spare one, so they can receive the verification code needed to connect WhatsApp.

    Data it can access
    • The phone number we supply to the organiser
    • Verification codes sent by Meta to that number
    • The forwarding number for voice calls
    Whose data
    Organiser users
    Where
    United States (US1 region)
    Transfer safeguard
    EU-US Data Privacy Framework, and Standard Contractual Clauses with the UK Addendum
    Their terms
    twilio.com

    No attendee data reaches Twilio. Conversations with attendees run over WhatsApp through Meta, not over these numbers. If that ever changes, this entry and the DPA annex must be revised before it does.

  • Google Cloud and Google APIs

    Google Ireland Limited

    Sign in with Google, Google Wallet passes, Google Maps in the site-map editor, and web fonts on branded pages.

    Data it can access
    • Name, email address
    • Google account identifier
    • Wallet pass contents
    • IP address, device and browser information
    Whose data
    Organiser users, Ticket buyers who save a pass, Visitors to branded pages
    Where
    European Union and the United States
    Transfer safeguard
    Standard Contractual Clauses with the UK Addendum
    Their terms
    cloud.google.com

    A Google Wallet pass contains the event name, venue, ticket type, and the ticket reference used as its barcode. It does not contain the holder name or email address.

  • Apple

    Apple Distribution International Ltd.

    Sign in with Apple, Apple Wallet passes, and push notification delivery to iOS devices.

    Data it can access
    • Name, email address
    • Apple account identifier
    • Device push tokens
    Whose data
    Organiser users, Mobile app users, Ticket buyers who save a pass
    Where
    Ireland and the United States
    Transfer safeguard
    Standard Contractual Clauses with the UK Addendum
    Their terms
    apple.com

    Apple Wallet passes are built on our own servers and handed to the device. Apple receives the push token used to signal that a pass changed, not the pass contents.

  • OpenRouter

    OpenRouter, Inc.

    Routes requests to large language models, used for drafting artist biographies, event copy, and campaign suggestions.

    Data it can access
    • Artist name, real name, location, and biography text
    • Organiser-authored event and campaign copy
    Whose data
    Artists, Organiser users
    Where
    United States
    Transfer safeguard
    Standard Contractual Clauses with the UK Addendum
    Their terms
    openrouter.ai

    No attendee or ticket-buyer data is sent to any model.

  • Slack

    Salesforce, Inc.

    Receives internal operational alerts from the platform.

    Data it can access
    • Alert text, which can incidentally contain a record identifier
    Whose data
    Not directed at any category; incidental only
    Where
    United States
    Transfer safeguard
    Standard Contractual Clauses with the UK Addendum
    Their terms
    salesforce.com

Subprocessors engaged by our subprocessors

Engaged by one of the providers above rather than by us. Listed so the whole chain is visible. Changes flow through that provider under its own agreement.

  • Google, reached through OpenRouter

    Google LLC

    Provides the model used for structured extraction of artist and event details.

    Data it can access
    • Whatever the prompt contains: artist and event copy
    Whose data
    Artists, Organiser users
    Where
    United States
    Transfer safeguard
    Relied on through the OpenRouter agreement
    Their terms
    cloud.google.com
  • Perplexity, reached through OpenRouter

    Perplexity AI, Inc.

    Provides the model used to research artists against public web sources.

    Data it can access
    • Artist name and the search context supplied with it
    Whose data
    Artists
    Where
    United States
    Transfer safeguard
    Relied on through the OpenRouter agreement
    Their terms
    perplexity.ai
  • Apple Push Notification service and Firebase Cloud Messaging, reached through Expo

    Apple Distribution International Ltd. and Google Ireland Limited

    The operating system push networks that carry a notification the last step to a phone.

    Data it can access
    • Device push tokens
    • Notification payload
    Whose data
    Mobile app users
    Where
    United States
    Transfer safeguard
    Relied on through the Expo agreement

Services you switch on yourself

Reached only because you connected an account, entered a key, or nominated a destination. You control whether these are used at all and you hold the relationship with them, so they sit outside our notice commitment.

  • Meta WhatsApp Business Platform

    Meta Platforms Ireland Limited

    Delivers WhatsApp messages between an organiser and their audience, using that organiser own WhatsApp Business account.

    Data it can access
    • Recipient phone numbers
    • Message content, inbound and outbound
    Whose data
    Attendees who message, or are messaged by, an organiser
    Where
    Ireland and the United States
    Transfer safeguard
    Standard Contractual Clauses with the UK Addendum, held by the organiser with Meta
    Their terms
    whatsapp.com

    The organiser owns the WhatsApp Business account and contracts with Meta directly. We act as their technology provider.

  • Meta Pixel

    Meta Platforms Ireland Limited

    Measures ticket sales for an organiser own advertising, where that organiser has added their pixel to an event.

    Data it can access
    • IP address, device and browser information
    • Pages viewed and purchase value
    • Meta advertising cookies
    Whose data
    Visitors to that organiser ticket storefront
    Where
    Ireland and the United States
    Transfer safeguard
    Standard Contractual Clauses with the UK Addendum, held by the organiser with Meta
    Their terms
    facebook.com

    Off unless the organiser supplies a pixel identifier, and it loads only for a visitor who has accepted analytics cookies.

  • Social publishing platforms

    Meta Platforms Ireland Limited, TikTok Information Technologies UK Limited, X Corp., Google Ireland Limited, and Mixcloud Ltd.

    Publishes posts, video, and audio to accounts an organiser has connected: Facebook, Instagram, Threads, TikTok, X, YouTube, and Mixcloud.

    Data it can access
    • Post content and media
    • The connected account identity and its access token
    Whose data
    Organiser users, Anyone appearing in the media they publish
    Where
    Ireland, the United States, and elsewhere depending on the platform
    Transfer safeguard
    Held by the organiser with each platform under its own terms
    Their terms
    facebook.com

    Reaches a platform only where the organiser has explicitly connected their own account.

  • Webhook endpoints you nominate

    Whichever party you nominate

    Sends event notifications to a URL an organiser or artist enters, for example their own Slack workspace or internal system.

    Data it can access
    • Whatever the notification carries, which can include buyer name and order details
    Whose data
    Attendees and ticket buyers
    Where
    Wherever the nominated endpoint is hosted
    Transfer safeguard
    Your responsibility, as the party choosing the destination

    We deliver to the address given. We have no relationship with the recipient and are not in a position to assess it.

Changes to this list

Before we add a platform subprocessor, we will give at least 30 days notice to organisers who have accepted the Data Processing Addendum, by email to the billing address on the account. If you have a reasonable data protection objection, tell us within that period and we will work with you on it. If we cannot resolve it, you may stop using the affected feature or terminate the affected services without penalty.

We may add a subprocessor immediately where it is needed to keep the service running or secure, for example replacing a provider that has failed. We will tell you as soon as we reasonably can afterwards, and the objection right is unchanged.

We do not give notice for services you switch on yourself, because adding one is your decision rather than ours.

Questions

Email privacy@grofomo.com. If you need a countersigned copy of the Data Processing Addendum, or a completed security questionnaire, ask at the same address.