The subprocessors below are approved for the listed purposes where Joqiva has an applicable vendor agreement, data processing agreement or equivalent data protection terms in place.
A provider is not approved to process Customer Personal Data as a subprocessor unless it is listed in this section or added under the DPA's urgent-change process.
6.1 Supabase
Provider:
Supabase, Inc., or the applicable Supabase contracting entity under Joqiva's vendor terms.
Service:
Core platform services for account access, workspace records, files, permissions and related Service operation.
Purpose of processing:
Supabase is used to support core Service operation, including account access, workspace records, files, access controls, audit-related records and related operational functionality.
Types of Customer Personal Data processed:
Supabase may process Customer Personal Data stored or generated in Joqiva workspaces, including:
(a) workspace user and access information;
(b) customer and End Customer names;
(c) customer and End Customer contact details;
(d) enquiry, job, quote and invoice data;
(e) invoice items and quote items;
(f) quote acceptance and decline records;
(g) payment workflow records and payment reports;
(h) bank transfer instructions provided by the Joqiva customer;
(i) files, PDFs and attachments;
(j) payment evidence or payment proof files;
(k) inbound email records linked to workspace data;
(l) audit logs;
(m) access logs and technical metadata;
(n) integration and operational event records where stored in the platform; and
(o) other Customer Personal Data submitted to or generated in the Service.
Location of processing:
Primary service region: United Kingdom.
Support, security and operational processing may occur in other provider locations, including locations outside the United Kingdom, as described in Supabase's applicable terms and subprocessor information.
Transfer safeguards:
Supabase data processing terms or equivalent contractual terms, together with applicable transfer mechanisms such as adequacy arrangements, UK transfer terms, standard contractual clauses or another lawful transfer mechanism where required.
Status:
Approved core platform provider.
6.2 Twilio SendGrid
Provider:
Twilio Inc. (Twilio SendGrid services).
Service:
Service email delivery, inbound email processing, email event processing and related communications services.
Purpose of processing:
Twilio SendGrid is used to send service emails, workspace invitation emails, quote emails, invoice emails, reminders and account-related emails, and to process delivery events, bounces and related email metadata. Where Joqiva enables inbound email processing, Twilio SendGrid may also process inbound email content and attachments.
Email delivery is handled through Twilio SendGrid. SMS delivery is handled through Twilio where SMS delivery is enabled.
Types of Customer Personal Data processed:
Twilio SendGrid may process Customer Personal Data contained in or related to emails, including:
(a) sender and recipient names;
(b) sender and recipient email addresses;
(c) email subject lines;
(d) email body content;
(e) inbound email content;
(f) email attachments;
(g) quote or invoice links;
(h) customer-facing page links;
(i) reminder content;
(j) delivery events;
(k) bounce events;
(l) open and click events where configured and lawful;
(m) IP addresses;
(n) timestamps;
(o) message identifiers; and
(p) related technical metadata.
Open and click tracking:
Open and click tracking is disabled in Joqiva's current configuration, and Joqiva's deployed-environment configuration rejects these tracking flags. If Joqiva later changes the Service to enable open tracking, click tracking or similar email tracking, Joqiva will first update the relevant technical controls and assess and implement applicable privacy, PECR, consent and disclosure requirements.
Location of processing:
Provider locations used for communications, support, security or operational services, including locations outside the United Kingdom.
Transfer safeguards:
Twilio data processing terms or equivalent contractual terms, together with applicable transfer mechanisms such as adequacy arrangements, UK transfer terms, standard contractual clauses, approved certification or another lawful transfer mechanism where required.
Status:
Active email communications provider.
6.3 Twilio
Provider:
Twilio Inc.
Service:
SMS communications provider.
Purpose of processing:
Twilio is used to send customer-facing quote links and related service messages by SMS and to process related SMS delivery status information.
Twilio is used for SMS communications only. Twilio is not used for Joqiva SaaS subscription billing or End Customer invoice payments.
Types of Customer Personal Data processed:
Twilio may process Customer Personal Data needed to deliver and track SMS messages, including:
(a) recipient phone number;
(b) SMS message content required to deliver the customer-facing quote link or related service message;
(c) SMS delivery status metadata;
(d) timestamps;
(e) message identifiers; and
(f) related technical metadata.
SMS delivery:
SMS delivery is an attempted communication and may generate delivery status information. Joqiva does not promise that every SMS will be delivered.
Location of processing:
Provider locations used for communications, support, security or operational services, including locations outside the United Kingdom.
Transfer safeguards:
Twilio data processing terms or equivalent contractual terms, together with applicable transfer mechanisms such as adequacy arrangements, UK transfer terms, standard contractual clauses, approved certification or another lawful transfer mechanism where required.
Status:
Active SMS communications provider for customer-facing quote links and related service messages.
6.4 OpenAI
Provider:
OpenAI OpCo, LLC.
Service:
AI-assisted processing provider.
Purpose of processing:
OpenAI may be used to provide AI-assisted enquiry extraction and AI-assisted extraction of customer and contact details from text manually submitted by a Joqiva user.
AI-assisted features may help extract, classify, summarise or prepare fields from submitted email or message text and manually pasted enquiry, customer or contact text.
AI-assisted output requires user review. It does not create final jobs, final quotes, final invoices, final customer communications or final business decisions automatically.
Types of Customer Personal Data processed:
OpenAI may process Customer Personal Data submitted for AI-assisted processing, including:
(a) submitted email or message body text;
(b) manually pasted enquiry, customer or contact text;
(c) customer display names and legal names;
(d) business names, company numbers and VAT numbers;
(e) contact names and role titles;
(f) email addresses and phone numbers;
(g) billing, service, registered or other submitted address details;
(h) enquiry details, service requirements and job descriptions;
(i) notes submitted by Joqiva users;
(j) limited attachment metadata, such as content type, size and scan or validation status, where an inbound email contains attachments;
(k) extracted fields and AI-assisted output;
(l) timestamps; and
(m) related technical metadata.
The current AI-assisted extraction implementation does not send attachment file contents to OpenAI.
Training and model improvement:
Joqiva does not authorise OpenAI to use Customer Personal Data submitted through Joqiva to train or improve general models unless Joqiva expressly states otherwise and has a lawful basis and required authorisation.
Retention:
OpenAI retention depends on the applicable OpenAI terms, account configuration, feature and retention controls. Joqiva will configure AI-assisted processing to minimise unnecessary retention and avoid storing AI provider responses as Joqiva business records where not needed.
Location of processing:
Provider locations used for AI-assisted processing, support, security or operational services, including locations outside the United Kingdom, unless a specific data residency arrangement applies.
Transfer safeguards:
OpenAI data processing terms, standard contractual clauses, UK transfer terms or another lawful transfer mechanism where required.
Status:
Approved AI service provider for AI-assisted enquiry and customer-detail extraction where the feature is enabled.
6.5 Vercel
Provider:
Vercel Inc., or the applicable Vercel contracting entity under Joqiva's vendor terms.
Service:
Web application delivery and related platform services.
Purpose of processing:
Vercel may be used to deliver Joqiva web application and customer-facing pages and to support related request handling, operational logging and service diagnostics.
Types of Customer Personal Data processed:
Vercel may process limited Customer Personal Data and service metadata where it appears in service requests, logs or diagnostics, including:
(a) IP addresses;
(b) browser and device information;
(c) page and request metadata;
(d) customer-facing page access metadata;
(e) account or workspace identifiers where included in application requests;
(f) error and diagnostic metadata; and
(g) other Customer Personal Data necessarily transmitted while providing the service.
Location of processing:
Provider locations used for service delivery, support, security and operational services, including locations outside the United Kingdom.
Transfer safeguards:
Vercel data processing terms or equivalent contractual terms, together with applicable transfer mechanisms such as adequacy arrangements, UK transfer terms, standard contractual clauses or another lawful transfer mechanism where required.
Status:
Approved web application delivery provider.
6.6 DigitalOcean
Provider:
DigitalOcean, LLC, or the applicable DigitalOcean contracting entity under Joqiva's vendor terms.
Service:
Application operation and related platform services.
Purpose of processing:
DigitalOcean may be used to provide and operate Joqiva application services and related operational functions required to provide, secure and maintain the Service.
Types of Customer Personal Data processed:
DigitalOcean may process Customer Personal Data transmitted through or stored temporarily by hosted Joqiva services, including:
(a) account and workspace request metadata;
(b) customer and End Customer names and contact details where processed through application services;
(c) enquiry, job, quote and invoice data where processed through application services;
(d) files, PDFs, email content, attachments and payment proof data where processed through application services;
(e) logs, events and operational metadata; and
(f) other Customer Personal Data necessary for Service operation.
Location of processing:
Provider locations used for service delivery, support, security and operational services, including locations outside the United Kingdom.
Transfer safeguards:
DigitalOcean data processing terms or equivalent contractual terms, together with applicable transfer mechanisms such as adequacy arrangements, UK transfer terms, standard contractual clauses or another lawful transfer mechanism where required.
Status:
Approved application services provider.
6.7 Cloudflare
Provider:
Cloudflare, Inc., or the applicable Cloudflare contracting entity under Joqiva's vendor terms.
Service:
Traffic delivery, security and abuse-prevention services.
Purpose of processing:
Cloudflare may be used to deliver and protect Joqiva services through traffic management, security checks, abuse and bot prevention, and related availability and reliability functions.
Types of Customer Personal Data processed:
Cloudflare may process limited Customer Personal Data and request metadata, including:
(a) IP addresses;
(b) request and access metadata;
(c) browser and device information;
(d) security and abuse-prevention signals;
(e) customer-facing page access metadata; and
(f) other data necessarily transmitted while the provider protects and delivers the Service.
Location of processing:
Provider service delivery, security, support and operational locations, including locations outside the United Kingdom.
Transfer safeguards:
Cloudflare data processing terms or equivalent contractual terms, together with applicable transfer mechanisms such as adequacy arrangements, UK transfer terms, standard contractual clauses or another lawful transfer mechanism where required.
Status:
Approved traffic delivery and security provider.
6.8 Sentry
Provider:
Functional Software, Inc. dba Sentry, or the applicable Sentry contracting entity under Joqiva's vendor terms.
Service:
Service monitoring, reliability diagnostics and issue investigation.
Purpose of processing:
Sentry may be used to identify, diagnose, investigate and resolve application errors, reliability issues and security-relevant operational incidents.
Types of Customer Personal Data processed:
Sentry may process limited diagnostic data where it appears in error events or performance traces, including:
(a) IP addresses where collected;
(b) browser, device and runtime information;
(c) service request metadata;
(d) user, account or workspace identifiers where configured;
(e) error messages and diagnostic context; and
(f) limited Customer Personal Data accidentally included in error context despite Joqiva's minimisation controls.
Location of processing:
Provider locations used for monitoring, support, security and operational services, including locations outside the United Kingdom.
Transfer safeguards:
Sentry data processing terms or equivalent contractual terms, together with applicable transfer mechanisms such as adequacy arrangements, UK transfer terms, standard contractual clauses or another lawful transfer mechanism where required.
Status:
Approved service monitoring and diagnostics provider.
6.9 Ideal Postcodes
Provider:
IDDQD Limited, trading as Ideal Postcodes.
Service:
Address lookup and postcode search services.
Purpose of processing:
Ideal Postcodes is used to provide address lookup, postcode search, address selection and related address-normalisation functionality.
Types of Customer Personal Data processed:
Ideal Postcodes may process address lookup data, including:
(a) postcode or address search text;
(b) address fragments entered by Joqiva users;
(c) a provider address identifier used to resolve a selected result;
(d) address results returned by the provider;
(e) request origin, referring application information and request metadata; and
(f) related provider and technical metadata.
Location of processing:
United Kingdom and any other support, security, infrastructure or operational locations identified in IDDQD Limited's applicable terms and subprocessor information.
Transfer safeguards:
IDDQD Limited's applicable data processing terms. If the service involves a restricted transfer outside the United Kingdom, Joqiva will rely only on a transfer mechanism incorporated into the applicable contractual terms or otherwise lawfully put in place for that transfer.
Status:
Active address lookup provider.