Joqiva Subprocessors

Third-party providers that Joqiva uses to process Customer Personal Data where Joqiva acts as processor.

Effective date: 24 Feb 2026 | Last updated: 16 August 2026

Introduction

This Subprocessors page identifies third-party providers that Joqiva uses to process Customer Personal Data on behalf of Joqiva customers where Joqiva acts as processor. This page forms part of the Joqiva Data Processing Agreement available. Providers listed as approved subprocessors are approved only for the processing functions described on this page. Other providers used for Joqiva's own controller-side business operations may be described in the Privacy Policy, Cookie Policy, Refund Policy, Partner Terms or other relevant notices.

1. Who we are

Joqiva is operated by FOP Mykola Marchuk Mykolaiovych, an individual entrepreneur registered in Ukraine, trading as Joqiva. Joqiva's current legal entity details, trading name, website, country of establishment, registered business address, correspondence address, registration information, UK VAT status, contact details, privacy contact and UK/EU representative information are maintained in the Legal Notice.

2. Scope of this page

This page applies to third-party providers that process Customer Personal Data for Joqiva where Joqiva acts as processor under the Joqiva DPA. Customer Personal Data means personal data contained in customer, enquiry, job, quote, invoice, file, email, payment report, reminder, audit log, document, workspace and related operational data that Joqiva processes on behalf of a Joqiva customer. This page does not list every provider used only for Joqiva's own internal business administration where that provider does not process Customer Personal Data as a subprocessor. This page also does not list providers that act only as independent controllers for their own services, unless Joqiva includes them for transparency. Where a provider processes Customer Personal Data as a subprocessor, Joqiva lists the provider on this page with its processing function, data categories, relevant location categories and transfer information.

3. Controller and processor model

For Customer Personal Data: (a) the Joqiva customer is normally the controller; (b) Joqiva is normally the processor; and (c) the providers listed in the "Approved subprocessors" section may act as subprocessors. For account registration, subscription billing, support, security, website operation, service administration, legal compliance, internal product analytics, service analytics and Joqiva's own business operations, Joqiva may act as an independent controller. Those controller processing activities are explained in the Joqiva Privacy Policy.

4. Important payment clarification

Joqiva does not process, collect, hold, transfer, settle, control or transmit money owed by End Customers to Joqiva customers. End Customers pay directly into the Joqiva customer's bank account by bank transfer. Joqiva does not initiate bank transfers, access payment accounts, or instruct banks or payment institutions to move End Customer funds. Joqiva may display bank transfer instructions, allow End Customers to indicate that they have paid, record payment reports, record owner confirmation, show overdue invoice status and send reminders. Joqiva does not use a payment processor for End Customer invoice payments. Any subscription billing provider used by Joqiva is only for Joqiva subscription fees payable by Joqiva customers to Joqiva. Subscription billing must not be mixed with End Customer invoice payment tracking.

5. Joqiva access locations

Joqiva provides a business workflow SaaS service. Customer Personal Data may be accessed by authorised Joqiva personnel or contractors from Joqiva operating locations, the United Kingdom and other locations described in the DPA for the purposes of providing, securing, supporting and maintaining the Service. Joqiva itself is not a subprocessor of its customers. This section is included for transparency because access to Customer Personal Data from outside the United Kingdom may be treated as an international transfer under applicable data protection law. Where required, international transfers involving Joqiva are addressed in the Joqiva DPA. Valid transfer mechanisms may include adequacy arrangements, UK transfer terms, standard contractual clauses, an applicable exception, or another lawful transfer mechanism available under applicable data protection law. Transfer risk assessments, data protection tests and supplementary measures may be used to support or assess a transfer mechanism where required, but they are not standalone transfer mechanisms.

6. Approved subprocessors

The subprocessors below are approved for the listed purposes where Joqiva has an applicable vendor agreement, data processing agreement or equivalent data protection terms in place. A provider is not approved to process Customer Personal Data as a subprocessor unless it is listed in this section or added under the DPA's urgent-change process. 6.1 Supabase Provider: Supabase, Inc., or the applicable Supabase contracting entity under Joqiva's vendor terms. Service: Core platform services for account access, workspace records, files, permissions and related Service operation. Purpose of processing: Supabase is used to support core Service operation, including account access, workspace records, files, access controls, audit-related records and related operational functionality. Types of Customer Personal Data processed: Supabase may process Customer Personal Data stored or generated in Joqiva workspaces, including: (a) workspace user and access information; (b) customer and End Customer names; (c) customer and End Customer contact details; (d) enquiry, job, quote and invoice data; (e) invoice items and quote items; (f) quote acceptance and decline records; (g) payment workflow records and payment reports; (h) bank transfer instructions provided by the Joqiva customer; (i) files, PDFs and attachments; (j) payment evidence or payment proof files; (k) inbound email records linked to workspace data; (l) audit logs; (m) access logs and technical metadata; (n) integration and operational event records where stored in the platform; and (o) other Customer Personal Data submitted to or generated in the Service. Location of processing: Primary service region: United Kingdom. Support, security and operational processing may occur in other provider locations, including locations outside the United Kingdom, as described in Supabase's applicable terms and subprocessor information. Transfer safeguards: Supabase data processing terms or equivalent contractual terms, together with applicable transfer mechanisms such as adequacy arrangements, UK transfer terms, standard contractual clauses or another lawful transfer mechanism where required. Status: Approved core platform provider. 6.2 Twilio SendGrid Provider: Twilio Inc. (Twilio SendGrid services). Service: Service email delivery, inbound email processing, email event processing and related communications services. Purpose of processing: Twilio SendGrid is used to send service emails, workspace invitation emails, quote emails, invoice emails, reminders and account-related emails, and to process delivery events, bounces and related email metadata. Where Joqiva enables inbound email processing, Twilio SendGrid may also process inbound email content and attachments. Email delivery is handled through Twilio SendGrid. SMS delivery is handled through Twilio where SMS delivery is enabled. Types of Customer Personal Data processed: Twilio SendGrid may process Customer Personal Data contained in or related to emails, including: (a) sender and recipient names; (b) sender and recipient email addresses; (c) email subject lines; (d) email body content; (e) inbound email content; (f) email attachments; (g) quote or invoice links; (h) customer-facing page links; (i) reminder content; (j) delivery events; (k) bounce events; (l) open and click events where configured and lawful; (m) IP addresses; (n) timestamps; (o) message identifiers; and (p) related technical metadata. Open and click tracking: Open and click tracking is disabled in Joqiva's current configuration, and Joqiva's deployed-environment configuration rejects these tracking flags. If Joqiva later changes the Service to enable open tracking, click tracking or similar email tracking, Joqiva will first update the relevant technical controls and assess and implement applicable privacy, PECR, consent and disclosure requirements. Location of processing: Provider locations used for communications, support, security or operational services, including locations outside the United Kingdom. Transfer safeguards: Twilio data processing terms or equivalent contractual terms, together with applicable transfer mechanisms such as adequacy arrangements, UK transfer terms, standard contractual clauses, approved certification or another lawful transfer mechanism where required. Status: Active email communications provider. 6.3 Twilio Provider: Twilio Inc. Service: SMS communications provider. Purpose of processing: Twilio is used to send customer-facing quote links and related service messages by SMS and to process related SMS delivery status information. Twilio is used for SMS communications only. Twilio is not used for Joqiva SaaS subscription billing or End Customer invoice payments. Types of Customer Personal Data processed: Twilio may process Customer Personal Data needed to deliver and track SMS messages, including: (a) recipient phone number; (b) SMS message content required to deliver the customer-facing quote link or related service message; (c) SMS delivery status metadata; (d) timestamps; (e) message identifiers; and (f) related technical metadata. SMS delivery: SMS delivery is an attempted communication and may generate delivery status information. Joqiva does not promise that every SMS will be delivered. Location of processing: Provider locations used for communications, support, security or operational services, including locations outside the United Kingdom. Transfer safeguards: Twilio data processing terms or equivalent contractual terms, together with applicable transfer mechanisms such as adequacy arrangements, UK transfer terms, standard contractual clauses, approved certification or another lawful transfer mechanism where required. Status: Active SMS communications provider for customer-facing quote links and related service messages. 6.4 OpenAI Provider: OpenAI OpCo, LLC. Service: AI-assisted processing provider. Purpose of processing: OpenAI may be used to provide AI-assisted enquiry extraction and AI-assisted extraction of customer and contact details from text manually submitted by a Joqiva user. AI-assisted features may help extract, classify, summarise or prepare fields from submitted email or message text and manually pasted enquiry, customer or contact text. AI-assisted output requires user review. It does not create final jobs, final quotes, final invoices, final customer communications or final business decisions automatically. Types of Customer Personal Data processed: OpenAI may process Customer Personal Data submitted for AI-assisted processing, including: (a) submitted email or message body text; (b) manually pasted enquiry, customer or contact text; (c) customer display names and legal names; (d) business names, company numbers and VAT numbers; (e) contact names and role titles; (f) email addresses and phone numbers; (g) billing, service, registered or other submitted address details; (h) enquiry details, service requirements and job descriptions; (i) notes submitted by Joqiva users; (j) limited attachment metadata, such as content type, size and scan or validation status, where an inbound email contains attachments; (k) extracted fields and AI-assisted output; (l) timestamps; and (m) related technical metadata. The current AI-assisted extraction implementation does not send attachment file contents to OpenAI. Training and model improvement: Joqiva does not authorise OpenAI to use Customer Personal Data submitted through Joqiva to train or improve general models unless Joqiva expressly states otherwise and has a lawful basis and required authorisation. Retention: OpenAI retention depends on the applicable OpenAI terms, account configuration, feature and retention controls. Joqiva will configure AI-assisted processing to minimise unnecessary retention and avoid storing AI provider responses as Joqiva business records where not needed. Location of processing: Provider locations used for AI-assisted processing, support, security or operational services, including locations outside the United Kingdom, unless a specific data residency arrangement applies. Transfer safeguards: OpenAI data processing terms, standard contractual clauses, UK transfer terms or another lawful transfer mechanism where required. Status: Approved AI service provider for AI-assisted enquiry and customer-detail extraction where the feature is enabled. 6.5 Vercel Provider: Vercel Inc., or the applicable Vercel contracting entity under Joqiva's vendor terms. Service: Web application delivery and related platform services. Purpose of processing: Vercel may be used to deliver Joqiva web application and customer-facing pages and to support related request handling, operational logging and service diagnostics. Types of Customer Personal Data processed: Vercel may process limited Customer Personal Data and service metadata where it appears in service requests, logs or diagnostics, including: (a) IP addresses; (b) browser and device information; (c) page and request metadata; (d) customer-facing page access metadata; (e) account or workspace identifiers where included in application requests; (f) error and diagnostic metadata; and (g) other Customer Personal Data necessarily transmitted while providing the service. Location of processing: Provider locations used for service delivery, support, security and operational services, including locations outside the United Kingdom. Transfer safeguards: Vercel data processing terms or equivalent contractual terms, together with applicable transfer mechanisms such as adequacy arrangements, UK transfer terms, standard contractual clauses or another lawful transfer mechanism where required. Status: Approved web application delivery provider. 6.6 DigitalOcean Provider: DigitalOcean, LLC, or the applicable DigitalOcean contracting entity under Joqiva's vendor terms. Service: Application operation and related platform services. Purpose of processing: DigitalOcean may be used to provide and operate Joqiva application services and related operational functions required to provide, secure and maintain the Service. Types of Customer Personal Data processed: DigitalOcean may process Customer Personal Data transmitted through or stored temporarily by hosted Joqiva services, including: (a) account and workspace request metadata; (b) customer and End Customer names and contact details where processed through application services; (c) enquiry, job, quote and invoice data where processed through application services; (d) files, PDFs, email content, attachments and payment proof data where processed through application services; (e) logs, events and operational metadata; and (f) other Customer Personal Data necessary for Service operation. Location of processing: Provider locations used for service delivery, support, security and operational services, including locations outside the United Kingdom. Transfer safeguards: DigitalOcean data processing terms or equivalent contractual terms, together with applicable transfer mechanisms such as adequacy arrangements, UK transfer terms, standard contractual clauses or another lawful transfer mechanism where required. Status: Approved application services provider. 6.7 Cloudflare Provider: Cloudflare, Inc., or the applicable Cloudflare contracting entity under Joqiva's vendor terms. Service: Traffic delivery, security and abuse-prevention services. Purpose of processing: Cloudflare may be used to deliver and protect Joqiva services through traffic management, security checks, abuse and bot prevention, and related availability and reliability functions. Types of Customer Personal Data processed: Cloudflare may process limited Customer Personal Data and request metadata, including: (a) IP addresses; (b) request and access metadata; (c) browser and device information; (d) security and abuse-prevention signals; (e) customer-facing page access metadata; and (f) other data necessarily transmitted while the provider protects and delivers the Service. Location of processing: Provider service delivery, security, support and operational locations, including locations outside the United Kingdom. Transfer safeguards: Cloudflare data processing terms or equivalent contractual terms, together with applicable transfer mechanisms such as adequacy arrangements, UK transfer terms, standard contractual clauses or another lawful transfer mechanism where required. Status: Approved traffic delivery and security provider. 6.8 Sentry Provider: Functional Software, Inc. dba Sentry, or the applicable Sentry contracting entity under Joqiva's vendor terms. Service: Service monitoring, reliability diagnostics and issue investigation. Purpose of processing: Sentry may be used to identify, diagnose, investigate and resolve application errors, reliability issues and security-relevant operational incidents. Types of Customer Personal Data processed: Sentry may process limited diagnostic data where it appears in error events or performance traces, including: (a) IP addresses where collected; (b) browser, device and runtime information; (c) service request metadata; (d) user, account or workspace identifiers where configured; (e) error messages and diagnostic context; and (f) limited Customer Personal Data accidentally included in error context despite Joqiva's minimisation controls. Location of processing: Provider locations used for monitoring, support, security and operational services, including locations outside the United Kingdom. Transfer safeguards: Sentry data processing terms or equivalent contractual terms, together with applicable transfer mechanisms such as adequacy arrangements, UK transfer terms, standard contractual clauses or another lawful transfer mechanism where required. Status: Approved service monitoring and diagnostics provider. 6.9 Ideal Postcodes Provider: IDDQD Limited, trading as Ideal Postcodes. Service: Address lookup and postcode search services. Purpose of processing: Ideal Postcodes is used to provide address lookup, postcode search, address selection and related address-normalisation functionality. Types of Customer Personal Data processed: Ideal Postcodes may process address lookup data, including: (a) postcode or address search text; (b) address fragments entered by Joqiva users; (c) a provider address identifier used to resolve a selected result; (d) address results returned by the provider; (e) request origin, referring application information and request metadata; and (f) related provider and technical metadata. Location of processing: United Kingdom and any other support, security, infrastructure or operational locations identified in IDDQD Limited's applicable terms and subprocessor information. Transfer safeguards: IDDQD Limited's applicable data processing terms. If the service involves a restricted transfer outside the United Kingdom, Joqiva will rely only on a transfer mechanism incorporated into the applicable contractual terms or otherwise lawfully put in place for that transfer. Status: Active address lookup provider.

7. Article 27 representatives

Joqiva has appointed Euverify Ltd (UK) and Euverify Ltd (Ireland) as UK and EU GDPR Article 27 representatives. These representatives act as contact points for UK/EU GDPR matters and data protection requests where applicable. They are not Joqiva's data protection officer, controller, processor, subprocessor, UK branch, EU branch, registered office or establishment. Provider: Euverify Ltd (UK) Purpose: UK GDPR Article 27 representative and secure GDPR request portal. Location: United Kingdom Provider: Euverify Ltd (Ireland) Purpose: EU GDPR Article 27 representative for EEA individuals where EU GDPR applies and secure GDPR request portal. Location: Ireland Contact: gdpr@euverify.com Portal: https://gdpr.euverify.com/verify/280fd1c9-68eb-438f-a2cd-92302bb9129e

8. Other transparency providers that are not normally DPA subprocessors

8.1 Analytics provider Joqiva may use an analytics provider for Joqiva's own website, product analytics and service improvement purposes, as described in the Privacy Policy and Cookie Policy. Analytics processing is normally controller-side Joqiva processing unless Joqiva expressly states that the provider processes Customer Personal Data as a subprocessor. Joqiva does not intentionally send customer quote content, invoice content, payment proof content, bank details, payment instructions, AI source input or output, email bodies, customer names, customer email addresses, customer phone numbers, credentials, secrets or full URLs containing access information to analytics providers. 8.2 Subscription billing provider Joqiva may use a billing provider or merchant of record to process Joqiva subscription fees, invoices, payment attempts, payment status, tax information, refunds and billing support information. Subscription billing is separate from End Customer invoice payments. Billing providers are not used for customer invoice bank-transfer payment tracking. Billing-provider processing is normally Joqiva controller-side processing, as described in the Privacy Policy and Refund Policy, unless Joqiva expressly states that the provider processes Customer Personal Data as a subprocessor. 8.3 Joqiva Partner Programme Joqiva operates its own Partner Programme system to administer partner applications, attribution, conversion validation, fraud prevention and commission approval. Partner Programme processing is Joqiva controller-side processing, as described in the Privacy Policy and Partner Terms. Customer invoice payments are not commissionable and are not processed through Joqiva or subscription billing providers. Joqiva does not disclose Customer Personal Data contained in workspace business records to an external affiliate network for the operation of its current Partner Programme.

9. Future subprocessors and provider categories

Joqiva may add, replace or remove subprocessors in accordance with the DPA. Future subprocessors may include providers for core service operation, security, reliability, support, communications, file review or scanning, analytics, subscription billing, AI-assisted processing or other Service functions. A provider is not approved to process Customer Personal Data as a subprocessor unless it is listed as an approved subprocessor on this page or is added under the DPA's urgent-change process. Where Joqiva makes a material change to subprocessors that process Customer Personal Data, Joqiva will provide notice and an opportunity to object as described in the DPA.

10. Providers not used for End Customer invoice payments

Joqiva does not process, collect, hold, transfer, settle, control or transmit money owed by End Customers to Joqiva customers. End Customers pay directly into the Joqiva customer's bank account by bank transfer. Joqiva does not use a payment processor for End Customer invoice payments. Any subscription billing provider used by Joqiva is used only for Joqiva subscription fees and is separate from End Customer invoice payment tracking. Communications providers such as Twilio SendGrid and Twilio are not used to process End Customer invoice payments.

11. Subprocessor due diligence

Before engaging a subprocessor that may process Customer Personal Data, Joqiva assesses, as appropriate: (a) the purpose of processing; (b) the categories of Customer Personal Data involved; (c) the categories of data subjects involved; (d) the provider's role and instructions; (e) security measures; (f) confidentiality obligations; (g) access controls; (h) data location and transfer safeguards; (i) retention and deletion commitments; (j) breach notification process; (k) subcontracting and onward transfer terms; (l) availability of a data processing agreement or equivalent terms; and (m) whether the provider offers sufficient guarantees to support Joqiva's obligations under the DPA.

12. Subprocessor contractual obligations

Where Joqiva uses a subprocessor to process Customer Personal Data, Joqiva will put in place a written contract or equivalent legal terms requiring the subprocessor to protect Customer Personal Data. Those terms must require the subprocessor to: (a) process Customer Personal Data only for the documented purposes and services for which the subprocessor is engaged; (b) process Customer Personal Data only under appropriate instructions; (c) maintain appropriate confidentiality; (d) use appropriate technical and organisational measures; (e) assist with data protection obligations where applicable; (f) support deletion, return or retention controls as required by applicable law and the DPA; (g) notify Joqiva of relevant personal data breaches where required; and (h) impose substantially equivalent protections on any approved onward subprocessors where required by applicable data protection law. Joqiva remains responsible to the Joqiva customer for the performance of its subprocessors as set out in the DPA.

13. International transfers

Joqiva and its subprocessors may process or access Customer Personal Data from countries outside the United Kingdom. Where required by applicable data protection law, Joqiva will use an appropriate transfer mechanism, which may include: (a) adequacy arrangements; (b) UK transfer terms or addenda; (c) standard contractual clauses; (d) approved certification, rules or equivalent safeguards where applicable; (e) an applicable exception where lawful and proportionate; (f) another lawful transfer mechanism permitted by applicable data protection law. Where Joqiva or the relevant party relies on appropriate safeguards rather than adequacy regulations or an exception, Joqiva will carry out or rely on an appropriate transfer risk assessment, data protection test or equivalent assessment where required. Supplementary technical, contractual or organisational measures may be applied where needed to support the relevant transfer mechanism. Joqiva will assess international transfers in light of the nature of the data, the provider, the destination country, the processing activity and the safeguards available.

14. Changes to subprocessors

Joqiva may add or replace subprocessors from time to time. Where Joqiva makes a material change to subprocessors that process Customer Personal Data under the DPA, Joqiva will provide notice before the change takes effect where reasonably possible. Notice may be provided by: (a) updating this page; (b) emailing the workspace owner or account contact; (c) providing an in-app notice; (d) posting a notice on the Joqiva website; or (e) sending notice to customers who have requested subprocessor change notices. To request subprocessor change notices, use the privacy or legal contact details in the Legal Notice with the subject line "Subprocessor notices".

15. Right to object

If you are a Joqiva customer and you object to a new or replacement subprocessor on reasonable data protection grounds, you must notify Joqiva in writing before the effective date stated in the notice. If no effective date is stated, you must notify Joqiva within 30 days after the notice. Your objection must explain the specific data protection grounds for the objection. Joqiva will review the objection in good faith and may, where reasonable and technically possible: (a) provide further information about the subprocessor; (b) provide information about safeguards; (c) suggest a workaround; (d) disable the affected feature; (e) delay the change for the objecting customer where feasible; (f) allow cancellation of the affected paid Service; or (g) take another reasonable step. If Joqiva cannot reasonably resolve the objection and the subprocessor is necessary to provide the Service, Joqiva may permit you to cancel the affected Service in accordance with the Terms of Service and DPA. Continued use of the affected Service after the effective date of a subprocessor change may be treated as authorisation of the subprocessor, unless you have made a valid unresolved objection before that date.

16. Emergency changes

Joqiva may add or replace a subprocessor without the usual advance notice where necessary to address an urgent security, legal, operational, availability or service continuity issue. In that case, Joqiva will provide notice as soon as reasonably practicable.

17. Vendor subprocessor chains

Joqiva's subprocessors may use their own subprocessors. Where a Joqiva subprocessor uses its own subprocessors, Joqiva relies on the contractual commitments, data processing terms, security measures and subprocessor controls provided by that vendor. Joqiva does not reproduce every vendor subprocessor chain on this page, but may refer to the vendor's own subprocessor list, data processing terms, trust centre or security documentation where appropriate. Joqiva remains responsible to the Joqiva customer for subprocessors as described in the DPA and applicable data protection law.

18. Data minimisation

Joqiva configures subprocessors so that they process only the Customer Personal Data reasonably necessary for the relevant service. Joqiva also seeks to avoid sending unnecessary Customer Personal Data to monitoring, support, AI, logging, communications or infrastructure providers that act as subprocessors. Joqiva does not intentionally send customer quote content, invoice content, payment proof content, bank details, payment instructions, AI source input or output, email bodies, customer names, customer email addresses, customer phone numbers, credentials, secrets or full URLs containing access information to providers unless necessary for the relevant Service function, lawful, documented and covered by the DPA or another applicable legal basis. Where email or SMS delivery is used, the communications provider may receive message content containing a customer-facing link because that is necessary to deliver the message to the intended recipient. Customers should not submit unnecessary sensitive personal data, special category personal data, criminal offence data, children's data, full payment card details, passwords or irrelevant personal data into Joqiva.

19. Questions

For questions about subprocessors, international transfers or this page, use the contact details maintained in the Legal Notice. The current privacy contact and legal contact are listed in the Legal Notice.