Legal

DUBHCORE — Sub-processors List

Version 1.0 — Date: 30 August 2026 — Final version Listed are only the providers actually used (verified on code/config). Dependencies present in the project but not actively used are NOT included. DPA/agreements: where the provider's DPA is incorporated into the terms or perfected via valid electronic acceptance, no separate handwritten signature is required; the evidence is the online acceptance (the possession of "signed" copies is not declared). The duration of Emergent's infrastructure logs was not communicated or confirmed by the provider (managed by Emergent within its own infrastructure; no unverified numerical period is stated) and does not currently constitute a launch blocker.

ProviderService / PurposeData categoriesPlace of processingInternational transferMechanism/GuaranteeNotes
StripeA) DUBHCORE subscriptions/billing; B) Stripe Connect for Studios' deposits; webhook eventsPayment/billing data, transaction identifiersEU/USA (PARTIAL — not verified)YesStripe DPA/DPP + SCC perfected via online acceptance of the termsStripe may act as an autonomous Controller for certain processing (payments, compliance, anti-fraud, own obligations) according to the applicable Stripe documentation; not a mere sub-processor
GoogleOnly OAuth + Google Calendar (read-only import)Account identifiers (email/profile), imported calendar eventsEU/USA (PARTIAL — not verified)YesGoogle Data Processing Terms + SCC via online acceptanceOAuth tokens stored encrypted (Fernet). Excluded: analytics, advertising, Google Fonts, AI services and other unused Google services
EmergentBackend hosting/infrastructure (K8s), private managed Object Storage, sending of transactional emails (managed Resend/SES), HubAll hosted categories (account, requests, images, documents, etc.); recipients' email addressesUnited States (VERIFIED)Yes (USA)Emergent DPA + SCC EU 2021/914Deployment platform; infrastructure sub-provider chain below

Expo / EAS (technical note — NOT a runtime sub-processor): used exclusively as a build/distribution tool for the mobile app. According to the technical audit, it does not process the personal data of end users of DUBHCORE during normal use of the app; therefore it is not included in the public list of sub-processors and is not presented as a runtime sub-processor of client data.

Apple Calendar: access takes place on the user's device (expo-calendar); it does not constitute a server-side sub-processor of DUBHCORE (no Apple calendar data is sent to the servers).

Health data (Art. 9) at the sub-processors: the health data (Tattoo/Piercing) is hosted on the Emergent infrastructure (already listed) together with the other categories; access is limited server-side to authorised roles only (least privilege). Emergent's confirmation regarding the admissibility of processing such data for the application does not constitute the lawfulness condition under Art. 9, which remains explicit consent (Art. 9(2)(a)) identified by the Studio as Controller. No other sub-processor specifically receives the health data.

Analytics/advertising/tracking: absent both in the app and on the Hub website (dubhcore.com) — verified audit (no analytics sub-processor).

DUBHCORE Hub (dubhcore.com): the contact form /contact (name, studio, email, country, message) sends the data to the Hub backend, stored in the MongoDB collection contact_requests of the Hub project (hosted on Emergent infrastructure, already listed). No external email/newsletter provider receives such data. Payments take place via external Stripe Payment Links (buy.stripe.com), already covered by the Stripe entry.

Google Fonts and Unsplash: are no longer active external services — the Hub's fonts and "Origin" image are now hosted locally. Therefore they do not appear among the external providers/recipients.

Verified infrastructure (Emergent Labs Inc.): DUBHCORE uses the infrastructure managed by Emergent Labs Inc. Infrastructure sub-providers with a verified/reasonably documented role in the DUBHCORE data flow:

ProviderService / PurposeLocationInternational transferGuarantee
Emergent Labs Inc.Managed platform/infrastructure (deployment, orchestration)United StatesYes (USA)DPA + SCC (EU Dec. 2021/914)
MongoDB AtlasManaged database of the applicationUnited StatesYes (USA)via Emergent DPA + SCC
Amazon Web Services (AWS)Cloud hosting / object storage / email, where applicableUnited StatesYes (USA)via Emergent DPA + SCC
CloudflareEdge/CDN/application servingEdge/globally distributed (PARTIAL — region not verified)Yesvia Emergent DPA + SCC

Production backups: automatic rotating, stored in the United States (detail in the Data Retention Schedule). DPA roles: Customer = Controller, Emergent = Processor; if the Customer is in turn Processor, Emergent = Sub-processor.

Not all providers present in Emergent's general Sub-processors page are listed, but only those with a verified role in the DUBHCORE data flow. No AI/LLM service (Gemini/Vertex/Bedrock, etc.) processes DUBHCORE user data (the technical audit did not detect any AI runtime processing).

Final note: the DPAs/agreements with the providers are perfected via valid electronic acceptance (no separate handwritten signature required; the evidence is the online acceptance). The retention period of Emergent's infrastructure logs (IP address, approximate location, browser, session/device identifiers, telemetry) was not communicated or confirmed by the provider: these logs are managed by Emergent within its own infrastructure and applicable terms/documentation; DUBHCORE does not state an unverified numerical period. This does not constitute a launch blocker.