DUBHCORE — Sub-processors List
Version 1.0 — Date: 30 August 2026 — Final version Listed are only the providers actually used (verified on code/config). Dependencies present in the project but not actively used are NOT included. DPA/agreements: where the provider's DPA is incorporated into the terms or perfected via valid electronic acceptance, no separate handwritten signature is required; the evidence is the online acceptance (the possession of "signed" copies is not declared). The duration of Emergent's infrastructure logs was not communicated or confirmed by the provider (managed by Emergent within its own infrastructure; no unverified numerical period is stated) and does not currently constitute a launch blocker.
| Provider | Service / Purpose | Data categories | Place of processing | International transfer | Mechanism/Guarantee | Notes |
|---|---|---|---|---|---|---|
| Stripe | A) DUBHCORE subscriptions/billing; B) Stripe Connect for Studios' deposits; webhook events | Payment/billing data, transaction identifiers | EU/USA (PARTIAL — not verified) | Yes | Stripe DPA/DPP + SCC perfected via online acceptance of the terms | Stripe may act as an autonomous Controller for certain processing (payments, compliance, anti-fraud, own obligations) according to the applicable Stripe documentation; not a mere sub-processor |
| Only OAuth + Google Calendar (read-only import) | Account identifiers (email/profile), imported calendar events | EU/USA (PARTIAL — not verified) | Yes | Google Data Processing Terms + SCC via online acceptance | OAuth tokens stored encrypted (Fernet). Excluded: analytics, advertising, Google Fonts, AI services and other unused Google services | |
| Emergent | Backend hosting/infrastructure (K8s), private managed Object Storage, sending of transactional emails (managed Resend/SES), Hub | All hosted categories (account, requests, images, documents, etc.); recipients' email addresses | United States (VERIFIED) | Yes (USA) | Emergent DPA + SCC EU 2021/914 | Deployment platform; infrastructure sub-provider chain below |
Expo / EAS (technical note — NOT a runtime sub-processor): used exclusively as a build/distribution tool for the mobile app. According to the technical audit, it does not process the personal data of end users of DUBHCORE during normal use of the app; therefore it is not included in the public list of sub-processors and is not presented as a runtime sub-processor of client data.
Apple Calendar: access takes place on the user's device (expo-calendar); it does not constitute a server-side sub-processor of DUBHCORE (no Apple calendar data is sent to the servers).
Health data (Art. 9) at the sub-processors: the health data (Tattoo/Piercing) is hosted on the Emergent infrastructure (already listed) together with the other categories; access is limited server-side to authorised roles only (least privilege). Emergent's confirmation regarding the admissibility of processing such data for the application does not constitute the lawfulness condition under Art. 9, which remains explicit consent (Art. 9(2)(a)) identified by the Studio as Controller. No other sub-processor specifically receives the health data.
Analytics/advertising/tracking: absent both in the app and on the Hub website (dubhcore.com) — verified audit (no analytics sub-processor).
DUBHCORE Hub (dubhcore.com): the contact form /contact (name, studio, email, country, message) sends the data to the Hub backend, stored in the MongoDB collection contact_requests of the Hub project (hosted on Emergent infrastructure, already listed). No external email/newsletter provider receives such data. Payments take place via external Stripe Payment Links (buy.stripe.com), already covered by the Stripe entry.
Google Fonts and Unsplash: are no longer active external services — the Hub's fonts and "Origin" image are now hosted locally. Therefore they do not appear among the external providers/recipients.
Verified infrastructure (Emergent Labs Inc.): DUBHCORE uses the infrastructure managed by Emergent Labs Inc. Infrastructure sub-providers with a verified/reasonably documented role in the DUBHCORE data flow:
| Provider | Service / Purpose | Location | International transfer | Guarantee |
|---|---|---|---|---|
| Emergent Labs Inc. | Managed platform/infrastructure (deployment, orchestration) | United States | Yes (USA) | DPA + SCC (EU Dec. 2021/914) |
| MongoDB Atlas | Managed database of the application | United States | Yes (USA) | via Emergent DPA + SCC |
| Amazon Web Services (AWS) | Cloud hosting / object storage / email, where applicable | United States | Yes (USA) | via Emergent DPA + SCC |
| Cloudflare | Edge/CDN/application serving | Edge/globally distributed (PARTIAL — region not verified) | Yes | via Emergent DPA + SCC |
Production backups: automatic rotating, stored in the United States (detail in the Data Retention Schedule). DPA roles: Customer = Controller, Emergent = Processor; if the Customer is in turn Processor, Emergent = Sub-processor.
Not all providers present in Emergent's general Sub-processors page are listed, but only those with a verified role in the DUBHCORE data flow. No AI/LLM service (Gemini/Vertex/Bedrock, etc.) processes DUBHCORE user data (the technical audit did not detect any AI runtime processing).
Final note: the DPAs/agreements with the providers are perfected via valid electronic acceptance (no separate handwritten signature required; the evidence is the online acceptance). The retention period of Emergent's infrastructure logs (IP address, approximate location, browser, session/device identifiers, telemetry) was not communicated or confirmed by the provider: these logs are managed by Emergent within its own infrastructure and applicable terms/documentation; DUBHCORE does not state an unverified numerical period. This does not constitute a launch blocker.