Privacy

Sub-responsabili

Elenco vivo dei fornitori autorizzati al trattamento di dati personali per conto di Zenitup.

Data Subprocessors

Zenitup LLC — Third-party processors authorised to handle personal data on our behalf

Last updated: July 20, 2026

Version: 1.3

Contact: info@zenitup.app — for any questions regarding this list or our data processing practices.

Zenitup LLC uses third-party service providers (subprocessors) to help operate and deliver the platform.

Each subprocessor is bound by data processing agreements that impose data protection obligations at least

equivalent to those in our Privacy Policy and in the Standard Contractual Clauses (EU SCCs 2021/914, Module 2)

where applicable.

We will give notice of any additions or replacements to this list at least 15 days in advance by updating this page and notifying customers who have signed a Data Processing Agreement with us.

Customers may object to changes within the notice period as provided in their DPA.

Authorised Subprocessors

ProviderFunctionCountryTransfer mechanismData categories
Hetzner Online GmbH hetzner.comPrimary hosting infrastructure — VPS/servers, database, application storage, backups (EU)Germany (EU)No transfer outside EEA. DPA Hetzner Online GmbH v1.2, accepted 20/06/2026. Processing exclusively in EU per §3 DPA.Account data, workspace data, end-client data, files, database, technical logs, application data (including any special category data uploaded by the controller). Backups encrypted before upload — Hetzner does not access plaintext content.
Google LLC cloud.google.comGoogle Calendar API / OAuth integration — free/busy availability, calendar list metadata for selecting calendars, reading coach-owned calendar events, creating and managing Zenitup-generated eventsUSA / GlobalEU-U.S. Data Privacy Framework (Google LLC certified) + EU SCCs Module 2 (Decision 2021/914) as additional safeguard. Google Cloud Data Processing Addendum accepted via Google Cloud/API Console Terms. Subprocessor notice: 30 days (DPA §11.4). Google API Services User Data Policy (15/02/2024): no advertising use, no AI training, no transfer to third parties, human access prohibited except in limited specified cases. ISO 27001, 27017, 27018, SOC 2, SOC 3.OAuth access/refresh tokens, calendar ID, calendar name/summary, primary calendar flag, access role, calendar timezone, event ID, sync token, free/busy cache, event title/time/timezone/status/location/meeting link. Scopes: calendar.freebusy, calendar.events.owned, calendar.calendarlist.readonly.
Cloudflare, Inc. cloudflare.comDNS, routing, network security, CDN / WAF / proxyUSA / Global edgeEU-U.S. Data Privacy Framework (Cloudflare certified) + EU SCCs Module 2 (Decision 2021/914) as additional safeguard. DPA Cloudflare v6.4, in force from 03/04/2026, accepted via Cloudflare account.IP addresses, HTTP headers, technical logs, traffic metadata, security events, DNS records.
SMTP2GO Sand Dune Mail Ltd smtp2go.comTransactional outbound email — operational emails, notifications, verifications, platform communicationsNew ZealandEU SCCs Module 2 (Decision 2021/914), governing law: Ireland, supervisory authority: Irish DPC. DPA SMTP2GO v1.4 (15/07/2025), accepted via EU dashboard. Data stored in EEA (EU data centre active on account).Recipient email address, name where present, workspace/account ID, transactional email content, delivery/bounce logs, metadata.
Postmark Wildbit LLC (ActiveCampaign group) postmarkapp.comInbound email / reply capture — receiving email replies and inbound webhooksUSA (AWS)EU-U.S. Data Privacy Framework (AC PM LLC certified, including UK Extension and Swiss-U.S. DPF) + EU SCCs Module 2 (Decision 2021/914), governing law: Ireland, jurisdiction: Ireland. DPA Postmark effective 17/11/2025, incorporated in Terms of Service.Sender/recipient, subject, email body, attachments where present, metadata, raw webhook payload, IP/technical logs.
Sentry Functional Software, Inc. sentry.ioError tracking, backend/frontend diagnostics, application security monitoringUSAEU-U.S. Data Privacy Framework (Sentry certified) + EU SCCs Module 2 (Decision 2021/914) as fallback, governing law: Ireland, jurisdiction: Ireland. DPA Sentry v5.1.0 (29/05/2024), accepted via Terms of Service. EU storage active on account (eu.sentry.io).Errors, stack traces, IP/user agent where collected, technical metadata. Sensitive payloads, tokens and health data excluded from logs via active scrubbing. send_default_pii=false enabled.
SMSFactor Commify France SAS smsfactor.comOutbound SMS — OTPs, operational notifications, sender brand managementFrance (EU)No transfer safeguard required for the direct contractual relationship — Commify France SAS is a French company subject to GDPR as an EU-established processor. DPA SMSFactor (20/12/2023), included in General Terms of Service, governing law: France, supervisory authority: CNIL. Note: SMS delivery may involve routing through international telecom operators; content is minimised accordingly.Phone number, SMS content, sender ID, delivery metadata, delivery status, logs.
OpenAI OpenAI OpCo LLC / OpenAI Ireland Ltd openai.comAI API — analysis, drafting, suggestions, summaries for coach/staff operational support (where AI features are enabled)USAEU SCCs Module 2 (Decision 2021/914) for intragroup transfer OpenAI Ireland Ltd → OpenAI OpCo LLC (USA). OpenAI Ireland Ltd is the contractual data importer for all EEA data (DPA Art. 4.1). DPA OpenAI (updated 01/12/2025, in force 01/01/2026): openai.com/policies/data-processing-addendum. No data retention for AI training on API/business tier.Minimised prompts (internal identifiers instead of names where possible), notes, progress data. Health data only where strictly necessary and on controller instruction. No data retention for training; zero data retention where ZDR is configured.
Anthropic Anthropic PBC / Anthropic Ireland, Ltd anthropic.comAI API (alternative / complementary) — analysis, drafting, suggestions (where AI features are enabled)USAEU SCCs Module 2 (Decision 2021/914), governing law: Ireland, jurisdiction: Ireland (Schedule 3, Clause 17–18). DPA Anthropic (effective 24/02/2025), incorporated in Commercial Terms of Service: anthropic.com/legal/data-processing-addendum. No data retention for training on API/commercial tier — contractually prohibited (Commercial Terms, Section B). Subprocessor list: anthropic.com/subprocessors.Minimised prompts, progress data. Health data only where strictly necessary. No use for AI training.

Google API Services — Limited Use Disclosure

Zenitup's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy ,

including the Limited Use requirements.

Google Calendar data is used exclusively to provide Zenitup's scheduling features. It is not used for advertising,

profiling, sale to third parties, or training AI/ML models.

Changes to this list. We will notify customers of any addition or replacement of a subprocessor with at least 15 days' advance notice by updating this page and, where a DPA is in place, by written notice to the customer contact on record.

Customers may object to a new or replacement subprocessor within the notice period as set out in their DPA.

Questions? Contact info@zenitup.app or our EU Representative:

Giuseppe Lo Presti — giuseppelopresti.avv@gmail.com .

This page was last updated July 20, 2026. Previous versions are available on request.

The contractual subprocessor list is contained in Annex III of the Standard Contractual Clauses (EU SCCs 2021/914)

signed between Zenitup LLC and each customer.