Sub-Processors at DateSteady

A public list of every third-party service that processes personal data on our behalf, why they touch it, where they're based, and the legal mechanism in place for cross-border transfers.

Last updated: 30 September 2026 · Controller: HoopFrog Inc., Federal Corp. No. 1467452-9, Alberta Canada · Privacy contact: dpo@datesteady.com

This page is published in compliance with UK GDPR Article 13(1)(f) (information about international transfers), Article 28 (use of processors), and Article 46 (transfer mechanisms), and the equivalent obligations under EU GDPR, PIPEDA, Quebec Law 25 (s.17 cross-border PIA), and Brazil's LGPD. It is the same dataset as our internal Records of Processing Activities - published here so any data subject can audit who touches their data, in one place, without making a Subject Access Request.

Sub-processors with current data flows

Vendor Purpose Jurisdiction Transfer mechanism
OVHcloud Primary infrastructure (web servers, databases, application hosting). Beauharnois (Quebec) datacentre. Canada (QC) Adequacy decision
Within Canada - no cross-border transfer.
VerifyMy Photo-ID age verification. Pass/fail handshake only - we never receive the document, DOB, or biometric. United Kingdom UK GDPR domestic
ISO 27001 certified.
Amazon Web Services Rekognition (image + video moderation labels, selfie face comparison, and Face Liveness for the live selfie check: a short camera video streamed from the member's device straight to AWS, and one frame from it compared with the member's main approved public profile photo), Transcribe (voice-note and voice-greeting moderation transcription), and S3 (transient biometric processing). Source images never persisted by DateSteady; AWS retention governed by AWS product policy. Our AWS organization is opted out of AWS using this content to improve its AI services. European Union (Ireland) Art. 28 DPA signed
UK SCC + IDTA execution in progress
Microsoft PhotoDNA hash matching (CSAM detection). Edge Hash SDK locally generates the hash; only the hash is sent to Microsoft. United States Art. 28 DPA signed
UK SCC + IDTA execution in progress
Project Arachnid Shield CSAM hash matching (Canadian Centre for Child Protection). The hash is generated locally; only a non-reversible image hash (PDQ) is shared - the image is not shared. Canada (MB) Adequacy decision
Within Canada - no cross-border transfer.
Cloudflare CDN, DDoS mitigation, WAF, R2 object storage for moderation queue and DSAR exports. United States Art. 28 DPA signed
UK SCC + IDTA execution in progress
proxycheck.io VPN and proxy screening at sign-up. Receives the connecting IP address only. Address logging is turned off on our account. Canada (stored in region of origin) Provider processor terms
No separate Art. 28 DPA on our current plan.
AbuseIPDB Abuse-report screening at sign-up (AbuseIPDB LLC). Receives the connecting IP address, and only when the connection is not identified as an ordinary home internet connection (for example a VPN, relay or hosting network), when the address already appears on a public abuse list, or when our own lists are temporarily unavailable. United States Provider terms
No Art. 28 DPA yet.
Project Honey Pot Spam and abuse screening at sign-up through its http:BL lookup (Unspam Technologies, Inc.), under the same conditions as AbuseIPDB. Receives the connecting IPv4 address. The lookup is sent as an unencrypted DNS query, so networks between us and the http:BL servers can see it. United States, Ireland Provider terms
No Art. 28 DPA yet.
Postmark Transactional email delivery (verification, security alerts, breach notifications, DSAR receipts). United States Art. 28 DPA signed
UK SCC + IDTA execution in progress
Twilio SMS delivery for phone verification and 2FA. Optional STUN/TURN signalling fallback for video calls (signalling metadata only - call media is peer-to-peer and never traverses Twilio). United States Art. 28 DPA signed
UK SCC + IDTA execution in progress
PayPal Subscription payment processing (primary for web). PCI-DSS handled by PayPal; we never touch card data. United States Art. 28 DPA signed
UK SCC + IDTA execution in progress
Google Play Billing Android in-app subscription billing. Payment runs entirely inside Google Play; we receive purchase tokens and entitlement status only - never card data. United States Google processes Play purchases under its own Google Play terms; DateSteady receives entitlement data only.
Google Vertex AI Support chatbot inference + Safety Tier 2 grooming-classifier (planned). Hosted in northamerica-northeast1 (Montreal) - data stays in Canada. Canada (QC) Adequacy decision
Inference path stays in Canada.
Mixpanel Product analytics, consent-gated (loads only after analytics consent). Session replay is disabled. United States Art. 28 DPA available
UK SCC + IDTA execution in progress
KLIPY (Kikliko, Inc.) GIF search in messages. Searches are proxied by our own server: KLIPY receives the words typed in the GIF search box, a result count, a paging cursor, an app label naming DateSteady and a "medium" content filter. No name, account ID, device ID or member IP address is sent with the search. The GIF image itself is loaded from KLIPY by the member's device, so KLIPY sees that device's IP address at display time. Replaced Tenor (Google) on 21 July 2026 after Google discontinued the Tenor API. United States Provider API terms + KLIPY privacy policy
No separate Art. 28 DPA recorded in our contract register at this date; no member identifiers are sent with the search.
Google (Ads, Analytics 4) Advertising conversion measurement and site analytics, consent-gated. Google Consent Mode sets every storage type to denied until you make a cookie choice, and only the products whose category you accepted are loaded. United States Google Ads Data Processing Terms / Google Analytics terms
Signed-contract status not separately recorded in our contract file.
Meta Platforms (Meta Pixel) Advertising conversion measurement, consent-gated. The pixel is not loaded at all until you accept marketing cookies. United States Meta Business Tools terms
Signed-contract status not separately recorded in our contract file.

Sub-processors with planned but not currently active flows

Vendor Purpose (when activated) Jurisdiction Status
Apple App Store iOS in-app subscription billing (when the iOS app launches). Payment would run entirely inside the App Store; we would receive transaction and entitlement status only - never card data. United States Pending iOS launch; not currently active.
IWF Image Intercept Complementary CSAM hash matching layer (UK-curated, free for small platforms). Only the locally-computed hash is shared. United Kingdom Code scaffolded; awaiting eligibility decision from IWF.
Microsoft Clarity UX session replay (default off; opt-in only). United States Covered by Microsoft DPA; not currently active.

Vendors we do not use

Transfer mechanism legend

Adequacy decision - receiving country is on UK / EU adequacy list. Art. 28 DPA signed - controller-processor terms in force. UK SCC + IDTA execution in progress - Standard Contractual Clauses + UK International Data Transfer Addendum being signed (vendor-side self-serve flow). Note - additional context.

How this list is maintained

This page is generated from the same source as our internal Records of Processing Activities (Art. 30). The two are kept in lockstep: any sub-processor change requires updating both. The internal RoPA holds full processing-purpose detail per processing activity; this public page collapses that detail per vendor for readability.

Material changes (new vendor onboarded, vendor removed, transfer mechanism changed) are announced via the privacy policy update notification in-app and the privacy@datesteady.com mailing list. To subscribe to that list, email us; opt-in is a single click and you can withdraw at any time.

Questions, complaints, or rights requests

For any question about a specific sub-processor, transfer mechanism, or to exercise a data subject right (Art. 15–22 / PIPEDA / Law 25 s.8.1 de-indexation / LGPD), email dpo@datesteady.com. We respond within 30 days (15 days for Brazilian residents under LGPD; 20 business days for Mexican residents under LFPDPPP).

You can also contact our EU + UK Article 27 representative (DataRep) once their addresses are published in our privacy policy §15A.