Service Providers, Recipients and Subprocessors
Last updated: 25 August 2026
GBD Software as a Service Private Limited Company uses third-party service providers, recipients and subprocessors to operate, secure, support, analyse, market and administer MillionVerifier.
Combined master list for (i) GBD-controller processing disclosed through the Privacy Policy and (ii) Customer Personal Data processed under the MillionVerifier DPA.
Payment processing
Stripe
Scope: Privacy Policy
Legal entity and address: Stripe Payments Europe, Limited, One Wilton Park, Wilton Place, Dublin 2, D02 FX04, Ireland
Purpose: Card/payment processing, saved payment methods, billing and Stripe Radar fraud prevention
Personal Data typically involved: Name, email, billing details, payment-method and transaction identifiers, fraud/risk signals, IP address, device and technical information
GDPR role for this use: Mixed: processor for specified merchant-directed processing and independent/joint controller for regulated payments, fraud/risk and other Stripe-determined processing
Privacy / legal information: Stripe Privacy Center
PayPal
Scope: Privacy Policy
Legal entity and address: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg
Purpose: Payment processing and payment administration
Personal Data typically involved: Name, email, billing information, transaction identifiers and payment-related information
GDPR role for this use: Independent controller / payment recipient for relevant payment processing
Privacy / legal information: PayPal Privacy
Analytics, forms, consent management and AI tools
Google Analytics (GA4)
Scope: Privacy Policy
Legal entity and address: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Purpose: Website analytics, traffic/product measurement, attribution and Google Signals
Personal Data typically involved: Online/cookie and advertising identifiers, IP-derived information, device/browser information, page/event data, referral information, conversion data and cross-device/audience information produced through Google Signals
GDPR role for this use: Processor for Analytics data handled under Google’s applicable data-processing terms, with separate controller processing for Google account/service and specified Google-determined purposes
Privacy / legal information: Google Privacy
Anthropic — Claude Team and API
Scope: Privacy Policy and DPA
Legal entity and address: Anthropic Ireland, Limited (EEA contracting and DPA entity). Invoice issuer and billing address: Anthropic, PBC, 548 Market Street, PMB 90375, San Francisco, California 94104, United States
Purpose: AI-assisted processing and analysis used to operate and support MillionVerifier, including processing Customer Personal Data where required, investigating and resolving complaints, service issues and customer enquiries, troubleshooting, and internal analysis/business workflows through Claude Team and the Anthropic API
Personal Data typically involved: Prompts, submitted files/content and generated outputs; Customer Personal Data processed through MillionVerifier, including email addresses and other Personal Data contained in customer-provided datasets or support materials; account and business contact information; support requests, complaints and enquiries; verification results; and service, log or diagnostic information included in the relevant workflow
GDPR role for this use: When GBD acts as controller, Anthropic acts as GBD's processor for Personal Data submitted through its commercial services. When GBD processes Customer Personal Data on behalf of a Customer under the MillionVerifier DPA, Anthropic acts as GBD's subprocessor. Anthropic separately acts as controller for its own account, security and service-administration processing
Privacy / legal information: Anthropic Privacy · Anthropic Privacy Center · Anthropic DPA information
Google Gemini
Scope: Privacy Policy and DPA
Legal entity and address: Google Cloud EMEA Limited, Velasco, Clanwilliam Place, Dublin 2, Ireland
Purpose: AI-assisted processing and analysis used to operate and support MillionVerifier, including processing Customer Personal Data where required, investigating and resolving complaints, service issues and customer enquiries, troubleshooting, and internal analysis/business workflows through Gemini
Personal Data typically involved: Prompts, generated outputs, files/content supplied to Gemini and Workspace content accessed through Gemini features; Customer Personal Data processed through MillionVerifier, including email addresses and other Personal Data contained in customer-provided datasets or support materials; account and business contact information; support requests, complaints and enquiries; verification results; and service, log or diagnostic information included in the relevant workflow
GDPR role for this use: When GBD acts as controller, Google acts as GBD's processor for Personal Data processed through the applicable Google business services. When GBD processes Customer Personal Data on behalf of a Customer under the MillionVerifier DPA, Google acts as GBD's subprocessor. Google separately acts as controller for its own account, security and service-administration processing
Privacy / legal information: Google Cloud Privacy · Google Cloud Data Processing Addendum
OpenAI — ChatGPT Business and API
Scope: Privacy Policy and DPA
Legal entity and address: OpenAI Ireland Ltd. (EEA contracting and DPA entity), 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland. Invoice issuer and billing address: OpenAI OpCo, LLC, 1455 3rd Street, San Francisco, California 94158, United States
Purpose: AI-assisted processing and analysis used to operate and support MillionVerifier, including processing Customer Personal Data where required, investigating and resolving complaints, service issues and customer enquiries, troubleshooting, and internal analysis/business workflows through ChatGPT Business and the OpenAI API
Personal Data typically involved: Prompts, submitted files/content and generated outputs; Customer Personal Data processed through MillionVerifier, including email addresses and other Personal Data contained in customer-provided datasets or support materials; account and business contact information; support requests, complaints and enquiries; verification results; and service, log or diagnostic information included in the relevant workflow
GDPR role for this use: When GBD acts as controller, OpenAI acts as GBD's processor for Personal Data submitted through ChatGPT Business and the OpenAI API. When GBD processes Customer Personal Data on behalf of a Customer under the MillionVerifier DPA, OpenAI acts as GBD's subprocessor. OpenAI separately acts as controller for its own account, security and service-administration processing
Privacy / legal information: OpenAI Privacy · OpenAI DPA
Klipfolio
Scope: Privacy Policy
Legal entity and address: Klipfolio Inc., 300 Greenbank Road, Suite 94, Ottawa, Ontario K2H 0B6, Canada
Purpose: Business intelligence, dashboards and analytics
Personal Data typically involved: Business contact information, account information, usage information and data imported into dashboards
GDPR role for this use: Processor for data processed on GBD’s behalf; controller for certain account and service information
Privacy / legal information: Klipfolio Privacy
Typeform
Scope: Privacy Policy
Legal entity and address: Typeform, S.L., Vía Augusta 29–31, 08006 Barcelona, Cataluña, Spain
Purpose: Online forms, surveys and collection of responses
Personal Data typically involved: Name, email, business information, form responses, IP/device and submission metadata
GDPR role for this use: Processor for form-response data submitted by GBD; controller for certain account/service information
Privacy / legal information: Typeform Privacy & Security
CookieYes
Scope: Privacy Policy
Legal entity and address: CookieYes Limited, 3 Warren Yard, Warren Park, Wolverton Mill, Milton Keynes, MK12 5NW, United Kingdom
Purpose: Cookie-consent management and consent records
Personal Data typically involved: Consent choices, consent records, cookie/online identifiers and technical information
GDPR role for this use: Processor for consent-management data; controller for certain account/service information
Privacy / legal information: CookieYes Privacy
Accounting, audit and financial administration
Bergmann Könyvelő Iroda
Scope: Privacy Policy
Legal entity and address: BERGMANN Könyvelő Iroda Kft., 1138 Budapest, Váci út 186., Hungary
Purpose: Bookkeeping, accounting, tax and financial administration
Personal Data typically involved: Customer/supplier contact details, invoice data, transaction information, tax and accounting records
GDPR role for this use: Mixed: processor where carrying out outsourced bookkeeping on GBD’s instructions; independent controller where legal/professional duties require it to determine processing
Privacy / legal information: Bergmann Privacy Notice
Főnixbata Auditáló
Scope: Privacy Policy
Legal entity and address: Főnixbata Auditáló Kft., 1152 Budapest, Szentmihályi út 131., Pólus Center, Wall Street 21., Hungary
Purpose: Statutory external audit
Personal Data typically involved: Contact information, financial records, invoices, transaction and accounting information required for the statutory audit
GDPR role for this use: Independent controller / professional recipient for statutory audit processing
Privacy / legal information: —
Hosting, servers, proxies and network infrastructure
Amazon Web Services (AWS)
Scope: Privacy Policy and DPA
Legal entity and address: Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg
Purpose: Cloud hosting, storage, infrastructure, backup and security
Personal Data typically involved: Account/contact data, application data, logs, IP addresses, security events and other hosted personal data
GDPR role for this use: Processor for hosted data; controller for certain account/service administration data
Privacy / legal information: AWS Privacy
Fasthosts
Scope: Privacy Policy and DPA
Legal entity and address: Fasthosts Internet Limited, 2 Cathedral Walk, The Forum, Gloucester GL1 1AU, United Kingdom
Purpose: Hosting, servers and related infrastructure
Personal Data typically involved: Hosted content, account/contact data, IP addresses, server and security logs
GDPR role for this use: Processor for hosted data; controller for certain account/service data
Privacy / legal information: Fasthosts Privacy Notice
RackForest
Scope: Privacy Policy and DPA
Legal entity and address: RACKFOREST Zrt., 1132 Budapest, Victor Hugo utca 11., 5. em. B05001. a., Hungary
Purpose: Hosting, servers and infrastructure
Personal Data typically involved: Hosted application/account data, Customer Personal Data, IP addresses, server logs and security data
GDPR role for this use: Processor for GBD-controller hosted data and subprocessor for Customer Personal Data; controller for its own account/service administration data
Privacy / legal information: RackForest Privacy Policy
Webshare
Scope: DPA
Legal entity and address: Webshare Software / Webshare, 340 S Lemon Ave #6464, Walnut, CA 91789, United States
Processing / infrastructure location: United States
Purpose: Proxy/network infrastructure used for verification traffic
Personal Data typically involved: Connection metadata, destination information and Customer Personal Data transmitted through the proxy service
GDPR role for this use: Subprocessor for verification traffic/data processed on GBD's behalf; controller for its own account, compliance and abuse-prevention data
Privacy / legal information: Webshare Privacy
ProxyScrape
Scope: DPA
Legal entity and address: Thib BV, Brugstraat 18/101, 2812 Mechelen, Belgium. Billing merchant shown on invoice: Paddle.com Market Ltd, Judd House, 18–29 Mora Street, London EC1V 8BT, United Kingdom
Processing / infrastructure location: United States
Purpose: Proxy/network infrastructure used for verification traffic
Personal Data typically involved: Connection metadata, destination information and Customer Personal Data transmitted through the proxy service
GDPR role for this use: Subprocessor for verification traffic/data processed on GBD's behalf; controller for its own account/service data
Privacy / legal information: ProxyScrape Privacy
Byteful (formerly Ping Proxies)
Scope: DPA
Legal entity and address: Ping Technology Labs LTD, Queens Chambers, John Dalton Street, Floor 3, Manchester M2 6ET, United Kingdom
Processing / infrastructure location: United States
Purpose: Proxy/network infrastructure used for verification traffic
Personal Data typically involved: IP addresses, targets accessed, connection/usage logs, destination information and Customer Personal Data transmitted through the service
GDPR role for this use: Subprocessor for verification traffic/data processed on GBD's behalf; controller for its own account, security and service data
Privacy / legal information: Byteful Privacy
GloryCloud
Scope: DPA
Legal entity and address: BEYOND TECHNOLOGY (HONG KONG) CO., LIMITED, Workshop 60, 3/F, Block A, East Sun Industrial Centre, No. 16 Shing Yip Street, Kowloon, Hong Kong
Processing / infrastructure location: United States
Purpose: Proxy and web-access infrastructure used for verification traffic
Personal Data typically involved: Connection metadata, destination information and Customer Personal Data transmitted through the service
GDPR role for this use: Subprocessor for verification traffic/data processed on GBD's behalf; controller for its own account/service data
Privacy / legal information: GloryCloud Privacy
BigCloudy
Scope: DPA
Legal entity and address: BigCloudy Internet Services Pvt. Ltd., B-1/1/7, MIDC Ambad, Nashik, Maharashtra 422012, India
Processing / infrastructure location: Germany
Purpose: VPS, dedicated server and hosting infrastructure used for MillionVerifier processing
Personal Data typically involved: Hosted application/verification data, IP addresses, server logs, security data and Customer Personal Data stored or processed on the servers
GDPR role for this use: Subprocessor for hosted Customer Personal Data; controller for its own account/service administration data
Privacy / legal information: BigCloudy Privacy
netcup
Scope: DPA
Legal entity and address: netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany
Processing / infrastructure location: Germany
Purpose: Server, VPS and hosting infrastructure used for MillionVerifier processing
Personal Data typically involved: Hosted application/verification data, IP addresses, server logs, security data and Customer Personal Data stored or processed on the servers
GDPR role for this use: Subprocessor for hosted Customer Personal Data; controller for its own account/service administration data
Privacy / legal information: netcup Privacy
ServerMania
Scope: DPA
Legal entity and address: ServerMania Inc., 205-1040 South Service Road, Stoney Creek, Ontario L8E 6G3, Canada
Processing / infrastructure location: Canada
Purpose: Dedicated server and cloud infrastructure used for MillionVerifier processing
Personal Data typically involved: Hosted application/verification data, IP addresses, server logs, security data and Customer Personal Data stored or processed on the servers
GDPR role for this use: Subprocessor for hosted Customer Personal Data; controller for its own account/service administration data
Privacy / legal information: ServerMania Privacy
ServerHub
Scope: DPA
Legal entity and address: ServerHub Inc., 2360 Corporate Circle, Suite 400, Henderson, NV 89074, United States
Processing / infrastructure location: United States
Purpose: Dedicated server and infrastructure services used for MillionVerifier processing
Personal Data typically involved: Hosted application/verification data, IP addresses, server logs, security data and Customer Personal Data stored or processed on the servers
GDPR role for this use: Subprocessor for hosted Customer Personal Data; controller for its own account/service administration data
Privacy / legal information: ServerHub Privacy
OneProvider
Scope: DPA
Legal entity and address: BrainStorm Network Inc., 3275 Av Francis-Hughes, Laval, QC H7L 5A5, Canada
Processing / infrastructure location: France
Purpose: Dedicated server and hosting infrastructure used for MillionVerifier processing
Personal Data typically involved: Hosted application/verification data, IP addresses, server logs, security data and Customer Personal Data stored or processed on the servers
GDPR role for this use: Subprocessor for hosted Customer Personal Data; controller for its own account/service administration data
Privacy / legal information: OneProvider Privacy
SEOHost / Lanos Technologies
Scope: DPA
Legal entity and address: Lanos Technologies Private Limited, 304, 3rd Floor, Silver Square, Dattatray Road, S.V. Road, Santacruz (West), Mumbai 400054, India
Processing / infrastructure location: United States
Purpose: Hosting/server infrastructure used for MillionVerifier processing
Personal Data typically involved: Hosted application/verification data, IP addresses, server logs, security data and Customer Personal Data stored or processed on the servers
GDPR role for this use: Subprocessor for hosted Customer Personal Data; controller for its own account/service administration data
Privacy / legal information: Lanos Technologies
Miss Hosting
Scope: DPA
Legal entity and address: Miss Group INC, 2719 Hollywood Boulevard, Suite A-241, Hollywood, FL 33020, United States
Processing / infrastructure location: Sweden
Purpose: Hosting/server infrastructure used for MillionVerifier processing
Personal Data typically involved: Hosted application and account data, Customer Personal Data, IP addresses, server logs and security/technical data
GDPR role for this use: Processor for GBD-controller hosted data and subprocessor for Customer Personal Data hosted or processed on the server; controller for its own account/service administration data
Privacy / legal information: Miss Hosting Privacy
DNS, network delivery and security
ClouDNS
Scope: Privacy Policy and DPA
Legal entity and address: Cloud DNS Ltd., 4 Iskar Str., Sofia 1000, Bulgaria
Purpose: DNS hosting and domain infrastructure
Personal Data typically involved: Domain/account information, IP addresses and DNS/technical metadata
GDPR role for this use: Processor/service provider for relevant technical data; controller for certain account information
Privacy / legal information: ClouDNS Privacy
Cloudflare
Scope: Privacy Policy and DPA
Legal entity and address: Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, United States
Purpose: DNS, CDN/reverse-proxy traffic delivery, Web Application Firewall (WAF), DDoS protection and network/security services
Personal Data typically involved: IP addresses, HTTP/network request metadata, URLs, device/browser information, security events, logs and Customer Personal Data transmitted through proxied MillionVerifier endpoints
GDPR role for this use: Processor for GBD-controller traffic/security data and subprocessor where Customer Personal Data passes through the service; controller for its own account, security and service-administration data
Privacy / legal information: Cloudflare Privacy
Email delivery and communications infrastructure
Mailgun
Scope: Privacy Policy
Legal entity and address: Mailgun Technologies, Inc., 112 E. Pecan St. #1135, San Antonio, TX 78205, United States
Purpose: Transactional/service email and marketing email delivery, routing, deliverability and bounce/complaint management
Personal Data typically involved: Recipient email address, sender information, message headers/content, campaign/service-message information, delivery/bounce/complaint data, IP addresses and technical metadata
GDPR role for this use: Processor for email data sent through GBD’s Mailgun account; controller for its own account, security and service-administration data
Privacy / legal information: Mailgun Privacy
Lead generation, sales intelligence and outreach
SmartReach.io
Scope: Privacy Policy
Legal entity and address: HVIF Solutions Private Limited, Plot No. 49, Road No. 2, Phase 2, Agricultural Colony, Hasthinapuram Central, Hyderabad, Telangana 500070, India
Purpose: Email outreach, campaign management and sales engagement
Personal Data typically involved: Prospect name, business email, company/job information, campaign status, email activity and communications
GDPR role for this use: Processor for prospect/campaign data supplied by GBD; controller for certain account/service data
Privacy / legal information: SmartReach Privacy
Zapmail
Scope: Privacy Policy
Legal entity and address: Outbox Labs Inc. d/b/a Zapmail, 108 W. 13th Street, Suite 100, Wilmington, Delaware 19801, United States
Purpose: Mailbox/domain infrastructure and outreach operations
Personal Data typically involved: Business contact information, mailbox/account data, domains, email metadata and communications
GDPR role for this use: Processor for customer-submitted workspace/mailbox/contact data; controller for certain account/billing/service data
Privacy / legal information: Zapmail Privacy
RB2B
Scope: Privacy Policy
Legal entity and address: GetEmails, LLC d/b/a RB2B / R! B2B, 1401 Lavaca Street, Unit #298, Austin, TX 78701, United States
Purpose: Website visitor identification and lead intelligence, including person-level identification/contact information
Personal Data typically involved: Website/device identifiers, IP/network information, browsing events, page interactions and matched person-level business/contact information
GDPR role for this use: Mixed: independent controller/data provider for the business/contact data it supplies and processor for specified GBD-submitted data under its service terms
Privacy / legal information: RB2B Privacy
SalesRobot
Scope: Privacy Policy
Legal entity and address: SalesRobot Inc., 2810 N Church St., PMB 162241, Wilmington, Delaware 19802, United States
Purpose: LinkedIn/sales outreach automation and campaign management
Personal Data typically involved: Prospect name, profile/business information, contact details, campaign activity and communications
GDPR role for this use: Processor for customer-supplied outreach data; controller for certain account/service data
Privacy / legal information: SalesRobot Privacy
Aircall
Scope: Privacy Policy
Legal entity and address: Aircall SAS, 11 Rue Saint-Georges, 75009 Paris, France
Purpose: Cloud telephony and sales/customer calls, including call recording, transcription, AI summaries and call analysis
Personal Data typically involved: Name, phone number, business contact information, call metadata, audio recordings, transcripts, AI-generated summaries/analysis and communications
GDPR role for this use: Processor for call/customer data handled through GBD’s account; controller for its own account, security and service-administration data
Privacy / legal information: Aircall Privacy
Apollo.io
Scope: Privacy Policy
Legal entity and address: ZenLeads, Inc. d/b/a Apollo.io, 440 N Barranca Ave, #4750, Covina, California 91723, United States
Purpose: B2B contact intelligence, prospecting, enrichment and sales engagement
Personal Data typically involved: Business contact details, professional/profile information, email/phone data, campaign and engagement information
GDPR role for this use: Mixed: independent controller/data provider for relevant Apollo database information; processor for certain customer-submitted data
Privacy / legal information: Apollo Privacy
Lusha
Scope: Privacy Policy
Legal entity and address: Lusha Systems Inc., 800 Boylston Street, Suite 1410, Boston, MA 02199, United States
Purpose: B2B contact intelligence, prospecting and enrichment
Personal Data typically involved: Business contact details, professional/profile information, email addresses and telephone numbers
GDPR role for this use: Independent controller/data provider for relevant business-profile data; processor for certain customer-submitted data
Privacy / legal information: Lusha Privacy
LinkedIn Sales Navigator
Scope: Privacy Policy
Legal entity and address: LinkedIn Ireland Unlimited Company, Five Wilton Park, Dublin, D02 FX04, Ireland
Purpose: B2B prospecting, professional-network research and Sales Navigator sales workflows
Personal Data typically involved: LinkedIn member/profile information, professional and company data, Sales Navigator activity, messages, notes and tags
GDPR role for this use: Mixed: LinkedIn acts as independent controller for LinkedIn member/profile data and as processor for specified customer data under LinkedIn’s product/DPA terms
Privacy / legal information: LinkedIn Privacy
Sales and reputation management
Faouzi Mansour
Scope: Privacy Policy
Legal entity and address: Faouzi Mansour, Mahdia, Rue 03, 5121 Rejich, Tunisia
Purpose: Sales outreach using both leads/data supplied by GBD and prospects independently sourced by the contractor
Personal Data typically involved: Prospect/customer name, business contact details, company/job information, communications and sales notes
GDPR role for this use: Mixed role: acts on GBD’s instructions for GBD-supplied lead/contact data and acts as an independent controller for prospecting activities where he independently sources/selects prospects and determines the outreach activity
Privacy / legal information: —
Trustpilot
Scope: Privacy Policy
Legal entity and address: Trustpilot A/S, Pilestræde 58, DK-1112 Copenhagen K, Denmark
Purpose: Customer review invitations using customer data uploaded by GBD, review collection/publication and reputation management
Personal Data typically involved: Customer name, email address, transaction/reference information supplied for invitations, review content and reviewer/account information
GDPR role for this use: Mixed: processor for specified business-supplied invitation data and independent controller for the Trustpilot review platform and reviewer activities
Privacy / legal information: Trustpilot Privacy
Advertising and marketing platforms
Reddit Ads / Reddit Pixel
Scope: Privacy Policy
Legal entity and address: Reddit Netherlands B.V., Keizersgracht 62, 1015 CS Amsterdam, The Netherlands
Purpose: Reddit advertising plus Reddit Pixel/conversion tracking, campaign measurement, audiences and retargeting
Personal Data typically involved: Cookie/advertising identifiers, IP/device information, website browsing events, campaign interactions, conversion events and audience information
GDPR role for this use: Independent controller / advertising recipient for the relevant Reddit advertising and measurement processing
Privacy / legal information: Reddit Privacy
LinkedIn Ads / Insight Tag
Scope: Privacy Policy
Legal entity and address: LinkedIn Ireland Unlimited Company, Five Wilton Park, Dublin, D02 FX04, Ireland
Purpose: LinkedIn advertising, Insight Tag, conversion tracking, website retargeting and Matched Audiences/contact-list uploads
Personal Data typically involved: LinkedIn/member identifiers, IP address, device/browser information, visited URLs and timestamps, campaign interactions, conversion events, hashed contact/audience data and advertising identifiers
GDPR role for this use: Independent-controller/controller-to-controller processing for the Insight Tag and relevant Marketing Solutions activities; processor role applies to specified customer-submitted data under LinkedIn’s terms
Privacy / legal information: LinkedIn Privacy
Google Ads
Scope: Privacy Policy
Legal entity and address: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Purpose: Advertising, conversion tracking, remarketing, Customer Match/contact-list uploads, Enhanced Conversions and audience measurement
Personal Data typically involved: Cookie/advertising identifiers, IP/device information, browsing and conversion events, hashed first-party contact/conversion data and audience information
GDPR role for this use: Independent-controller/controller-to-controller recipient for relevant advertising processing, with product-specific processor functions for specified customer-provided data
Privacy / legal information: Google Privacy
Internal communication, support and project management
Slack
Scope: Privacy Policy
Legal entity and address: Slack Technologies Limited, Salesforce Tower, Spencer Place, Dublin 1, Co. Dublin, D01 W2Y3, Ireland
Purpose: Internal messaging, collaboration, file sharing and project communication
Personal Data typically involved: Name, work email, messages, files, workspace/account information and activity metadata
GDPR role for this use: Processor for Customer Data; controller for certain account/service information
Privacy / legal information: Slack Privacy
Zoom
Scope: Privacy Policy
Legal entity and address: Zoom Communications, Inc., 55 Almaden Blvd, 6th Floor, San Jose, CA 95113, United States
Purpose: Video meetings, calls, internal/external communication and collaboration
Personal Data typically involved: Name, email, meeting metadata, chat/messages, meeting content and technical data
GDPR role for this use: Processor for customer meeting data; controller for certain account/service data
Privacy / legal information: Zoom Privacy
SAAS First
Scope: Privacy Policy
Legal entity and address: Southern Vector Limited, 26 Applefield Court, Northwood, Christchurch 8051, New Zealand
Purpose: Customer support, CRM, communications and service-management tools
Personal Data typically involved: Name, email, business/contact information, support conversations, CRM records and usage/service information
GDPR role for this use: Processor for end-user/customer data supplied by GBD; controller for its own account, security and service-administration data
Privacy / legal information: SAAS First Privacy
Google Workspace — Gmail, Drive, Meet, Calendar, Docs, Sheets and related Workspace services
Scope: Privacy Policy
Legal entity and address: Google Cloud EMEA Limited, Velasco, Clanwilliam Place, Dublin 2, Ireland
Purpose: Business email, Google Meet video meetings, calendars, Google Drive/document storage, productivity and internal collaboration
Personal Data typically involved: Name, business email, messages, meeting/calendar information, files/documents, contacts and account/usage metadata
GDPR role for this use: Processor for Workspace Customer Data; controller for Google account, security and service-administration data
Privacy / legal information: Google Cloud Privacy
Dropbox
Scope: Privacy Policy
Legal entity and address: Dropbox International Unlimited Company, One Park Place, Floor 6, Hatch Street Upper, Dublin 2, Ireland
Purpose: File storage, sharing, backup and collaboration
Personal Data typically involved: Name, email, files/content, sharing information, account and usage information
GDPR role for this use: Processor for qualifying team/customer data; controller for certain account/service data
Privacy / legal information: Dropbox Privacy