Subprocessor List
Version 1.4 · Effective date: 12 September 2026 · Governing law: Scotland
General authorisation
This list identifies providers that may process personal data for AppGantry's Service. It forms Annex 3 to the Data Processing Agreement with which it is supplied or otherwise made available. A provider is used only where its function or the relevant feature is required.
1 Current subprocessors and recipients
| Provider | Role | Data involved | Processing location | Transfer approach |
| Microsoft Azure | Hosting, compute, databases, artifact storage, monitoring, secrets and infrastructure | Account, Customer Content, Build artifacts, operational logs, identifiers and service data | Provider locations configured for the Service; no hosting region is stated | Adequacy where applicable; approved contractual safeguards and supplementary measures for restricted transfers |
| Paddle | Merchant of Record; checkout, payment, subscription, billing, fraud and tax | Identity/contact, transaction, subscription, device/network and fraud-prevention data | Locations used by Paddle and its providers | Paddle's lawful transfer mechanisms; Paddle may be an independent controller for its obligations |
| SMTP2GO | Transactional email delivery | Recipient name/address, message content, delivery and network metadata | Provider processing locations | Adequacy or approved contractual safeguards as applicable |
| Brevo (Sendinblue) | Transactional email delivery | Recipient name/address, message content, delivery and network metadata | Provider processing locations | Adequacy or approved contractual safeguards as applicable |
| bunny.net | CDN for static assets, avatars and documentation where enabled | IP/network request data and requested assets; avatar or documentation content | Provider edge and processing locations | Adequacy or approved contractual safeguards as applicable |
| Sentry EU | Error and performance monitoring | Error, trace, device/browser, network and diagnostic context, subject to redaction | European Union environment | UK adequacy for EEA processing; safeguards for any onward restricted transfer |
| PostHog EU | Server-side feature flags only; not browser analytics capture | Service identifiers, feature-flag context and limited operational data | European Union environment | UK adequacy for EEA processing; safeguards for any onward restricted transfer |
| hCaptcha | Abuse and automated-traffic prevention when enabled | IP address, user-agent, interaction and challenge data | Provider processing locations | Adequacy or approved contractual safeguards as applicable |
2 Customer-controlled storage
Where an Enterprise Customer enables bring-your-own-storage ("BYOSA"), Customer's own Microsoft Azure tenant stores Build artifacts. That Azure relationship is selected and controlled by Customer and is not an AppGantry-appointed subprocessor for the Customer's tenant. AppGantry retains Build metadata and encrypted or sealed access configuration required to operate the integration.
3 Customer-selected recipients
Where Customer configures App Store Connect, Google Play, Microsoft Intune or Enterprise BYOSA, AppGantry sends or stores data using Customer credentials at Customer's direction. Apple device provisioning may transmit a device identifier, name, model and operating-system information. These providers are Customer-selected recipients, not AppGantry-appointed subprocessors for that activity. Their processing is governed by Customer's arrangements with them.
4 Changes and objections
AppGantry has general authorisation to appoint subprocessors under the DPA. We will give advance notice by email or in the Service of an intended new or replacement subprocessor. For processing subject to the incorporated SCCs, notice will be given at least 30 days before appointment unless Customer expressly agrees to a shorter period. For other processing, notice will normally be at least 30 days where practicable. The notice will identify the provider, function and intended effective date.
Customer may object during the notice period on reasonable, documented data-protection grounds by emailing contact@appgantry.com. AppGantry and Customer will work in good faith on a commercially reasonable solution. The remedies and limits in the DPA apply.
Emergency replacement or use on shorter notice may be necessary for processing not subject to the incorporated SCCs to protect security, maintain service continuity, comply with law or respond to a provider's unexpected cessation. We will notify Customer as soon as reasonably practicable.
The legal entity, processing locations and applicable transfer mechanism for a listed provider are available on request from contact@appgantry.com.
5 Version history and contact
Version 1.4 has proposed effective date 12 September 2026. Future versions will identify their own version and effective date. Questions and objections should be sent to contact@appgantry.com.
Questions about this document? support@appgantry.com.