A sub-processor is a third party that processes personal data on our behalf so that Ihjiz can run. This is the complete list. Many entries are active only when a business switches the corresponding feature on; a business that never connects Telegram, for example, never sends anything to Telegram.
We notify account owners by email and in the platform at least 30 days before adding a sub-processor that will handle Business Data. Objection rights are described in section 3 of the Data Processing Addendum. Entries marked [to confirm] await a final deployment decision and will be filled in before launch.
1.Infrastructure
| Provider | Purpose | Data | Location | Active |
|---|---|---|---|---|
| Render Services, Inc. | Application hosting (API and web apps) | All data in transit through the application | [region to confirm] | Always |
| Neon, Inc. | Managed PostgreSQL database | All stored Business Data and account data | [region to confirm] | Always |
| [S3-compatible object storage provider] | Uploaded files, generated PDFs and exports | Files, invoices, reports | [region to confirm] | Always |
2.Messaging channels
| Provider | Purpose | Data | Location | Active |
|---|---|---|---|---|
| Meta Platforms, Inc. / Meta Platforms Ireland Ltd | WhatsApp Business Platform, Instagram messaging, Messenger | Message content, phone numbers or handles, delivery status | United States, Ireland | When a business connects a WhatsApp, Instagram or Facebook account |
| Telegram FZ-LLC | Telegram Bot API | Message content, Telegram user IDs | United Arab Emirates, distributed | When a business connects a Telegram bot |
| Twilio Inc. | SMS delivery and one-time codes | Phone numbers, message text | United States | When SMS is enabled with Twilio |
| Vonage (Ericsson) | SMS delivery | Phone numbers, message text | United States, United Kingdom | When SMS is enabled with Vonage |
| Bird (formerly MessageBird) | SMS delivery | Phone numbers, message text | Netherlands | When SMS is enabled with Bird |
| Resend, Inc. | Transactional and campaign email | Email addresses, message content, delivery events | United States | When email is enabled with Resend |
| Twilio SendGrid | Transactional and campaign email | Email addresses, message content, delivery events | United States | When email is enabled with SendGrid |
| Mailgun (Sinch) | Transactional and campaign email | Email addresses, message content, delivery events | United States, European Union | When email is enabled with Mailgun |
| Google LLC — Firebase Cloud Messaging | Push notifications to the staff mobile app and web | Device tokens, notification text | United States | When push notifications are enabled |
| Apple Inc. — Apple Push Notification service | Push notifications to iOS devices | Device tokens, notification text | United States | When the iOS staff app is used |
3.Payments
Card details are entered directly with the provider and never reach Ihjiz. Each business connects its own account; Ihjiz is not the merchant of record.
| Provider | Purpose | Data | Location | Active |
|---|---|---|---|---|
| Stripe, Inc. / Stripe Payments Europe | Card payments, payouts (Stripe Connect), Ihjiz subscription billing | Payer name, email, amount, payment status; card data held by Stripe only | United States, Ireland | Subscription billing always; customer payments when a business connects Stripe |
| HyperPay (Mada, STC Pay, cards) | Customer payments | Payer name, amount, payment status | Saudi Arabia | When a business connects HyperPay |
| Tap Payments | Customer payments | Payer name, amount, payment status | Kuwait, Saudi Arabia, United Arab Emirates | When a business connects Tap |
| PayPal Holdings, Inc. | Customer payments | Payer name, email, amount, payment status | United States, Luxembourg | When a business connects PayPal |
4.AI assistant
Off by default. When a business enables the AI agent or assistant, the customer's message and the records needed to answer it are sent to the provider that business selected. We use the providers' business API tiers. Google, Anthropic and OpenAI state that content submitted through those APIs is not used to train their models; DeepSeek's standard terms do not offer the same commitment, so a business selecting DeepSeek should review them.
| Provider | Purpose | Data | Location | Active |
|---|---|---|---|---|
| Google LLC — Gemini API | AI replies and assistant | Conversation text, relevant booking and service data | United States | When selected by the business |
| Anthropic, PBC | AI replies and assistant | Conversation text, relevant booking and service data | United States | When selected by the business |
| OpenAI, L.L.C. | AI replies and assistant | Conversation text, relevant booking and service data | United States | When selected by the business |
| DeepSeek | AI replies and assistant | Conversation text, relevant booking and service data | China | When selected by the business |
5.Other services
| Provider | Purpose | Data | Location | Active |
|---|---|---|---|---|
| Google LLC — Calendar API | Two-way calendar synchronisation | Appointment times and titles for staff who connect a Google account | United States | When a staff member connects Google Calendar |
| Google LLC, Meta Platforms — Sign in | Social sign-in | Name, email, provider account ID | United States, Ireland | When a user signs in with Google or Facebook |
| OpenStreetMap Foundation (Nominatim, tiles) | Address lookup and map display | Business addresses; the viewer's IP address when a map is shown | United Kingdom, distributed | When a business sets a location or shows a map |
| Google LLC — Fonts | Typefaces on the website and app | Viewer's IP address and request headers | United States | Always |
| Adobe Inc. — Fonts | Typefaces in the app | Viewer's IP address and request headers | United States | Always, in the app |
| Cloudflare, Inc. — cdnjs | Open-source libraries in the app | Viewer's IP address and request headers | Distributed | Always, in the app |
6.Changes to this list
This page is the record of changes. When we add, replace or remove a sub-processor we update the table and the date at the top, and we notify account owners as described above. Questions: privacy@ihjiz.co.