Sub-processors and transfers (Annex III to the DPA)
Version 1.0 — last updated: 2026-10-10
This list forms part of the Data Processing Agreement (DPA) concluded between each business and GD Projects, Lda.. It identifies the providers that process data on behalf of the business in delivering the platform, the role of each one, the data involved, the processing and access locations and the applicable transfer mechanism. The version in force on the date of acceptance is kept with the acceptance evidence.
1. Active providers
The following providers receive data in the current delivery of the platform. Each processes the data only for the stated function, under the data processing agreement that forms part of the service terms contracted by GD Projects, Lda..
| Entity | Service and role | Data and purpose | Processing and access locations | Transfers outside the EEA |
|---|---|---|---|---|
| Google Cloud EMEA Limited (Ireland), with Google LLC (United States) and affiliates as sub-processors | Google Cloud and Firebase: authentication, database, files, scheduled tasks and encryption keys. Sub-processor | Account and business data stored on the platform, including customers, bookings, professionals, notes and encrypted credentials. Service delivery and security | Database in the European eur3 multi-region; files and encryption keys in europe-west1 (Belgium); Firebase Authentication in the United States; provider support access from other countries | Google LLC certified under the EU–US Data Privacy Framework; standard contractual clauses in Google's data processing terms |
| Vercel Inc. (United States) | Application hosting and execution. Sub-processor | Application requests and responses in transit and minimised technical logs. Service delivery and security | Functions run in Frankfurt (Germany); global delivery network; company and support access in the United States | EU–US Data Privacy Framework certification stated by Vercel; 2021 standard contractual clauses in Vercel's data processing agreement |
| Cloudflare, Inc. (United States) | Turnstile (abuse protection) and technical entry points for callbacks and diagnostics. Processor; for Turnstile signals it also acts as controller under its own notice | IP address and technical browser signals on public forms; technical messages in transit, with no persistent logging configured. Abuse prevention and secure routing | Cloudflare global network; company in the United States | Standard contractual clauses and other mechanisms in Cloudflare's data processing agreement |
| Functional Software, Inc., trading as Sentry (United States) | Error and performance diagnostics. Sub-processor | Minimised technical events, without contact details, request bodies or cookies. Fault detection and correction | Organisation in the European Union data region (Germany); company and support access in the United States | Standard contractual clauses and other mechanisms in Sentry's data processing agreement |
| Stripe Payments Europe, Limited (Ireland), with Stripe, Inc. (United States) and affiliates | Platform subscriptions and online booking payments in the business's own Stripe account. Independent controller for financial and fraud-prevention duties; processor where the Stripe contract so provides | Payer, payment and billing data. Charging, refunds and compliance with legal obligations | European Union and United States, according to Stripe's infrastructure | Stripe certified under the EU–US Data Privacy Framework; standard contractual clauses in Stripe's data transfer addendum |
2. Planned providers, not yet receiving data
The following providers receive data only after the activation conditions are met and this list is updated under the DPA.
| Entity | Planned function | Status |
|---|---|---|
| SEND IT — Software e Serviços para Telecomunicações, S. A. (Portugal), Arpoone platform | Transactional SMS and email, such as verification codes and booking notices | Not active: no business data is sent |
| Google, under each user's Google account | Google Calendar and Google Meet, through a professional's voluntary connection | No general use; depends on the connection and on the terms of the user's Google account |
3. Changes and information
Additions or replacements follow the sub-processor section of the DPA, with at least thirty days' written notice and a right to object on reasoned grounds. Providers that GD Projects, Lda. uses only for its own invoicing and correspondence, such as Google Workspace, Kapta and Moloni, do not process data on behalf of businesses and are recorded in its own processing register.
You can request a copy of the applicable safeguards at geral@tamarcado.pt.