Skip to main content

Sub-processors and transfers (Annex III to the DPA)

Version 1.0 — last updated: 2026-10-10

This list forms part of the Data Processing Agreement (DPA) concluded between each business and GD Projects, Lda.. It identifies the providers that process data on behalf of the business in delivering the platform, the role of each one, the data involved, the processing and access locations and the applicable transfer mechanism. The version in force on the date of acceptance is kept with the acceptance evidence.

1. Active providers

The following providers receive data in the current delivery of the platform. Each processes the data only for the stated function, under the data processing agreement that forms part of the service terms contracted by GD Projects, Lda..

Active providers
EntityService and roleData and purposeProcessing and access locationsTransfers outside the EEA
Google Cloud EMEA Limited (Ireland), with Google LLC (United States) and affiliates as sub-processorsGoogle Cloud and Firebase: authentication, database, files, scheduled tasks and encryption keys. Sub-processorAccount and business data stored on the platform, including customers, bookings, professionals, notes and encrypted credentials. Service delivery and securityDatabase in the European eur3 multi-region; files and encryption keys in europe-west1 (Belgium); Firebase Authentication in the United States; provider support access from other countriesGoogle LLC certified under the EU–US Data Privacy Framework; standard contractual clauses in Google's data processing terms
Vercel Inc. (United States)Application hosting and execution. Sub-processorApplication requests and responses in transit and minimised technical logs. Service delivery and securityFunctions run in Frankfurt (Germany); global delivery network; company and support access in the United StatesEU–US Data Privacy Framework certification stated by Vercel; 2021 standard contractual clauses in Vercel's data processing agreement
Cloudflare, Inc. (United States)Turnstile (abuse protection) and technical entry points for callbacks and diagnostics. Processor; for Turnstile signals it also acts as controller under its own noticeIP address and technical browser signals on public forms; technical messages in transit, with no persistent logging configured. Abuse prevention and secure routingCloudflare global network; company in the United StatesStandard contractual clauses and other mechanisms in Cloudflare's data processing agreement
Functional Software, Inc., trading as Sentry (United States)Error and performance diagnostics. Sub-processorMinimised technical events, without contact details, request bodies or cookies. Fault detection and correctionOrganisation in the European Union data region (Germany); company and support access in the United StatesStandard contractual clauses and other mechanisms in Sentry's data processing agreement
Stripe Payments Europe, Limited (Ireland), with Stripe, Inc. (United States) and affiliatesPlatform subscriptions and online booking payments in the business's own Stripe account. Independent controller for financial and fraud-prevention duties; processor where the Stripe contract so providesPayer, payment and billing data. Charging, refunds and compliance with legal obligationsEuropean Union and United States, according to Stripe's infrastructureStripe certified under the EU–US Data Privacy Framework; standard contractual clauses in Stripe's data transfer addendum

2. Planned providers, not yet receiving data

The following providers receive data only after the activation conditions are met and this list is updated under the DPA.

Planned providers, not yet receiving data
EntityPlanned functionStatus
SEND IT — Software e Serviços para Telecomunicações, S. A. (Portugal), Arpoone platformTransactional SMS and email, such as verification codes and booking noticesNot active: no business data is sent
Google, under each user's Google accountGoogle Calendar and Google Meet, through a professional's voluntary connectionNo general use; depends on the connection and on the terms of the user's Google account

3. Changes and information

Additions or replacements follow the sub-processor section of the DPA, with at least thirty days' written notice and a right to object on reasoned grounds. Providers that GD Projects, Lda. uses only for its own invoicing and correspondence, such as Google Workspace, Kapta and Moloni, do not process data on behalf of businesses and are recorded in its own processing register.

You can request a copy of the applicable safeguards at geral@tamarcado.pt.