Sub-Processors Registry
Version: 1.1
Effective Date: June 16, 2026
1. Introduction
This page provides a complete and up-to-date list of all authorized Sub-processors engaged by Unistack Software Services - FZCO («Unistack», «we», «us») to process Personal Data on behalf of our clients (Data Controllers) in connection with the provision of our Services.
In accordance with Article 28 of the GDPR and our Data Processing Agreement (DPA), we maintain transparency about the third parties that may have access to your Personal Data. All Sub-processors are contractually obligated to maintain data protection standards no less protective than those described in our Privacy Policy and Trust & Security page.
2. Current List of Authorized Sub-Processors
2.1 Identity Verification and Compliance
| Sub-Processor | Jurisdiction | Purpose of Processing | Categories of Personal Data | Transfer Mechanism |
|---|---|---|---|---|
| Sumsub Inc. | Cayman Islands (with EU entity: Sumsub Ltd., Ireland) | Identity verification, KYC (Know Your Customer), AML (Anti-Money Laundering) screening, document verification, fraud detection | Passport and ID document images, facial biometric data, business registration documents, beneficial ownership information, sanctions/PEP screening data | EU Standard Contractual Clauses (SCCs) + Transfer Impact Assessment (TIA) |
Details:
- Service: Sumsub provides automated identity verification and compliance screening services.
- Data Location: Primary processing occurs in the EU (Ireland) and/or Cayman Islands.
- Security Certifications: ISO 27001, SOC 2 Type II, PCI DSS Level 1.
- Sub-processor List: Sumsub maintains its own sub-processor list at https://sumsub.com.
- Privacy Policy: https://sumsub.com
2.2 Contract and Document Management
| Sub-Processor | Jurisdiction | Purpose of Processing | Categories of Personal Data | Transfer Mechanism |
|---|---|---|---|---|
| OneNDA Ltd. | United Kingdom | Management of Non-Disclosure Agreements (NDAs), electronic signatures, contract lifecycle management | Names, email addresses, job titles, company names, electronic signatures, document metadata | UK Adequacy Decision (EU Commission Decision 2021/1754) / UK IDTA for UK-originated data |
Details:
- Service: OneNDA provides standardized NDA templates and electronic signature workflows.
- Data Location: United Kingdom (with cloud hosting in EU/UK data centers).
- Security Certifications: ISO 27001 (in progress), SOC 2 (in progress).
- Sub-processor List: OneNDA maintains its own sub-processor list at https://www.onenda.com.
- Privacy Policy: https://www.onenda.com
2.3 Cloud Infrastructure and Hosting
| Sub-Processor | Jurisdiction | Purpose of Processing | Categories of Personal Data | Transfer Mechanism |
|---|---|---|---|---|
| Amazon Web Services (AWS) | USA (with EU data centers in Frankfurt, Ireland) | Cloud hosting, data storage, computing infrastructure, content delivery | All categories of Personal Data processed in connection with Services | EU Standard Contractual Clauses (SCCs) + AWS Data Processing Addendum |
Details:
- Service: AWS provides cloud infrastructure, including EC2, S3, RDS, Lambda, and other services.
- Data Location: Clients may select data residency in EU (Frankfurt, Ireland) or UAE regions.
- Security Certifications: ISO 27001, SOC 1/2/3, PCI DSS Level 1, HIPAA, FedRAMP.
- Sub-processor List: AWS maintains its own sub-processor list at https://aws.amazon.com.
- Privacy Policy: https://aws.amazon.com
2.4 Business Communication
| Sub-Processor | Jurisdiction | Purpose of Processing | Categories of Personal Data | Transfer Mechanism |
|---|---|---|---|---|
| Slack Technologies, LLC (Salesforce) | USA | Business communication, team messaging, file sharing | User names, email addresses, message content, file attachments | EU Standard Contractual Clauses (SCCs) + Slack Data Processing Addendum |
Details:
- Service: Slack provides team communication and collaboration platform.
- Data Location: USA (with EU data residency options available).
- Security Certifications: ISO 27001, SOC 1/2/3, PCI DSS Level 1, HIPAA.
- Sub-processor List: Slack maintains its own sub-processor list at https://slack.com.
- Privacy Policy: https://slack.com
2.5 Domain and DNS Management
| Sub-Processor | Jurisdiction | Purpose of Processing | Categories of Personal Data | Transfer Mechanism |
|---|---|---|---|---|
| GoDaddy Operating Company, LLC | USA | Domain name registration, DNS management, SSL certificates | Registrant name, email address, organization name, payment information | EU Standard Contractual Clauses (SCCs) + GoDaddy Data Processing Addendum |
Details:
- Service: GoDaddy provides domain registration and DNS management services.
- Data Location: USA.
- Security Certifications: ISO 27001, SOC 2, PCI DSS Level 1.
- Sub-processor List: GoDaddy maintains its own sub-processor list at https://www.godaddy.com.
- Privacy Policy: https://www.godaddy.com
3. Categories of Sub-Processors
Our Sub-processors fall into the following categories:
| Category | Sub-Processors | Purpose |
|---|---|---|
| Identity Verification & Compliance | Sumsub | KYC/AML verification, fraud detection |
| Contract Management | OneNDA | NDA management, electronic signatures |
| Cloud Infrastructure | AWS | Hosting, storage, computing |
| Communication | Slack | Team messaging, collaboration |
| Domain Management | GoDaddy | DNS, SSL certificates |
4. Notification of Changes
In accordance with our Data Processing Agreement (DPA), we are committed to providing you with advance notice of any changes to this Sub-Processors list.
4.1 Notification Process
- Advance Notice: We will provide at least thirty (30) days' written notice before adding or replacing any Sub-processor.
- Notification Method: Notice will be provided via:
- Email to the primary contact specified in your Agreement;
- Update to this webpage (with revision of the «Last Updated» date);
- For clients with a dedicated account manager, direct communication from the account manager.
4.2 Right to Object
If you object to the engagement of a new or replacement Sub-processor on reasonable data protection grounds:
- Please notify us in writing within fifteen (15) days of receiving notice of the change.
- We will work with you to find an alternative solution, which may include:
- Using a different Sub-processor;
- Implementing additional safeguards;
- Terminating the affected portion of the Agreement (if no reasonable alternative exists).
4.3 Sub-Processor Failure
If a Sub-processor fails to comply with its data protection obligations:
- We will immediately notify you;
- We will take appropriate remedial action, which may include terminating the Sub-processor;
- We remain fully liable to you for the acts and omissions of our Sub-processors, as per our DPA.
5. Due Diligence and Ongoing Monitoring
We conduct rigorous due diligence before engaging any Sub-processor and maintain ongoing monitoring to ensure continued compliance:
5.1 Pre-Engagement Due Diligence
Before engaging a new Sub-processor, we assess:
- Technical and organizational security measures (encryption, access controls, incident response);
- Privacy compliance (GDPR, UAE PDPL, and other applicable laws);
- Security certifications (ISO 27001, SOC 2, PCI DSS, etc.);
- Sub-processor transparency (public sub-processor list, DPA availability);
- Data location and transfer mechanisms (adequacy decisions, SCCs, TIAs);
- Reputation and track record (security incidents, regulatory actions).
5.2 Ongoing Monitoring
We continuously monitor Sub-processor compliance through:
- Annual security reviews of Sub-processor certifications and audit reports;
- Contractual audits (right to audit clauses in all Sub-processor agreements);
- Incident monitoring (tracking security incidents and breach notifications);
- Regulatory updates (monitoring changes in applicable laws and guidance).
6. Data Transfer Mechanisms
For Sub-processors located outside the European Economic Area (EEA), UK, or Switzerland, we ensure appropriate safeguards are in place:
| Transfer Scenario | Legal Mechanism |
|---|---|
| EEA → USA | EU Standard Contractual Clauses (SCCs) + Transfer Impact Assessment (TIA) |
| EEA → UK | UK Adequacy Decision (EU Commission Decision 2021/1754) |
| EEA → Cayman Islands | EU SCCs + TIA |
| UK → USA | UK International Data Transfer Addendum (IDTA) or UK SCCs |
| UK → Third Countries | UK IDTA or UK SCCs |
| UAE → Third Countries | UAE PDPL Art. 22 cross-border transfer requirements |
Transfer Impact Assessments (TIAs): Where required, we conduct TIAs to assess the legal framework of the recipient country and implement supplementary measures where necessary.
7. Your Rights
You have the right to:
- Request information about the Sub-processors engaged to process your Personal Data;
- Object to changes in the Sub-processor list (as described in Section 4.2);
- Request a copy of the safeguards in place for international data transfers;
- Lodge a complaint with a supervisory authority if you believe your rights have been violated.
To exercise these rights, please contact us at privacy@getunistack.com.
8. Contact Information
For questions or requests regarding this Sub-Processors Registry or our data protection practices:
Data Protection Contact: privacy@getunistack.com
EU Representative: eu_rep@getunistack.com
Security Issues: security@getunistack.com
Postal Address:
Unistack Software Services - FZCO
IFZA Business Park, DDP
PO Box 342001
Dubai, United Arab Emirates
9. Changes to This Registry
We may update this Sub-Processors Registry from time to time to reflect changes in our Sub-processor engagements. We will:
- Update the «Last Updated» date at the top of this page;
- Provide advance notice to clients as described in Section 4;
- Maintain a historical record of changes upon request.