Subprocessors and Data Flow

Attached you find a list of all subprocessors of the products and services provided by the Interactive Paper GmbH.

Company Name
Company Location
Importance
Service
Data Location
Data Categories
Hetzner Online GmbH
Industriestr. 25 91710 Gunzenhausen, Germany
Mandatory
Hosting provider
Germany
Personal Data as determined by the Controller
DigitalOcean EU B.V. - Zweigniederlassung Deutschland
Am Sandtorkai 68, 20457 Hamburg, Germany
Mandatory
Hosting and infrastructure services for storing and processing data.
Germany (DigitalOcean Data Center)
Personal Data as determined by the Controller.
Grunewald GmbH
Lindenbergstraße 4434123 Kassel, Germany
Optional, only if address data is exchanged
Production partner / processing of address data for postal dispatch
Germany
Address data of end-users
Oliver Homrich e.K.
Siegener Straße 41157258 Freudenberg, Germany
Optional, only if address data is exchanged
Production partner / processing of address data for postal dispatch
Germany
Address data of end-users
Artisan Colour
8970 E Bahia Dr, Scottsdale, AZ 85260, United States
Optional, only if address data is exchanged and mailed out in the United States
Production partner / processing of address data for postal dispatch
United States
Address data of end-users Transfer basis: EU Standard Contractual Clauses (Art. 46(2)(c) GDPR), Commission Decision 2021/914.
Sentry (Functional Software, Inc.)
45 Fremont Street, San Francisco, CA 94105, United States
Mandatory
Error monitoring and crash reporting. Processes error stack traces which may incidentally contain personal data (e.g. user IDs, email addresses in error messages). Used whenever an unhandled error or exception occurs in any Interactive Paper application.
United States
Technical error data, which may incidentally include user identifiers, IP addresses, or other personal data present in error context. Transfer basis: EU Standard Contractual Clauses (Art. 46(2)(c) GDPR), Commission Decision 2021/914.
Stripe, Inc.
354 Oyster Point Blvd, South San Francisco, CA 94080, United States
Mandatory, only if client uses paid subscription
Payment processing and subscription billing. Used when a client purchases or renews a paid subscription plan on the  letsinteract.com  platform. Processes billing name, email, and payment card data.
United States (Stripe also has EU infrastructure via Stripe Payments Europe, Ltd., Dublin)
Billing contact name, email address, payment card data (tokenised), billing address, subscription details. Transfer basis: EU Standard Contractual Clauses (Art. 46(2)(c) GDPR), Commission Decision 2021/914.
Google LLC (Google Analytics 4)
1600 Amphitheatre Parkway, Mountain View, CA 94043, United States
Mandatory (analytics enabled)
Web analytics and usage tracking for the Creator platform. Collects anonymised usage data (page views, session duration, feature interactions) to understand platform usage patterns. Active whenever a logged-in user interacts with the Creator application.
United States
Pseudonymised user identifiers, IP addresses (anonymised), browser/device data, page URLs, session and interaction events. Transfer basis: EU Standard Contractual Clauses (Art. 46(2)(c) GDPR), Commission Decision 2021/914.
Google LLC (Google OAuth / SSO)
1600 Amphitheatre Parkway, Mountain View, CA 94043, United States
Optional, only if user selects Google login
Single Sign-On (SSO) authentication via Google OAuth 2.0. Used when a platform user chooses to log in to the Creator application using their Google account. Transfers name, email address and Google account identifier upon login.
United States
Name, email address, Google account identifier. Transfer basis: EU Standard Contractual Clauses (Art. 46(2)(c) GDPR), Commission Decision 2021/914.
LinkedIn Corporation
1000 West Maude Avenue, Sunnyvale, CA 94085, United States
Optional, only if user selects LinkedIn login
Single Sign-On (SSO) authentication via LinkedIn OAuth 2.0. Used when a platform user chooses to log in to the Creator application using their LinkedIn account. Transfers name, email address and LinkedIn profile ID upon login.
United States
Name, email address, LinkedIn profile identifier. Transfer basis: EU Standard Contractual Clauses (Art. 46(2)(c) GDPR), Commission Decision 2021/914.
Microsoft Corporation (Azure AD / Entra ID)
One Microsoft Way, Redmond, WA 98052, United States
Optional, only if user selects Microsoft/Azure AD login
Enterprise Single Sign-On via Microsoft Azure Active Directory (Entra ID). Used when a corporate user logs in to the Creator application using their company Microsoft account. Primarily used by enterprise clients with Microsoft 365 tenants.
United States (EU data residency available via Microsoft EU Data Boundary)
Name, email address, Microsoft/Azure AD account identifier, tenant ID. Transfer basis: EU Standard Contractual Clauses (Art. 46(2)(c) GDPR), Commission Decision 2021/914.
WeClapp GmbH
Lauteschlägerstraße 23, 64289 Darmstadt, Germany
Mandatory, only if client has a paid subscription or purchase order
ERP system used for invoicing, customer account management, and accounting. Client contact and billing data is transferred to WeClapp when a subscription is created, renewed, or a purchase order is issued. Data remains within the EU (Germany).
Germany (EU)
Client company name, billing contact name, email address, postal address, VAT number, subscription/order details. No transfer outside the EEA — no SCCs required.
Google LLC (Gmail API — Transactional Email)
1600 Amphitheatre Parkway, Mountain View, CA 94043, United States
Mandatory
Transactional email delivery via Gmail API service account. Used to send platform-triggered emails such as campaign invitations, account registration confirmations, and access notifications to end-users and platform users.
United States
Recipient email addresses, name (where included in email), email subject and body content of platform notifications. Transfer basis: EU Standard Contractual Clauses (Art. 46(2)(c) GDPR), Commission Decision 2021/914.

PDF document 228KB
It appears you do not have a PDF plugin for this browser.