Zonelytix legal
Subprocessors
Version 1.1 · Last updated
Zonelytix uses a small number of specialist providers to run the Service. This page lists every one that processes personal data on our behalf, what it receives and where. It forms part of the Privacy policy.
Contents
1. What a subprocessor is
A subprocessor is a third party that processes personal data on our instructions to deliver part of the Service. Each one is bound by a data processing agreement that limits what it may do with the data to what we tell it, requires appropriate security, and flows down the same obligations to its own providers. Providers that receive no personal data, such as market data feeds, are listed for completeness and marked as such.
2. Current subprocessors
“If enabled” means the provider is used only when configured for the production deployment; the list is updated when that happens. The named hosting, analytics and error monitoring providers and the Supabase region will be stated before launch.
3. Independent controllers you also deal with
Some parties process your data under their own privacy policies rather than on our instructions: Whop for the payment transaction itself, Google when you sign in with Google, Telegram as a messaging platform, your broker, your prop firm, and the blockchain network and stablecoin issuer involved in a reward payout. We do not control their processing, and their policies apply to it.
4. How we add or change one
Before adding a subprocessor that will receive personal data, or materially changing what an existing one receives, we update this page at least 30 days in advance and post the change in the changelog. Members who have asked to be notified by email receive a notice. If you object to a new subprocessor on reasonable data protection grounds and we cannot resolve the objection, you may close your account and the Refund policy applies as for a removed feature. Removals and changes of a provider’s location are recorded here with the date.
5. Safeguards
Where a subprocessor processes data outside the EEA, the UK or Switzerland, we rely on the safeguards described in the Privacy policy: an adequacy decision, the EU-US Data Privacy Framework for certified recipients, or standard contractual clauses with the UK addendum and a transfer risk assessment. Copies are available from privacy@zonelytix.com.