GDPR Compliance & Data Transparency

List of Subprocessors

Last Updated: July 2026 • GDPR Article 28 Compliance Standard

Third-Party Data Processor Policy

To deliver Safa's digital wallet and attendance services, we engage specialized third-party service providers (subprocessors) to perform data processing activities. Under GDPR Article 28 and our Data Processing Addendum (DPA), all subprocessors listed below undergo rigorous security vetting and are contractually bound to process data solely in accordance with Safa's strict privacy instructions.

Supabase, Inc.

Jurisdiction: USA
Verified

Primary database hosting, PostgreSQL storage, and user authentication infrastructure

Stripe, Inc.

Jurisdiction: USA
Verified

Payment processing, customer billing portal, and subscription management

Resend, Inc.

Jurisdiction: USA
Verified

Transactional email notifications, parental clearance alerts, and welcome dispatches

Pusher, Inc.

Jurisdiction: USA
Verified

Real-time websocket infrastructure for live kiosk check-in activity streaming

Google, LLC

Jurisdiction: USA
Verified

Federated authentication (Google OAuth) and artificial intelligence processing (Gemini API)

Vercel, Inc.

Jurisdiction: USA
Verified

Web application hosting, serverless edge function execution, and global CDN delivery

Subprocessor Updates & Notification Rights

Safa maintains an up-to-date registry of subprocessors on this page. Subscribers and enterprise data controllers have the right to receive notification of any planned changes to our subprocessor list prior to the engagement of new data handlers.