Bank Data Privacy policy.
Sub-processor List — Sligo Data Solutions
Last updated: [03-09-2026]
Under GDPR Article 28(2), Sligo Data Solutions, as processor, discloses the following sub-processors engaged in providing the Platform to its clients (data controllers).
| Sub-Processor | Purpose | Physical Storage Location | Data Transfer Outside EU? | Legal Transfer Safeguard |
|---|---|---|---|---|
| Supabase | Database, authentication, backend hosting | EU Region — Germany | No | N/A — data remains in the EEA |
| Stripe | Payment processing (via Stripe Connect; each client's payments settle to their own connected Stripe account) | United States | Yes | EU-U.S. Data Privacy Framework & Standard Contractual Clauses |
| Resend | Transactional email (booking/class reminders) | United States | Yes | EU-U.S. Data Privacy Framework & Standard Contractual Clauses |
| Enable Banking | Open banking / bank transaction sync for the client's own business account | EU | No | N/A |
| Netlify | Frontend static hosting | N/A — no personal data stored; API calls go directly to Supabase | N/A | N/A |
Sligo Data Solutions will notify clients of any change to this list, consistent with the terms of the Data Processing Agreement, before the change takes effect.
Also in place: Sligo Data Solutions has requested/holds Supabase's own Data Processing Agreement, covering Supabase's role as sub-processor to Sligo Data Solutions.