Sub-processors
The third-party services that handle personal data on our behalf across this website and our applications: what each one does, where it processes data, how long it keeps it, and the mechanism relied on for transfers out of the EEA.
- Effective
- Last updated
- Version
- 1.0.0
What a sub-processor is Link to this section: What a sub-processor is
A sub-processor is a third party that handles personal data on our behalf, under our instructions — a hosting provider, an email service, the hosted model behind an AI feature. They are not free to use the data for their own purposes.
The GDPR requires us to be able to say who they are. This page is that list, and it is what the sharing section of the privacy policy refers to. It covers this website and our applications.
None of the applications has been released, so the rows below describe what a released application will rely on rather than something already running. Each is a placeholder until the provider is chosen and the contract is signed. Naming a likely candidate now would be a guess dressed as a fact.
Current sub-processors Link to this section: Current sub-processors
| Provider | What it does | Data it sees | Processing location | Retention | Transfer mechanism |
|---|---|---|---|---|---|
| [HOSTING_PROVIDER] — this detail has not been filled in yet | Serves this website; keeps server logs. | IP address, user agent, requested URL, timestamp. | [HOSTING_REGION] — this detail has not been filled in yet | As retained by the provider, to be confirmed and then stated here. | To be confirmed with the provider — Data Privacy Framework certification or Standard Contractual Clauses. |
| [EMAIL_PROVIDER] — this detail has not been filled in yet | Delivers contact form enquiries to us. | Everything you put in the contact form, plus your email address. | [EMAIL_PROVIDER_REGION] — this detail has not been filled in yet | Two years from our last exchange, matching the privacy policy. | To be confirmed with the provider — Data Privacy Framework certification or Standard Contractual Clauses. |
| [MODEL_PROVIDER] — this detail has not been filled in yet | Runs the hosted model behind application features that do not run on your device. | Whatever you submit to a hosted feature — the text, image or audio you give it, and whatever the feature attaches as context. | [MODEL_PROVIDER_REGION] — this detail has not been filled in yet | [MODEL_INPUT_RETENTION] — this detail has not been filled in yet | To be confirmed with the provider — Data Privacy Framework certification or Standard Contractual Clauses. |
| A crash and diagnostics provider, not yet chosen. | Records what an application was doing when it crashed, so the fault can be found and fixed. | Device model, operating system version, application version, the crash trace, and a generated install identifier. Not your name, and not the content you were working on. | To be confirmed when the provider is chosen. | To be set at the shortest period that still allows a crash to be diagnosed. | To be confirmed with the provider — Data Privacy Framework certification or Standard Contractual Clauses. |
The app stores are not sub-processors Link to this section: The app stores are not sub-processors
Distribution is planned through the App Store and Google Play. When an application is published there, Apple and Google handle the download, the store account, and any purchase or subscription themselves.
They do that as independent controllers: for their own purposes, under their own privacy policies, and not on our instructions. That is why they are in a separate table. It is a distinction people usually skip past, and it matters at the exact moment it is inconvenient — we cannot instruct either company to delete, correct or export what they hold about you, because it was never ours to instruct. Those requests go to them.
| Party | What it handles | Our relationship to it |
|---|---|---|
| Apple | App Store distribution, the store account, purchases, subscriptions and receipts. | Independent controller. We receive sales and payout reporting, not your payment details. |
| Google Play distribution, the store account, purchases, subscriptions and receipts. | Independent controller, on the same basis. |
Where a product is free and takes no payment, there is nothing for them to process on the purchase side. The store still handles the download and the store account, and that part is still theirs rather than ours.
Business customers under a contract or a licence are billed by us directly rather than through a store, so nothing on this list applies to that route. What we hold and why is set out in the privacy policy and in the agreement itself.
What we require of them Link to this section: What we require of them
Before a provider is added:
- There is a written contract with the data protection terms Article 28 requires.
- The transfer mechanism for any data leaving the EEA is identified specifically for that provider, not assumed in general.
- The security measures are appropriate to the data involved.
- They are permitted to engage their own sub-processors only under equivalent terms.
- For a model provider, whether anything sent to it may be used to train its own models is answered in writing before it is used, not inferred from a marketing page. The answer we require is: [MODEL_TRAINING_POSITION] — this detail has not been filled in yet.
Changes and objections Link to this section: Changes and objections
To be told when this list changes, email contact@littlestone.world and ask to be added to the notification list.
For business customers with a data processing agreement, the notice period and objection rights in that agreement apply. Where it is silent, we will give thirty days' notice before a new sub-processor starts handling personal data, and you may object during that period.
The "last updated" date at the top moves whenever this page changes. That is enforced by the build rather than left to memory.