← Governance framework
Platform Operations

Vendor and Sub-processor Management Policy

Due diligence, contractual safeguards and ongoing oversight for third-party vendors and sub-processors.

Version
v1.0
Effective
2026-07-19
Last reviewed
2026-07-19
Next review
2027-07-19
Owner
Compliance Lead
Approver
Executive Team
Anchored by content hashissued 2026-07-29
Payload hash
07a4548b9740c574faef9b4a9bd80ba8f59ecee395dd7c9b96b1e940abd17475
SHA-256 digest of the receipt content
Issuer AID
EP1_FGkcwfHAuih6VUzv9kgAVBvvSoaswSUao61lkxhE
Party that issued this receipt
ImpactMiles handle
audit:governance:07a4548b9740c574

This receipt is anchored by content hash. A resolvable credential SAID is not available for this record.

Applies to

  • All vendors with access to production data or systems

Jurisdictions

  • Hong Kong (PDPO, IRD s.88)
  • United Kingdom (UK GDPR, DPA 2018)
  • European Union (GDPR)
  • Singapore (PDPA)
  • Australia (Privacy Act 1988)
  • Japan (APPI)
  • Wider APAC per country taxonomy

How this is applied in-product

  • Public sub-processor register
  • DPA in place before production access
  • Annual vendor risk review

1. Onboarding

  • Security and privacy assessment before contract signature.
  • DPA with Standard Contractual Clauses where personal data crosses borders.
  • Named business owner for each vendor.

2. Current Sub-processors

  • Lovable Cloud (Supabase) - hosting, database, auth, storage.
  • TAS operator - KERI issuance and verification.
  • Veraf.ai - KYB and AML screening.
  • Payment gateway providers - configured per region in payment_gateways.
Questions or concerns about this policy? Contact the DPO.

Related policies