← Governance framework
Platform Operations
Vendor and Sub-processor Management Policy
Due diligence, contractual safeguards and ongoing oversight for third-party vendors and sub-processors.
- Version
- v1.0
- Effective
- 2026-07-19
- Last reviewed
- 2026-07-19
- Next review
- 2027-07-19
- Owner
- Compliance Lead
- Approver
- Executive Team
Anchored by content hashissued 2026-07-29
Payload hash
07a4548b9740c574faef9b4a9bd80ba8f59ecee395dd7c9b96b1e940abd17475SHA-256 digest of the receipt content
Issuer AID
EP1_FGkcwfHAuih6VUzv9kgAVBvvSoaswSUao61lkxhEParty that issued this receipt
ImpactMiles handle
audit:governance:07a4548b9740c574This receipt is anchored by content hash. A resolvable credential SAID is not available for this record.
Applies to
- All vendors with access to production data or systems
Jurisdictions
- Hong Kong (PDPO, IRD s.88)
- United Kingdom (UK GDPR, DPA 2018)
- European Union (GDPR)
- Singapore (PDPA)
- Australia (Privacy Act 1988)
- Japan (APPI)
- Wider APAC per country taxonomy
How this is applied in-product
- Public sub-processor register
- DPA in place before production access
- Annual vendor risk review
1. Onboarding
- Security and privacy assessment before contract signature.
- DPA with Standard Contractual Clauses where personal data crosses borders.
- Named business owner for each vendor.
2. Current Sub-processors
- Lovable Cloud (Supabase) - hosting, database, auth, storage.
- TAS operator - KERI issuance and verification.
- Veraf.ai - KYB and AML screening.
- Payment gateway providers - configured per region in payment_gateways.
Questions or concerns about this policy? Contact the DPO.