Subprocessors
OpenApp uses the following processors to operate the Service. This list is the customer-facing register for organization customers under the Data Processing Agreement.
Privacy contact: tomer+privacy@openapp.house.
OpenApp-operated production hosting is Amazon Web Services region eu-central-1.
Customer-connected products are listed separately: OpenApp does not operate their infrastructure and does not assert where those vendors store data.
| Processor | Role | Personal data involved | Location / transfer | Transfer tool |
|---|---|---|---|---|
| Amazon Web Services | Compute, PostgreSQL, object storage, logs, email/SMS when configured (Simple Email Service / Simple Notification Service) | Account, directories, media, audit, operational logs | eu-central-1 (primary) |
Not a restricted transfer for EU hosting |
| Google (Identity) | Optional sign-in | Name, email, provider identifiers | Extra-European Economic Area as Google operates | Standard Contractual Clauses and/or EU–US Data Privacy Framework if Google participates |
| Google Maps / Geocoding | Address autocomplete (browser) and server geocoding when the Controller stores a site address | Addresses, coordinates | Extra-European Economic Area as Google operates | Standard Contractual Clauses and/or Data Privacy Framework if participating |
| Google Gemini API | Optional directory photo enrich when the Controller enables it with an API key | Photos the operator submits for analysis (OpenApp does not retain those photos) | Extra-European Economic Area as Google operates | Standard Contractual Clauses and/or Data Privacy Framework if participating |
| Apple Push Notification service | Native incoming-call alerts on iOS | Device token, caller label (building / apartment) | Extra-European Economic Area as Apple operates | Standard Contractual Clauses and/or vendor terms |
| Firebase Cloud Messaging (Google) | Native incoming-call alerts on Android | Device token, caller label | Extra-European Economic Area as Google operates | Standard Contractual Clauses and/or Data Privacy Framework if participating |
| Web Push (VAPID) | Browser call notifications | Push subscription endpoint | First-party / browser vendor | Necessary for the notification the user enabled |
Not OpenApp subprocessors (customer-connected)
| Product | How it is used | Data categories that may leave OpenApp | Storage location |
|---|---|---|---|
| PalGate Cloud (palgate.com) | Gate / garage integration the Controller links | Phone numbers and directory fields the integration syncs, plus commands the Controller triggers | Not specified by OpenApp. Governed by PalGate Cloud. |
| Other hardware or cloud integrations the Controller enables | Per integration | Categories required to operate that connector | Vendor's terms |
| Customer audit webhooks | Optional HMAC-signed POST of audit events to a URL the Controller sets | Event JSON the Controller chooses to send | Controller's destination; Controller is controller of that transfer |
ICE / WebRTC
Live intercom uses WebRTC. OpenApp does not fall back to Google STUN servers. Interactive Connectivity Establishment (ICE) servers must be configured for the deployment (for example an EU TURN/STUN service). If none are configured, the client does not send session candidates to Google.
Changes
Material additions will be posted here. Organization customers may object as described in the Data Processing Agreement.