Legal — 09
Sub-processors
This page lists the sub-processors that Sammes engages to run its apps and website, what each one does, the categories of data involved, and where the data is processed. It also explains how we tell you about changes and how you can object.
1. What a sub-processor is
A sub-processor is a third party that a data controller, or a processor acting for a controller, engages to process personal data on the controller's behalf. In plain terms, it is a supplier that touches personal data so that a service can be delivered: the servers an app runs on, the service that sends an email, or the tool that shows a crash report.
This page lists the sub-processors that SAMMES AS engages for its three apps (Connect, Intel and Social) and for the website at sammes.no. It is maintained as part of our transparency obligations under Article 28 of the GDPR.
2. Our role
For the personal data in your account, SAMMES AS is the controller. We decide why and how that data is processed, and we are responsible for it.
Where one of our business customers uses Sammes to process data about its own end users, Sammes may act as a processor for that customer. In those cases the customer is the controller, and we engage the sub-processors below under a data processing agreement.
We flow the same obligations down to every sub-processor. Each one may process personal data only on our documented instructions, only for the purpose we specify, and under confidentiality and security obligations that are at least as protective as our own. We remain accountable to you for our sub-processors' performance. Our Privacy Policy explains the wider data picture, including the legal bases we rely on and the rights you have.
3. Changes and your right to object
We notify you before we add or replace a sub-processor, so that you have a genuine opportunity to object.
- Notice period: 30 days. We give at least 30 days' notice of any new or replacement sub-processor.
- How we notify. We publish the change on this page and, where you have a contract or an account with us, we notify the contact we hold for you by email.
- Your right to object. If you reasonably object to a change, tell us within the 30-day notice period. We will discuss the change with you in good faith and look for a workable solution. If we cannot resolve the objection and you do not want to continue with the change, you may terminate the affected part of the service.
- Urgent changes. In rare cases we may need to act more quickly, for example to close a security gap. If that happens, we will tell you as soon as possible afterwards.
4. Current sub-processors
Our default is that production data is hosted and processed within the European Economic Area (EEA). The table below states what each sub-processor does, the categories of personal data involved, and where the data is processed. Where a sub-processor is outside the EEA, the safeguards are described in section 5.
| Sub-processor | Purpose | Data categories | Location |
|---|---|---|---|
| Amazon Web Services EMEA SARL | Cloud hosting, storage and infrastructure for the platform | Account data, device data, application content and backups | Sweden (Stockholm) and Ireland, within the EEA |
| BunnyWay d.o.o. (Bunny.net) | Content delivery and network protection for the website and media | IP addresses, request metadata and security events | Slovenia, within the EEA |
| Sendinblue SAS (Brevo) | Transactional and notification email delivery | Name, email address and delivery metadata | France, within the EEA |
| Google Ireland Limited (Firebase Cloud Messaging) | Push notification delivery to mobile devices | Device push token and notification payload | Ireland, within the EEA |
| Plausible Insights OÜ (Plausible Analytics) | Privacy-friendly, cookieless product analytics | Aggregated usage events; no cookies and no cross-site identifiers | Estonia, within the EEA |
| Functional Software, Inc. (Sentry) | Error and crash monitoring for the apps | Diagnostic and error data, IP address, user and device identifiers | United States, outside the EEA (see section 5) |
| Apple Distribution International Ltd. | In-app purchase and subscription payment processing | Purchase and subscription records; no full card data | Ireland, within the EEA, with limited processing in the United States under safeguards |
| Crisp IM SAS (Crisp) | Customer support inbox and messaging | Name, email address and support conversation content | France, within the EEA |
Apple and Google also process payment and subscription data as independent controllers under their own privacy policies; where they do so, they are not acting as our sub-processors.
5. International transfers
Our production data is hosted within the EEA. A small number of the sub-processors above are established outside the EEA, or have group companies and support functions outside it.
Where personal data is transferred outside the EEA, we put appropriate safeguards in place:
- The transfer is covered by the European Commission's Standard Contractual Clauses (SCCs), approved by Commission Implementing Decision (EU) 2021/914.
- We carry out a transfer impact assessment for each such sub-processor, and we review the assessment when the law or the practical risk changes.
- We apply supplementary measures where they are needed, such as encryption in transit and at rest, access controls, and minimising the data that leaves the EEA.
- The sub-processor must tell us if it can no longer meet these obligations, and we must be able to remove or replace it if that happens.
You can ask for more detail about the safeguards for a specific sub-processor by emailing [email protected].
6. Contact
Questions about this page, about a specific sub-processor, or about our data processing agreement can be sent to [email protected]. See our Privacy Policy for how to exercise your rights and how to complain to the Norwegian Data Protection Authority (Datatilsynet), or write to us at SAMMES AS, Øvrehusvegen 37E, 4054 Tjelta, Norway.