Subprocessors
The complete list of companies that can process personal data on our behalf. It includes services that are configured and currently switched off, because a list of what could touch your data is more useful than a list of what did this morning.
1.The list
| Company | What it does for us | Where it processes | Transfer safeguard | Status |
|---|---|---|---|---|
| Hetzner Online GmbH | Server hosting, database, and object storage for converted video | Germany | None. Data stays in the EU | In use |
| Google Ireland Limited (Google Analytics 4) | Anonymous usage statistics for the public pages | Ireland, with onward transfer to the United States | EU Standard Contractual Clauses and the EU-US Data Privacy Framework | Only with your consent |
| OpenAI Ireland Ltd | Checks single video frames during automatic shot detection, to tell a rally apart from a break in play | Ireland, with onward transfer to the United States | EU Standard Contractual Clauses | Configured, switched off |
| Google Ireland Limited (Gemini) | Reserved for automatic shot recognition on video. Configured in the production environment, and no code calls it today | Ireland, with onward transfer to the United States | EU Standard Contractual Clauses | Configured, switched off |
Your video and your account data are handled by the first row only. They are stored in Germany and they do not leave the EU in normal use.
2.What the status column means
- In use
- Processing personal data now, for every user. Without it the service does not run.
- Only with your consent
- Processing nothing until a visitor accepts analytics on the cookie page. Declining keeps it at zero. Today the analytics tag is not installed at all, so this row processes nothing for anybody.
- Configured, switched off
- A service the application can call and currently does not, because a feature flag is off. It is listed because the wiring exists. A processor that is disclosed while dormant costs nothing; one discovered later costs a great deal.
3.What is deliberately absent
Some things a site usually has to disclose are absent here because we do not use them.
- No content delivery network for fonts, icons or scripts. Every asset is served from this domain. Loading a page tells no third party that you were here.
- No advertising or marketing platform. No pixels, no retargeting, no social buttons.
- No third-party email provider. Password reset messages are sent from our own mail server.
- No payment processor. Nothing on this site takes a payment today. A paid plan would add a row here before it launched.
- No IP geolocation service. The cookie hint decides using a country code the network already provides, and treats an unknown country as EU.
4.Being told when this changes
We announce a new subprocessor at least 30 days before it begins processing. Write to privacy@tencoline.com to be added to that notice by email.
Controllers under the data processing agreement may object on reasonable data protection grounds during those 30 days, and may terminate the affected service without penalty if the objection cannot be resolved.