Lista podprocesorów / Subprocessor List — WalletHero
Wersja / Version: 1.0 · Data ostatniej aktualizacji / Last updated: 28 lipca 2026 / 28 July 2026
Niniejsza lista stanowi załącznik do Umowy powierzenia przetwarzania danych / This list constitutes an annex to the Data Processing Agreement.
Administratorem platformy jest / The platform is operated by: Collective Arkadiusz Wasilonek (Arkadiusz Wasilonek — jednoosobowa działalność gospodarcza wpisana do CEIDG / sole proprietorship registered in CEIDG), ul. Florencja 23D, 05-300 Mińsk Mazowiecki, Polska / Poland, VAT ID (NIP) 8222182106, REGON 14584187900000.
O zmianach listy informujemy Merchantów z wyprzedzeniem określonym w Umowie powierzenia. / Merchants are notified of changes to this list with the advance notice specified in the DPA.
Wersja polska
| Podmiot | Cel przetwarzania | Kategorie danych | Region przetwarzania | Mechanizm transferu poza EOG |
|---|---|---|---|---|
| DigitalOcean, LLC (usługi świadczone z centrów danych UE) | Hosting infrastruktury platformy: klaster Kubernetes (DOKS), zarządzana baza danych PostgreSQL, magazyn plików (Spaces — region fra1, Frankfurt) | Wszystkie dane platformy, w tym powierzone dane klientów końcowych | UE (Frankfurt, Niemcy) | Dane przechowywane w UE; na wypadek dostępu z USA: certyfikacja EU–U.S. Data Privacy Framework oraz standardowe klauzule umowne (SCC) włączone do DPA DigitalOcean |
| Mailgun Technologies, Inc. (Sinch) | Wysyłka transakcyjnych wiadomości e-mail (region UE) | Adres e-mail, imię i nazwisko odbiorcy, treść wiadomości | UE (endpoint regionu UE) | Region UE; na wypadek dostępu z USA: certyfikacja EU–U.S. Data Privacy Framework oraz SCC (DPA Sinch/Mailgun) |
| Apple Inc. | Doręczanie i aktualizacja kart Apple Wallet (APNs/PassKit) | Tokeny urządzeń/push, dane zawarte na karcie (np. imię, saldo punktów) | USA | Standardowe klauzule umowne (SCC) — Apple nie uczestniczy w EU–U.S. Data Privacy Framework i opiera transfery na SCC |
| Google LLC | Google Wallet API (wydawanie i aktualizacja kart Google Wallet); Google Sign-In (uwierzytelnianie użytkowników panelu) | Dane zawarte na karcie (np. imię, saldo punktów); podstawowe dane profilu Google przy logowaniu (e-mail, imię i nazwisko, identyfikator) | USA | Certyfikacja EU–U.S. Data Privacy Framework (Google LLC) oraz SCC w warunkach przetwarzania danych Google |
| Functional Software, Inc. (Sentry) | Monitorowanie błędów aplikacji i odtwarzanie sesji (z maskowaniem treści wprowadzanych przez użytkownika) | Dane techniczne o błędach, identyfikatory użytkownika/sesji, adres IP, zamaskowane nagrania sesji | USA (region domyślny; hosting w UE jest opcją wybieraną przy zakładaniu organizacji) | Certyfikacja EU–U.S. Data Privacy Framework (Functional Software, Inc.) oraz SCC w DPA Sentry |
| Cloudflare, Inc. | DNS, terminacja TLS, ochrona i przekazywanie ruchu sieciowego | Adresy IP, metadane ruchu sieciowego (dane w tranzycie) | Globalnie (sieć rozproszona) | Certyfikacja EU–U.S. Data Privacy Framework (status aktywny) oraz SCC w DPA Cloudflare |
| Expo (650 Industries, Inc.) | Budowanie i dystrybucja aplikacji mobilnej (EAS) | Artefakty budowania aplikacji; co do zasady bez danych klientów końcowych | USA | Certyfikacja EU–U.S. Data Privacy Framework (650 Industries, Inc.) oraz SCC jako mechanizm uzupełniający |
Uwagi:
- Dane produkcyjne platformy (baza danych, pliki) przechowywane są w UE (DigitalOcean, Frankfurt). Dostawcy z USA wykorzystywani są wyłącznie w zakresie wskazanych wyżej funkcji.
- Skorzystanie z niektórych podprocesorów zależy od konfiguracji wybranej przez Merchanta (np. Apple/Google — odpowiednio do typu wydawanych kart).
- Status certyfikacji EU–U.S. Data Privacy Framework zweryfikowano na dzień ostatniej aktualizacji niniejszej listy. Certyfikacje są odnawiane corocznie i mogą zostać wycofane — aktualny status każdego dostawcy można sprawdzić na dataprivacyframework.gov.
English version
| Entity | Purpose of processing | Data categories | Processing region | Transfer mechanism outside the EEA |
|---|---|---|---|---|
| DigitalOcean, LLC (services provided from EU data centers) | Hosting of the platform infrastructure: Kubernetes cluster (DOKS), managed PostgreSQL database, file storage (Spaces — region fra1, Frankfurt) | All platform data, including entrusted end-customer data | EU (Frankfurt, Germany) | Data stored in the EU; for potential US access: EU–U.S. Data Privacy Framework certification and Standard Contractual Clauses incorporated into DigitalOcean’s DPA |
| Mailgun Technologies, Inc. (Sinch) | Transactional email delivery (EU region) | Recipient email address and name, message content | EU (EU region endpoint) | EU region; for potential US access: EU–U.S. Data Privacy Framework certification and SCC (Sinch/Mailgun DPA) |
| Apple Inc. | Delivery and updating of Apple Wallet passes (APNs/PassKit) | Device/push tokens, data shown on the pass (e.g., name, point balance) | US | Standard Contractual Clauses (SCC) — Apple does not participate in the EU–U.S. Data Privacy Framework and relies on SCCs |
| Google LLC | Google Wallet API (issuing and updating Google Wallet passes); Google Sign-In (panel user authentication) | Data shown on the pass (e.g., name, point balance); basic Google profile data at sign-in (email, name, identifier) | US | EU–U.S. Data Privacy Framework certification (Google LLC) and SCCs under Google’s data processing terms |
| Functional Software, Inc. (Sentry) | Application error monitoring and session replay (with masking of user-entered content) | Technical error data, user/session identifiers, IP address, masked session recordings | US (default region; EU hosting is an option selected when the organization is created) | EU–U.S. Data Privacy Framework certification (Functional Software, Inc.) and SCCs under Sentry’s DPA |
| Cloudflare, Inc. | DNS, TLS termination, traffic protection and routing | IP addresses, network traffic metadata (data in transit) | Global (distributed network) | EU–U.S. Data Privacy Framework certification (active) and SCCs under Cloudflare’s DPA |
| Expo (650 Industries, Inc.) | Mobile app builds and distribution (EAS) | App build artifacts; as a rule no end-customer data | US | EU–U.S. Data Privacy Framework certification (650 Industries, Inc.) and SCCs as a supplementary mechanism |
Notes:
- The platform’s production data (database, files) is stored in the EU (DigitalOcean, Frankfurt). US providers are used solely for the functions indicated above.
- The use of some sub-processors depends on the Merchant’s configuration (e.g., Apple/Google — depending on the type of passes issued).
- EU–U.S. Data Privacy Framework certification status was verified as of the last update of this list. Certifications are renewed annually and may be withdrawn — each provider’s current status can be checked at dataprivacyframework.gov.