DRAFT — pending legal review. Not final counsel-approved wording.
Data recipients and service providers
Version 3.0.0 · Effective 2026-08-01 · Last updated 2026-07-28
Previous versions
- 2.0.0 · 2026-08-01 — Added role column; Stripe dual role; OpenAI reclassified as independent controller; PostgreSQL self-hosted; ACS added; Art.28-only framing removed.
- 1.0.0 · 2026-07-25 — First published draft.
Note for counsel: Azure region specifics are confirmed at sign-off via the Evidence Checklist. Where a region is not stated below, services are deployed in the EEA / as configured.
This page lists the third parties that receive personal data in connection with CramDeck and the legal relationship under which they do so. Not every recipient is an Article 28 GDPR processor; some act as independent controllers for their own purposes. The "Role" column clarifies each case.
Infrastructure and identity (Microsoft — processor)
| Recipient | Role | Contracting entity | What it processes | Where | Transfer safeguard |
|---|---|---|---|---|---|
| Microsoft Entra External ID | Processor (Art. 28) | Microsoft Ireland Operations Ltd, Dublin, Ireland | Email address, name, authentication events, identity tokens | EEA / as configured | EU Data Boundary; DPF certification and SCCs in the Microsoft DPA |
| Azure Cosmos DB | Processor (Art. 28) | Microsoft Ireland Operations Ltd | Profiles, decks, cards, favourites, groups, study state, media metadata | EEA / as configured | As above |
| Azure Blob Storage | Processor (Art. 28) | Microsoft Ireland Operations Ltd | Uploaded images and other media | EEA / as configured | As above |
| Azure API Management | Processor (Art. 28) | Microsoft Ireland Operations Ltd | Feed requests proxied through our API gateway, including request metadata | EEA / as configured | As above |
| Azure Key Vault | Processor (Art. 28) | Microsoft Ireland Operations Ltd | Application secrets only; does not store end-user content or personal data | EEA / as configured | As above |
| Azure Communication Services (ACS) | Processor (Art. 28) | Microsoft Ireland Operations Ltd | Recipient email address, message content for purchase confirmations and service notifications | EEA / as configured | As above |
Self-hosted database
| Recipient | Role | What it processes | Where |
|---|---|---|---|
| PostgreSQL (self-hosted) | Not a third-party recipient | Accounts, sessions, billing metadata, integration tokens, consent records, audit log, content reports | Our own infrastructure in the EEA |
PostgreSQL is deployed on infrastructure we control. No third-party provider has access to the data it stores beyond the hosting of the virtual machine (covered by the Microsoft entries above).
AI (Microsoft — processor)
| Recipient | Role | Contracting entity | What it processes | Where | Transfer safeguard |
|---|---|---|---|---|---|
| Azure OpenAI Service | Processor (Art. 28) | Microsoft Ireland Operations Ltd | Prompts you submit to the AI deck wizard and the generated output. Not used to train models. Retention of flagged content for abuse review follows the Microsoft agreement and configured abuse-monitoring settings; reviewers, where applicable, are located in the EEA | EEA / as configured | EU Data Boundary; DPF and SCCs |
| Azure AI Content Safety | Processor (Art. 28) | Microsoft Ireland Operations Ltd | Generated text submitted for harm classification | EEA / as configured | As above |
Payments (Stripe — dual role)
| Recipient | Role | Contracting entity | What it processes | Where | Transfer safeguard |
|---|---|---|---|---|---|
| Stripe | Processor (Art. 28) for payment processing on our behalf; Independent controller for its own fraud-prevention, regulatory and financial-service purposes | Stripe Payments Europe, Ltd., Dublin, Ireland, with Stripe, Inc., USA | Customer identifier, email, name, amounts, currency, purchased items, subscription state. Card numbers are handled by Stripe and never reach us | Ireland, with access from the USA | EU-US DPF certification and SCCs in the Stripe DPA |
Optional — only with your consent (Google — processor)
| Recipient | Role | Contracting entity | What it processes | Where | Transfer safeguard |
|---|---|---|---|---|---|
| Google Tag Manager and Google Analytics | Processor (Art. 28) | Google Ireland Limited, Dublin, Ireland, with Google LLC, USA | Usage events, device and browser data, approximate location, consent state. Loaded only after you opt in to analytics cookies (Consent Mode Basic) | Ireland, with access from the USA | EU-US DPF certification and SCCs in the Google Ads Data Processing Terms |
Optional — only if you connect the integration (OpenAI — independent controller)
| Recipient | Role | Contracting entity | What it processes | Where | Transfer safeguard |
|---|---|---|---|---|---|
| OpenAI (ChatGPT) | Independent controller — not a CramDeck processor or subprocessor | OpenAI Ireland Ltd, Dublin, Ireland, with OpenAI, L.L.C., USA | Data you exchange with the ChatGPT agent via our OAuth integration. Governed by OpenAI's own terms (App Developer Terms) and privacy policy | Ireland, with access from the USA | SCCs in the OpenAI DPA |
OpenAI processes data you voluntarily send through the ChatGPT integration under its own controllership. We do not instruct OpenAI on the purposes of its processing; it determines those independently.
Not in use
Azure Application Insights appeared on earlier versions of this page. The telemetry SDK is not installed and no telemetry is sent. It will be added back here before it is enabled.
Changes
We will update this page when we add or replace a material recipient, and we will note the change in the version history above. If you object to a new processor, you may terminate your account before the change takes effect. Contact: hello@cramdeck.com.