Subprocessor Policy
Applies to: 42 Support, 42 Ekonomi
To provide our Services, we use carefully selected third-party service providers.
- We use subprocessors only where necessary.
- We require appropriate contractual safeguards.
- We remain responsible for our subprocessors as required by GDPR.
- We maintain a current list of subprocessors.
- We will update this list when material changes occur.
This summary is provided for convenience only. The legally binding terms are set out below.
Purpose
This Policy explains how 42 Scandinavia AB selects, manages and discloses subprocessors used in connection with our Services.
It supplements our:
What Is a Subprocessor?
A subprocessor is a third party engaged by 42 Scandinavia to process Personal Data on behalf of our Customers.
Examples include providers of:
- cloud infrastructure;
- email delivery;
- payment processing;
- monitoring;
- operational support.
Not every third-party supplier is a subprocessor. For example, a company providing office supplies would not normally process Customer Data.
Selection Principles
Before engaging a subprocessor, 42 Scandinavia considers factors such as:
- security practices;
- privacy practices;
- reliability;
- contractual commitments;
- GDPR compliance;
- operational necessity.
Where appropriate, we enter into data processing agreements with subprocessors.
Current Subprocessors
The following subprocessors are used at the time of publication.
| Provider | Purpose | Data Processed | Primary Location* |
|---|---|---|---|
| Lovable | Managed application hosting | Customer Data, application data | Europe (as provided by the service) |
| Supabase (where applicable) | Database infrastructure | Customer Data stored by the application | Europe (where applicable) |
| Resend | Transactional email delivery | Email addresses, email content required for delivery | As documented by the provider |
| Stripe | Payment processing | Billing and payment information | Global, with appropriate safeguards |
* Data processing locations may change as providers evolve their infrastructure. Customers should refer to each provider's published documentation for current regional information.
Future Subprocessors
42 Scandinavia may add or replace subprocessors as our Services evolve.
When selecting a new subprocessor, we will take reasonable steps to ensure that the provider offers appropriate safeguards for the protection of Personal Data.
Where required by applicable law or contractual commitments, Customers will be informed of material changes before they take effect.
International Data Transfers
Some subprocessors may process Personal Data outside the European Economic Area (EEA).
Where this occurs, 42 Scandinavia will implement appropriate safeguards in accordance with Chapter V of the GDPR, such as:
- European Commission adequacy decisions;
- Standard Contractual Clauses (SCCs);
- other lawful transfer mechanisms.
Customer Questions and Objections
Customers may contact us with reasonable questions regarding our subprocessors.
Where the GDPR or an applicable agreement provides a right to object to a new subprocessor, Customers should notify us in writing as soon as reasonably practicable after receiving notice.
42 Scandinavia will consider such objections in good faith and work with the Customer to determine whether a reasonable solution can be achieved.
If no reasonable solution is available, either party may exercise any termination rights available under the applicable agreement.
Changes to this Policy
This Policy may be updated from time to time.
The current version will always be published on our websites.
Material changes to the subprocessor list will normally be reflected before or when those changes take effect.
Contact
Questions regarding this Policy or our subprocessors may be directed to:
42 Scandinavia AB
Organisation No. 556827-3204
P O Hallmans gata 3
SE-112 06 Stockholm
Sweden
Document History
| Version | Date | Description |
|---|---|---|
| 1.0 | Publication | Initial release |
