Last updated and roles
Last updated: 7 September 2026. This overview supplements https://desklix.com/en/privacy/ for the website and platform. Technical involvement does not make every provider a subprocessor in every operation. Processors engaged by Desklix may be subprocessors for Customer Data, and direct processors for Desklix’s own contact, account and contract administration. Independent controllers and customer-connected services are identified accordingly. The agreed data processing agreement and its schedules govern Customer Data. This public list does not replace that agreement, agreed notifications or objection rights concerning provider changes.
Convex · backend, database and files
Legal entity: Convex, Inc. Used for core platform operations as a processor or subprocessor. Data: account, organisation, booking, resource, integration and other application data and stored files. The configured production region is EU West (Ireland); support and other providers may operate outside the EEA. The Convex DPA provides EU Standard Contractual Clauses for necessary third-country transfers. Information: https://www.convex.dev/legal/dpa and https://www.convex.dev/legal/subprocessors.
Cloudflare · website, web app and API hosting
Legal entity: Cloudflare, Inc. Used for the website including the demo form, and platform web, API and edge hosting. Data: IP addresses, request, session, authentication, delivered application and log data. Global edge/CDN infrastructure with processing in the USA and further provider locations. The published DPA includes EU Standard Contractual Clauses. Contractual coverage of the plan in use for processing real personal Customer Data is not yet confirmed and must be established before the corresponding customer release. Publishing this overview does not confirm that release. Information: https://www.cloudflare.com/cloudflare-customer-dpa/ and https://www.cloudflare.com/privacypolicy/.
WorkOS · authentication and identity
Legal entity: WorkOS, Inc. Used for authentication and, where enabled, SSO, MFA and directory synchronisation as a processor or subprocessor. Data: identity, organisation, authentication, SSO and directory data. Processing in the USA and at published subprocessor locations. The DPA provides EU Standard Contractual Clauses, particularly modules 2 or 3 depending on the role. Information: https://workos.com/legal/data-processing-addendum and https://workos.com/legal/subprocessors.
Resend · email delivery
Legal entity: Plus Five Five, Inc., USA (Resend). Delivers demo and contact requests and transactional platform messages as a processor or subprocessor. Data: sender and recipient addresses, message content and delivery metadata. Processing in the USA and by published providers. The DPA includes EU Standard Contractual Clauses, particularly modules 2 and 3. Information: https://resend.com/legal/dpa and https://resend.com/legal/privacy-policy.
Microsoft 365 · business mailbox and optional customer connection
European legal entity: Microsoft Ireland Operations Limited, Ireland. Desklix uses Microsoft 365 for its own business mailbox and inquiry handling. Customers can also authorise connections to their Microsoft 365 calendars and resources. Depending on the operation, data include contact and message content, identity, calendar, room, resource, meeting and delivery metadata. The Desklix tenant is within the EU Data Boundary with documented limited exceptions; customer tenant regions and settings depend on customer configuration. The Microsoft DPA and, where necessary, Standard Contractual Clauses or applicable adequacy decisions govern transfers. For customer connections Microsoft may also be a provider engaged directly by the customer. Information: https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA and https://privacy.microsoft.com/en-us/privacystatement.
OpenAI · optional AI floor-plan optimisation
Legal entity for the European API service described here: OpenAI Ireland Ltd. Used only on request of the AI floor-plan optimiser as a processor or subprocessor. Data: selected floor-plan images, editing instructions and technical request identifiers; images may contain personal information supplied by the user. No special EU data residency is agreed here for the standard API; processing in Ireland, the USA and other published locations is possible. The DPA provides applicable adequacy decisions and Standard Contractual Clauses. Information: https://openai.com/policies/data-processing-addendum/ and https://openai.com/policies/sub-processor-list/.
Google Maps · optional maps under independent responsibility
Contractual entity: Google Cloud EMEA Limited; European controller for the relevant Google services: Google Ireland Limited. Maps load in building administration only after active selection. Data: IP address, technical usage data, search requests, addresses and coordinates. Processing in Ireland and through Google’s global infrastructure. Google Maps is used here under Controller-to-Controller terms and is therefore not categorically listed as a subprocessor. Transfers may rely on the Standard Contractual Clauses described there and applicable adequacy decisions. Information: https://cloud.google.com/maps-platform/terms/maps-controller-terms and https://policies.google.com/privacy.
Stripe / Link · checkout and payments
European Stripe contractual entity: Stripe Payments Europe, Limited, Ireland. In Managed Payments checkout, the Link seller specifically identified there is the merchant of record. Data: business, billing, tax, payment, device and transaction data. Processing in Ireland and through global Stripe infrastructure including the USA. Roles vary by operation; in particular, independent payment, fraud prevention, tax and seller obligations are not categorically subprocessing for Desklix. The parties and terms shown at checkout apply, together with the Stripe DPA, Data Transfers Addendum and applicable adequacy decisions or Standard Contractual Clauses. This list does not confirm final approval of all roles and contractual arrangements. Information: https://stripe.com/privacy, https://stripe.com/legal/dpa and https://link.com/privacy.
Customer-connected systems and changes
HR systems such as Workday and other systems authorised by the customer connect through its accounts and permissions. That connection alone does not make them subprocessors engaged by Desklix. The customer determines the permitted exchange and its own providers. Optional functions that have not been activated do not receive data merely because someone visits the website. Updating this overview does not replace a contractually required provider approval. Please contact hello@desklix.com about actual use, contractual evidence or transfer safeguards.