Vendors that process personal data on Noria's behalf under Article 28 GDPR
A subprocessor is an external entity engaged by Noria to process personal data on behalf of our customers (data controllers). Each subprocessor is bound by a written contract that meets the requirements of Article 28(4) GDPR, including confidentiality, technical and organisational security and audit rights.
Whenever possible, we favour vendors that host and process exclusively in the European Economic Area (EEA). Where that is not feasible, we ensure one of the safeguards set out in Chapter V of the GDPR:
| Subprocessor | Purpose | Categories of Data | Location | Transfer Basis |
|---|---|---|---|---|
| Meta Platforms Ireland Ltd. WhatsApp Business API | Sending and receiving messages, managing approved templates, number authentication | Phone number, contact name, message content, delivery metadata | Ireland (EEA) | SCCs + DPF |
| Google Ireland Ltd. Google Calendar API + OAuth 2.0 | Calendar event sync, meeting scheduling, OAuth authentication | Email, calendar events, encrypted access tokens | Ireland (EEA) + USA | SCCs + DPF |
| OpenAI Ireland Ltd. API gpt-4o-mini | Natural-language processing for AI agents configured by the customer | Message content (only what is needed for the answer), tenant guardrails | Ireland (EEA) + USA | SCCs + DPF |
| __PROVIDER_HOSTING__ Cloud and database infrastructure | Platform hosting, PostgreSQL databases, file storage | All Platform data (encrypted at rest with AES-256 and in transit with TLS 1.2+) | __HOSTING_REGION__ (EU) | EU/EEA |
| __PROVIDER_EMAIL__ Transactional email | Notifications, security alerts, password recovery | Email address, notification content | __EMAIL_REGION__ | EU/EEA |
Note on “__PROVIDER__” placeholders: the vendors marked with placeholders are confirmed internally and updated on this page before any production processing. Enterprise customers may request the detailed list (including ISO 27001 / 27701 / SOC 2 certifications) by writing to contacto@noria.pt.
In addition to the subprocessors above, the customer may enable additional integrations (CRM, payment gateway, billing software, etc.) from the Integrations menu. In those cases the customer is responsible for the legal basis and the data-processing agreement with those external vendors. Noria acts only as a technical intermediary for the transmission of the configured data.
We commit to notifying every customer at least 30 days in advance before adding, replacing or removing any subprocessor from this list, in line with Article 28(2) GDPR. Notice is delivered via:
The customer has the right to object to a new subprocessor within a reasonable period. If the objection cannot be resolved, either party may terminate the agreement without penalty.
Subprocessing contracts, security certifications, SOC 2 / ISO 27001 reports and Transfer Impact Assessments (TIAs) can be made available to enterprise customers under NDA, on request to contacto@noria.pt with the subject “Audit — Subprocessors”.