Effective date
Pursuant to Section 6 of this DPA, the Controller agrees to the Processor's engagement of the Sub-processors listed at the dynamic URL below.
The Processor maintains an up-to-date list of all authorized Sub-processors, including their legal entity names, corporate locations, processing locations, and specific services provided:
Subprocessor Registry & Data Recipients List
| Entity Name & Location | Legal Role & Purpose | Processing Location | Third-Country Transfer (Legal Basis) | Technical & Organizational Measures (TOMs) | DPA Status / Agreement Link | Privacy Contact / DPO |
|---|---|---|---|---|---|---|
| Amazon Web Services EMEA SARL (Luxembourg / AWS Inc., USA) | Processor: Core LHM Cloud hosting, relational database management automated backup storage | EEA (Frankfurt eu-central-1) | YES (Backup redundancy & Tier 3 US engineering support) - EU-U.S. DPF / Art. 46 GDPR (SCCs) | ISO 27001, ISO 27017, ISO 27018, SOC 1/2/3, AES-256 encryption at rest, TLS 1.3 in transit | Public DPA: AWS GDPR DPA | aws-privacy@amazon.com |
| Cloudflare, Inc. (USA) | Processor: Cloudflare can be used by STUN server for WebRTC | EEA / Global Edge Nodes | YES - EU-U.S. DPF / SCCs | ISO 27001, SOC 2 Type II, DNSSEC, SSL/TLS Encryption, IP Anonymization, Rate Limiting | Public DPA: Cloudflare DPA | privacy@cloudflare.com |
| Stripe Payments Europe Ltd. (Ireland / Stripe Inc., USA) | Processor / Independent Controller: Credit card processing, subscription management, payment tokenization, MoR | EEA / USA | YES - EU-U.S. DPF / SCCs | PCI-DSS Level 1, ISO 27001, End-to-end payment encryption, Tokenization | Public DPA: Stripe DPA | privacy@stripe.com |
| Lemon Squeezy LLC (USA) | Merchant of Record (MoR) / Controller: reseller of LHM licenses, checkout processing, statutory global VAT & Sales Tax compliance | USA / EEA | YES - EU-U.S. DPF / SCCs | PCI-DSS, TLS 1.3 Encryption, SOC 2 Compliance, Fraud detection | Executed via Merchant Agreement / Terms | privacy@lemonsqueezy.com |
| IFirma S.A. (Poland) | Processor: Statutory accounting, tax ledger management, and legal invoice generation | Poland (EEA) | NO (Strictly within the EEA) | ISO 27001, Polish Data Protection Act compliance, Encrypted database storage | Bilateral DPA executed via IFirma platform | iod@ifirma.pl |
| Google Ireland Ltd. (Ireland / Google LLC, USA) | Processor (Workspace & Analytics) / Controller (Ads & SSO): Corporate email infrastructure (lhm@lexogrine.com), web traffic analytics, STUN server for WebRTC | EEA / USA | YES - EU-U.S. DPF / SCCs | ISO 27001, SOC 2/3, TLS 1.3, Data encryption at rest, IP Pseudonymization | Public DPA: Google Business Terms | data-protection-office@google.com |
| Twilio Ireland Ltd. (SendGrid) (Ireland / Twilio Inc., USA) | Processor: Twilio can be used as a STUN server for WebRTC | EEA / USA | YES - EU-U.S. DPF / Binding Corporate Rules (BCRs) / SCCs | ISO 27001, SOC 2 Type II, TLS 1.3 transport encryption, API key security | Public DPA: Twilio DPA | privacy@twilio.com |
| Discord, Inc. (USA) | Processor / Independent Controller: Community support, user ticket handling, and voluntary Feedback collection (ยง 10 Terms) | USA | YES - EU-U.S. DPF / SCCs | SOC 2 Type II, TLS 1.3 encryption, Access control (RBAC) | Public DPA: Discord Terms | privacy@discord.com |
| Valve Corporation (Steam) (USA) | Independent Controller: OpenID Single Sign-On (SSO) authentication for CS2/Dota 2 players & organizers, Steam Web API for profile/avatar loading | USA | YES - Art. 49(1)(a) GDPR (Explicit user consent upon SSO redirect) | Transport encryption, OpenID Protocol | N/A (Independent Controller - OpenID API) | questions@valvesoftware.com |
| GitHub, Inc. (USA / Microsoft) | Independent Controller: Single Sign-On (SSO) | USA / EEA | YES - EU-U.S. DPF / SCCs | ISO 27001, SOC 2 Type II, OAuth 2.0 Protocol | Public DPA: Microsoft DPT | privacy@github.com |
| LinkedIn Ireland Unlimited (Ireland / USA) | Independent Controller: SSO authentication | EEA / USA | YES - EU-U.S. DPF / SCCs | ISO 27001, OAuth 2.0, TLS Encryption | Public DPA: LinkedIn DPA | DPO via LinkedIn Webform |
| Microsoft Ireland Operations Limited (Ireland / Microsoft Corporation, USA) | Independent Controller / Data Recipient: website behavior analytics, including heatmaps, session recordings, page and DOM rendering, clicks, scrolling, pointer movements, diagnostic and performance data, pseudonymous user/session identifiers, and non-identifying conversion events | EEA / USA | YES - SCCs between Microsoft Ireland Operations Limited and Microsoft Corporation; where applicable EU-U.S. DPF | Azure security controls; encryption at rest (AES-256) and in transit (TLS); default sensitive-content masking; additional element masking; restricted public-page allowlist; consent signaling and cookie withdrawal | N/A (Independent Controller, not Processor): Microsoft Clarity Terms of Use / Microsoft Privacy Statement | Microsoft Privacy Support / DPO; Clarity: clarityMS@microsoft.com |
Note: The Controller may subscribe to updates on the page specified above or will receive updates via email notifications prior to any changes to the list.