Privacy Policy
Last updated: September 2, 2026
This Privacy Policy describes how Lince Media LLC, doing business as CitaFlow ("CitaFlow", "we", "our", "us"), handles personal data in relation to our websites, apps, APIs, and associated voice and messaging services. References to "CitaFlow" or the "Data Controller" include any Affiliate or successor that may assume the provision of the Service in the future, pursuant to Section 6.3.
1. Who We Are and Scope
Data Controller:
Lince Media LLC
25 SE 2nd Ave, Ste 550 #1172
Miami, FL 33131, United States
privacy [arroba] citaflow [punto] com
Scope: We provide a SaaS platform for appointment management and communications for businesses. We process data from both our customers (paying users) and third parties with whom our customers interact, such as their potential or current clients who call, send messages, or book appointments.
Roles:
- For account data, billing, service analytics, and marketing, CitaFlow is the data controller.
- For data we process "on behalf of" a customer about their own contacts, calls, messages, appointments, and associated content, CitaFlow acts as a data processor and our DPA is part of the service agreement.
- Some network providers and telecommunications operators act as independent controllers for certain metadata and regulatory traffic obligations.
Third-party transparency: The customer (data controller) must inform its customers/users that their data will be processed by CitaFlow as a data processor, and provide a link to this Privacy Policy when appropriate. Third-party data (customers' customers) is received only on behalf of the customer; it is the customer's responsibility to notify their own users pursuant to Art. 14 GDPR.
2. Data We Process
2.1 Account and Billing Data
Name, contact details, email, phone, login credentials, company information (business name, tax ID), billing addresses, transaction history, plan and subscription status.
2.2 Service Usage
- Configuration and preferences, schedules, calendars, and appointments.
- Technical system logs, device identifiers, and IP addresses.
- Product events and performance metrics.
- Operational communication and support.
2.3 Voice, Messages, and Content
Optional features you can enable and configure:
- Incoming calls, routing, signaling, and metadata. The voice assistant only handles incoming calls; CitaFlow does not place automated outbound calls.
- Voicemail recordings: Voicemail messages are recorded when the voicemail feature is active.
- AI transcription: When the voice assistant handles calls, the audio is transcribed in real time to analyze the interaction. These calls are NOT recorded; only an approximate text transcription is kept, visible to the business in its dashboard. Calls transferred to another number are neither recorded nor transcribed by CitaFlow.
- Messaging and chat: SMS, WhatsApp, Telegram, Instagram, Facebook Messenger, and the web chat widget, including message content (text and, where applicable, images) and shortened links.
You can disable these features and define retention periods.
2.4 Cookies and Similar Technologies
We use technologies necessary to operate the service and, if enabled, analytics and marketing, according to your consent settings. See our Cookie Policy.
2.5 Categories of Data Subjects
Administrative and operational users of our customers, customer personnel (including, if the customer enables the Team module, contact details and time-tracking records of their employees), and individuals who interact with phone numbers or communication channels configured by our customers.
2.6 Consent Records and Fraud Prevention
When you or our customers' clients give consent (for example, for marketing, recurring appointments, or external partners), we keep evidence including timestamp, source, IP address, user-agent, and a hash of the accepted text (Art. 7.1 GDPR). During sign-up of new accounts we may process the IP address and a technical device identifier to verify the business and prevent fraud and abuse of the service (legitimate interest).
2.7 Access logs for public booking sites
The public booking pages our customers publish (on web.citaflow.com or on their own domain) generate a technical access record for each visit: date and time, domain and requested path, IP address, approximate country derived from the IP, user-agent, referring page and a request identifier. We do not record URL parameters or any form data. Its sole purpose is service security and diagnostics: detecting automated data extraction, abuse and availability incidents. The legal basis is our legitimate interest in protecting the service and our customers (Art. 6.1.f GDPR). With respect to visitors to a customer's site we act as a processor on that customer's behalf. These records are kept for a maximum of 31 days and are then deleted automatically. The admin panel and appointment-management pages are excluded from this logging.
3. Purposes and Legal Bases
Only applicable when GDPR applies.
Contract Performance: Providing the service, operating accounts and subscriptions, customer support, phone number and messaging provisioning, integrations, operational security.
Legitimate Interest: Improving and protecting the service, abuse and fraud detection, aggregated analytics, non-commercial operational communications. You may object when appropriate.
Consent: Electronic marketing, non-essential cookies, call recording when required by national regulations, and optional features that require it. You may withdraw it at any time.
Legal Obligation: Accounting and taxes, compliance with applicable telecommunications regulations, responding to valid legal requests, and breach notification when appropriate.
4. Transparency in Voice and AI Features (Regulation (EU) 2024/1689, "AI Act")
CitaFlow includes an AI-powered receptionist that can handle voice calls and chat conversations on behalf of the businesses that enable it. In compliance with Article 50 of the EU Artificial Intelligence Act, we clearly inform people when they are interacting with an AI system:
- Voice: at the beginning of every call handled by the assistant, a notice is played informing the caller that the call is handled by an artificial intelligence and that the conversation is transcribed. This notice is enabled by default for all businesses and cannot be disabled. No explicit consent is requested; it is an informational notice.
- Chat: on all chat channels (WhatsApp, Telegram, Instagram, Facebook Messenger, and the web widget), the assistant identifies itself as an AI virtual assistant at the start of the conversation. This identification is enabled by default and cannot be disabled.
- The assistant answers truthfully if asked whether it is an artificial intelligence, and can hand the conversation over to a person at the business.
- The business can customize its welcome messages, but cannot remove the identification of the system as AI.
- You can use the assistant without retaining transcriptions, enabling only real-time processing and/or minimal retention.
Model providers: the assistant's responses are generated using large language models from external providers (see section 6.1). We use those providers' business APIs, whose terms exclude the use of your conversation data to train their models.
Automated decisions: the assistant manages appointments and enquiries, but does not make decisions that produce legal or similarly significant effects on individuals (see section 9). Human intervention by the business is always available.
5. Processing Location and Transfers
Primary Storage in the EU:
- Database and storage: Supabase, EU region, and EU-compliant storage.
- API and apps: EU infrastructure with Hetzner and Railway depending on the component.
- CDN and sites: Cloudflare.
Access from the U.S. and other countries: Team members and some providers may access from outside the EEA only when necessary to provide the service. When a U.S. provider is certified under the EU-U.S. Data Privacy Framework, we rely on that adequacy decision; otherwise, international data transfers are carried out under EU-approved Standard Contractual Clauses (Decision 2021/914), combined with additional technical and organizational safeguards (e.g., encryption in transit and at rest) in line with EDPB guidance post-Schrems II. Transfer impact assessments are conducted when appropriate.
6. Providers and Recipients
We do not sell personal data. We only share data with:
6.1 Data Processors
CitaFlow enters into GDPR-compliant data processing agreements (DPAs) with every service provider acting as a data processor prior to processing data on its behalf. Our main processors include:
- Supabase: database, authentication, and storage (EU region).
- Hetzner and Railway: hosting and servers.
- Cloudflare: CDN, perimeter security, anti-bot verification (Turnstile), and custom domain management.
- Twilio: CPaaS platform for numbers and voice calls.
- OpenAI: real-time voice processing, audio transcription, and semantic indexing of content when you enable AI features.
- Google: large language models (Gemini) for the chat assistant and content moderation; Firebase Cloud Messaging for push notifications; Google Places for business verification at sign-up.
- Stripe: payments and subscription management, PCI DSS Level 1 certified.
- Brevo (formerly Sendinblue): email marketing, contact management and internal CRM for handling enquiries about external partners.
- SendGrid (Twilio): transactional email delivery.
- BulkGate: SMS delivery.
- Sentry: application error monitoring, with content masking.
- Axiom: storage of technical service logs.
In addition, we use tools self-hosted on our own infrastructure (they are not external recipients of data): n8n (internal lead and sales-flow orchestration), Chatwoot (CitaFlow support chat), and Umami (cookieless analytics).
6.2 Communications, Channels, and Operators
- Twilio: CPaaS platform for numbers and voice calls.
- Underlying operators: for example, Enreach Communications S.L.U. for Spanish numbering.
- Meta Platforms: when you or your business's clients use the WhatsApp, Instagram, or Facebook Messenger channels, Meta processes the messages and profile identifiers as the channel provider, under its own terms and privacy policies.
- Telegram: when the Telegram channel is used, Telegram processes the messages under its own terms.
Some operators, carriers, and channel providers process certain metadata and regulatory obligations as independent controllers.
6.3 Affiliate Companies and Change of Controller
We may share data with companies in our corporate group (parent companies, subsidiaries, or entities under common control) that participate in providing the Service.
In the event of a corporate reorganization, merger, acquisition, asset sale, or any transaction by which another entity in our group assumes the role of data controller or data processor with respect to your data, we will notify you with reasonable prior notice (typically 30 days) by email or in-product notification. The successor entity will continue to honor the commitments set out in this Privacy Policy and in our DPA, unless you are notified otherwise with sufficient prior notice to exercise your rights. The technical and organizational safeguards, retention periods, and legal bases described herein will be maintained or strengthened; they will not be reduced without prior notice.
6.4 Other Recipients
Public authorities when legally obligated, law firms and advisors for legal defense, or third parties in corporate transactions (such as mergers, acquisitions, reorganizations, or asset sales), applying appropriate safeguards.
6.5 Sub-processors
We maintain an updated list of sub-processors, with prior notice of changes when possible. You can subscribe to receive notifications.
6.6 External partners we may refer your data to
When you ask us for information about products or services offered by an external partner with whom CitaFlow has a commercial arrangement, we may share with that partner the data needed to handle your enquiry, such as trading name, contact details (email and, if you provided it, phone number), country, your CitaFlow user identifier, and any information you have given us about your business (for example, the monthly revenue bracket you declared). This sharing only happens when you expressly ask us to do so or when you give specific consent at the point of data collection.
Current external partner:
- Teya — independent provider of POS and payment services, currently available in Spain. When you request that Teya contacts you about its POS or payment services from the CitaFlow dashboard, we may share with Teya the data described above. Teya will process your data as an independent data controller, subject to its own privacy policy and terms. CitaFlow is not a payment institution, acquirer, bank, payment processor or terminal provider. Contracting, approval, pricing, terms, installation and support for the POS and payment services are Teya's responsibility.
Minimum data shared: trading name, user email, phone (only if already on file in your account), country, your CitaFlow user identifier, and the business information you have provided (for example, revenue bracket). For this referral flow we do not share with the partner any card data, CVC, IBAN, identity documents or KYC information.
Purpose: to allow the external partner to contact you, assess providing its services and, where applicable, contract directly with you.
Legal basis: your explicit consent (Art. 6.1.a GDPR) collected at the time you request information or, alternatively, the performance of pre-contractual measures taken at your request (Art. 6.1.b GDPR). We keep evidence of your request and/or consent — including timestamp, account identifier, IP address, user-agent and a hash of the text you accepted — pursuant to Art. 7.1 GDPR.
Referral compensation: CitaFlow may receive compensation from the partner if you sign up for their services. You can request more information about this compensation by contacting contact [arroba] citaflow [punto] com .
Withdrawal of consent: you can ask us at any time to stop sharing your data with the partner, either from your dashboard or by writing to privacy [arroba] citaflow [punto] com . Withdrawal does not affect data the partner may already have processed on its own as an independent controller: for that, you should contact the partner directly under its privacy policy.
Retention by CitaFlow: we keep the record of your enquiry and the consent evidence for the duration of your account and for the period needed to defend any potential claims, in line with the general retention periods set out in section 7 of this Policy. You can request its deletion by writing to privacy [arroba] citaflow [punto] com or from your settings panel.
6.7 Integrations You Enable
The CitaFlow dashboard lets you connect third-party services using your business's own account. If you enable them, we will share with them only the data strictly necessary, following your instructions, and the provider will process it under the contract you hold with them:
- Google Calendar: appointment synchronization (event data may include the name, email, and phone number of the booked client).
- Stripe Connect: charges to your clients where your business is the merchant and responsible for the charge.
- Quipu and Alegra: invoice issuance from your own invoicing account (invoices may include the billed client's name).
- Shopify: product catalog for sales and charges.
- Teya: POS and payment services (see section 6.6).
7. Retention
- Account data: for the duration of the relationship and, after termination, for the time necessary for legal obligations, typically 3 to 7 years for tax and accounting purposes.
- Security technical logs: 12 months by default.
- Voicemail, call transcriptions, and chat conversations: kept while the business account remains active, so the business can review them in its dashboard, and deleted through the account deletion lifecycle (section 7.1). The business can request shorter retention periods.
- Appointment data: configurable; default 24 months.
- Backups: rotate in cycles of up to 35 days, unless otherwise legally required.
- Consent records (marketing, recurring appointments, external partners): for the duration of the account and up to 6 years to defend against potential claims, in line with Art. 7.1 GDPR.
- Account verification and fraud prevention records: for the time necessary to protect the service against repeated abuse.
7.1 Account lifecycle after cancellation
When a user cancels their subscription, their data follows the retention lifecycle below:
- Grace period (0–30 days): All data remains intact. The user can reactivate their account at any time without data loss.
- Archive (30–90 days): The assigned phone number is suspended, future appointments are automatically cancelled, and affected clients are notified. The user can still reactivate their account, but will need to re-verify their phone number.
- Permanent deletion (after 90 days): Personal data (clients, appointments, settings, services, chatbot, integrations) is anonymized or irreversibly deleted. The phone number is permanently closed.
- Billing data: Retained for 6 years after cancellation in accordance with applicable commercial and tax legislation (Art. 30 of the Spanish Commercial Code, without prejudice to the tax limitation periods of the Spanish General Tax Law and Directive 2006/112/EC).
Email notifications are sent at each transition: upon cancellation, upon archiving, and 10 days before permanent deletion.
7.2 Right to portability and erasure
At any time during the retention lifecycle, the user can:
- Export their data (Art. 20 GDPR): Download a complete copy of all their data as a ZIP archive with JSON/CSV files from the dashboard or the cancelled account page.
- Request immediate erasure (Art. 17 GDPR): Permanently delete all their data immediately, without waiting for the 90-day retention cycle, from the settings page or by contacting privacy [arroba] citaflow [punto] com .
8. Security
Encryption in transit and at rest, access controls with MFA and RBAC, project segregation, logging and monitoring, periodic security testing, vulnerability management, backups, and incident response plan.
9. Your Rights
If GDPR applies, you may request: access, rectification, deletion, restriction, portability, and objection, as well as not to be subject to solely automated decisions when they produce legal or similar effects. You may also withdraw your consent at any time.
CitaFlow respects all the data subject rights listed above and does not perform any profiling or automated decision-making that produces legal or similarly significant effects on individuals.
How to exercise them: You can exercise your portability (data export) and erasure (account deletion) rights directly from your dashboard under Settings > Billing, without needing to contact us. For any other rights, write to us at privacy [arroba] citaflow [punto] com . We may request reasonable additional information to verify your identity, avoiding unnecessary documents. We will respond within one month, extendable in complex cases.
Complaints: You may file a complaint with your local supervisory authority in the EEA. You may also contact our EU representative (see section 12).
9.1 Marketing Communications: Consent and Opt-out
To send you marketing communications (promotions, news) we will ask for your explicit consent at the point where we capture your data (public booking form, embed, manual entry from the business dashboard, import with a declaration from the controller). Every change to your consent status is recorded in our audit trail with the date, source and, where applicable, a hash of the text you saw when accepting (Art. 7.1 GDPR).
You can withdraw your consent at any time through any of these channels:
- Public page, no account needed: citaflow.com/en/legal/opt-out (email or phone number only).
- WhatsApp: sending
STOPorBAJAto the business's number, or using WhatsApp's option to stop receiving marketing messages (Meta notifies us automatically). - Telegram: sending
STOPorBAJAto the business's bot. - Email: to privacy [arroba] citaflow [punto] com .
Opting out of marketing does not affect transactional notifications (appointment confirmations, reminders, payment notifications), which are justified by the provision of the service (Art. 6.1.b GDPR).
10. Minors
The service is not directed at minors. We do not knowingly collect data from minors below the applicable age of consent in your country.
11. Breach Notification
When we act as data controller: We will notify the competent supervisory authority within 72 hours of becoming aware of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals. If there is high risk, we will inform affected individuals without undue delay.
When we act as data processor: When we process data on behalf of our customers, we will notify the customer (as data controller) without undue delay upon becoming aware of a personal data breach affecting their data. We will provide the customer with information necessary to fulfill their notification obligations to authorities and affected individuals. The customer, as data controller, is responsible for making notifications to supervisory authorities and data subjects.
12. Representative in the European Union
Pursuant to Article 27 of the GDPR, we have designated Guillermo Garcia Diaz as our representative in the European Union for data protection matters. The representative acts as a point of contact for EU data protection authorities and for data subjects who wish to exercise their rights in relation to personal data processing. Reachable at Polígono Industrial Les Tàpies, Calle Gil Vernet 54/55 - B #2115, L'Hospitalet de l'Infant, T 43890, Spain, or via privacy [arroba] citaflow [punto] com .
13. Regional Information
13.1 European Economic Area
- Legal basis, rights, and complaints as indicated above.
- International transfers with appropriate safeguards.
- We may request that certain customers conduct a data protection impact assessment when their configuration involves high risk.
13.2 United Kingdom
- If you are in the United Kingdom, processing is governed by the UK GDPR and the Data Protection Act 2018, and you have rights equivalent to those described in section 9.
- You may lodge a complaint with the Information Commissioner's Office (ICO, ico.org.uk). You can also send any complaint to privacy [arroba] citaflow [punto] com ; we will acknowledge receipt and respond within the statutory timeframes.
- International transfers from the United Kingdom rely on the UK Extension to the EU-U.S. Data Privacy Framework or on the ICO's International Data Transfer Addendum, depending on the provider.
13.3 Spanish-speaking LATAM Countries
We will honor the applicable rights in each jurisdiction and, when necessary, make adapted local notices available. If local regulations require additional requirements, we will communicate them in customer agreements and product documentation.
14. Cookies and Analytics
We use cookies and similar technologies according to the following categories:
Essential: necessary to operate the service, for example authentication, security, fraud prevention, and load balancing. Always active.
Analytics: we use Umami configured without cookies and with aggregated data. It does not create profiles for advertising and does not track across sites. Depending on implementation and your local authority's guidance, some cookie-less measurements may require consent. When necessary, we will request your consent before activating non-essential analytics.
Marketing: we may use Meta Pixel and TikTok Pixel for campaign measurement and retargeting. In the EEA, the United Kingdom, and countries with similar requirements, these pixels are only loaded after your consent through the cookie banner or preference center settings. The Google Ads tag loads in consent mode (Consent Mode v2) with consent denied by default; it only measures conversions with cookies if you accept. You may withdraw your consent at any time and we will stop using these tags.
First-party attribution: we use our own first-party visit-source identifiers, not shared with advertising networks, to know which channel brought you to us; details are in the Cookie Policy.
Preference Management: we display a cookie banner with granular control and a preference center where you can change your choice at any time. Until you grant your consent, marketing tags do not set cookies or send advertising identifiers.
Details of providers, purposes, and retention periods are in the Cookie Policy.
15. Changes
We will post any changes on this page and attempt to notify by email or within the product when there are substantial modifications. We will indicate the date of last update.
16. Contact
Privacy: privacy [arroba] citaflow [punto] com
General: contact [arroba] citaflow [punto] com
Postal Address: Lince Media LLC, 25 SE 2nd Ave, Ste 550 #1172, Miami, FL 33131, U.S.A.
Annex A. Recommended Configuration Controls for Customers
- Keep the AI notice in calls and chat: it is enabled by default and must not be removed (Regulation (EU) 2024/1689, Art. 50). If you customize your welcome messages, do not remove the assistant's identification as AI.
- Inform your own clients that their data is processed with CitaFlow as a processor (Art. 13/14 GDPR), for example in your privacy policy or at the booking point.
- Configure consent for recording when required by your country.
- If you enable advertising pixels on your booking page or landing page, obtain your visitors' consent in accordance with the applicable cookie regulations.
- Define retention periods in accordance with the minimization principle.
- Limit access and enable 2FA for internal users.
- Periodically review the activity log and integration inventory.
Annex B. Key Provider List and References
Supabase, Hetzner, Railway, Cloudflare, Twilio, OpenAI, Google, Stripe, Brevo, SendGrid, BulkGate, Sentry, Axiom. Consult their DPAs and sub-processors on their trust pages. We will update this list when there are relevant changes.
Data Processing Agreement
Data Processing Agreement / Acuerdo de Tratamiento de Datos (DPA/ATD)
Between:
- Customer identified in the Service Order, acting as data controller or as upper-level processor, as applicable, on its own behalf and on behalf of its affiliates that use the Service ("Customer").
- Lince Media LLC, doing business as CitaFlow, 25 SE 2nd Ave, Ste 550 #1172, Miami, FL 33131, United States ("Provider" or "CitaFlow").
Term: from the effective date of the Service Order and for as long as CitaFlow processes Personal Data on behalf of the Customer.
1. Subject Matter and Nature of Processing
CitaFlow will process personal data on behalf of the Customer to provide the SaaS platform for appointment management and communications, its voice, chat, messaging, and operational analytics functionalities. Processing includes hosting, transmission, storage, indexing, optional transcription, generation of responses through artificial intelligence models of the listed sub-processors, messaging, support, and security measures.
2. Categories of Data Subjects and Types of Data
Data Subjects: Customer's users, Customer's personnel, Customer's clients and potential clients, individuals who call or write to the numbers or channels operated by the Customer.
Data: contact data, account identifiers, communication metadata, message and chat conversation content, recordings and transcriptions if enabled, appointments and calendars, staff time-tracking records if the Customer enables the Team module, preferences, incidents, and technical logs. The Customer shall not introduce special categories unless permitted by law and explicitly configured.
3. Instructions and Compliance
CitaFlow will only process data in accordance with the Customer's documented instructions, including this DPA and the Contract. If an instruction violates regulations, CitaFlow will notify when it becomes aware. The Customer is responsible for the lawfulness of processing and obtaining consent when appropriate.
4. Confidentiality
CitaFlow will ensure that persons authorized to process data commit to confidentiality and receive appropriate training.
5. Security
CitaFlow will implement appropriate technical and organizational measures, including encryption in transit and at rest, role-based access controls, multi-factor authentication for administrative access, logging and monitoring, vulnerability management, encrypted backups, and incident response plans. A security measures annex may be updated to reflect improvements without reducing the level of protection.
6. Sub-processors
The Customer authorizes the use of sub-processors for necessary activities. CitaFlow will ensure that written contracts exist imposing obligations equivalent to this DPA. Current list: Supabase, Hetzner, Railway, Cloudflare, Twilio, OpenAI, Google, Stripe, Brevo, SendGrid, BulkGate, Sentry, and Axiom. AI model providers are used through their business APIs, whose terms exclude the use of Customer data to train their models. CitaFlow will notify changes with reasonable advance notice and the Customer may object for reasonable grounds. If the parties do not find a viable alternative, the Customer may terminate the affected part of the Service without penalty.
7. Assistance to Customer
CitaFlow will assist the Customer, to the extent reasonable and at proportionate cost, to respond to data subject rights requests and comply with security, breach notification, impact assessment, and prior consultation obligations to authorities.
8. Security Breaches
CitaFlow will notify the Customer without undue delay of a security breach affecting data processed on behalf of the Customer, providing available information to help the Customer comply with notification obligations.
9. International Transfers
When access or transfer involves a country without an adequacy decision, the Standard Contractual Clauses approved by Decision (EU) 2021/914, Module 2 or Module 3 as applicable, will apply, incorporated by reference. When the recipient is certified under the EU-U.S. Data Privacy Framework, the transfer may rely on that adequacy decision, keeping the SCCs as a fallback safeguard. The parties accept the docking clause, standard definitions, and appendices. CitaFlow will apply additional safeguards, such as encryption in transit and at rest, strict access controls, and internal policies limiting government requests.
10. Audits
Upon request and at most once a year, CitaFlow will make available necessary information to demonstrate compliance, including summaries of third-party audits. On-site audits will be coordinated with at least 30 days' advance notice, will be limited to reasonably necessary areas, and will be subject to confidentiality obligations and reasonable support fees.
11. Deletion or Return
Upon termination of the service or at the Customer's request, CitaFlow will delete or return personal data, except for minimum retention necessary for legal obligations or defense of claims. Backups are deleted at the end of their cycle.
12. Liability and Priority
CitaFlow's total liability under this DPA is limited according to the main Contract. In case of conflict between this DPA and the Contract, this DPA will prevail regarding data processing. If there is conflict between this DPA and the SCCs, the SCCs will prevail.
13. Applicable Law and Jurisdiction
When the SCCs apply, the law and competent courts will be those designated in the SCCs. For the rest, the law and jurisdiction agreed in the main Contract will apply.
DPA Annexes
Security Annex: description of current technical and organizational measures.
Sub-processors Annex: updated list available upon request or on the Provider's legal page.