Skip to main content

Data Processors (Art. 28 GDPR)

Last updated: March 1, 2026

OpenHospi uses the following third-party processors for the processing of personal data. All processors are located within the EU/EEA. No personal data is transferred outside the European Economic Area.

1. Supabase (Database & Storage)

RoleProcessor: database hosting (PostgreSQL) and file storage (profile photos, room photos)
LocationDublin, Ireland (eu-west-1)
Data processedAll personal data stored in the database, uploaded photos
Data processing agreementData processing agreement pursuant to Art. 28 GDPR in place (Supabase Data Processing Agreement)
SecurityEncryption at rest and in transit, SOC 2 Type II certified

2. Vercel (Web Hosting & Edge)

RoleProcessor: web application hosting, serverless functions, edge network
LocationDublin, Ireland (eu-west-1)
Data processedHTTP requests (IP address, user agent) in server logs
Data processing agreementData processing agreement pursuant to Art. 28 GDPR in place (Vercel Data Processing Addendum)
SecurityAutomatic HTTPS, DDoS protection, SOC 2 Type II certified

3. Upstash (Redis: Rate Limiting)

RoleProcessor: Redis database for rate limiting and abuse prevention
LocationIreland (AWS eu-west-1)
Data processedAnonymised rate limit counters (user ID hashes). No personal data stored
Data processing agreementData processing agreement pursuant to Art. 28 GDPR in place (Upstash DPA)
SecurityEncryption at rest and in transit

5. Sentry (Crash Reporting)

RoleProcessor: crash reporting and error monitoring
LocationFrankfurt, Germany (eu-central-1)
Data processedError events, stack traces, device model, OS version, app version. No personal data: sendDefaultPii disabled, IP stripping enabled, no session replay, no user tracking
Data processing agreementData processing agreement pursuant to Art. 28 GDPR in place, with Standard Contractual Clauses (SCCs)
Retention90 days
SecurityEncryption at rest and in transit. Sentry's internal organisational metadata (developer accounts, project configs (no end-user data)) may be replicated to the US per Sentry's infrastructure

6. Expo/EAS (Mobile App Distribution)

RoleProcessor: mobile app builds, over-the-air (OTA) updates, and app distribution
LocationUnited States (Google Cloud Platform). Build servers process only app source code and produce binaries. No personal end-user data is involved
Data processedApp source code, JavaScript bundles, build metadata. No personal data collected from end users
Data processing agreementExpo Terms of Service and Privacy Policy apply. Expo complies with the EU-US Data Privacy Framework and uses Standard Contractual Clauses (SCCs) for international transfers
GDPR relevanceNo personal end-user data is transferred to or processed on EAS build servers. Only app source code and bundles are processed. Expo's international transfer safeguards (EU-US DPF, SCCs) provide additional protection per Art. 45-46 GDPR
SecuritySigned updates, HTTPS-only delivery, code signing for OTA updates