Legal
Sub-processors
Genorah Labs engages third-party service providers ("sub-processors") to assist in delivering our services. These sub-processors may process personal data on our behalf in accordance with our instructions and applicable data protection laws, including GDPR Article 28 and Indonesian PP No. 71/2019.
All sub-processors are bound by Data Processing Agreements (DPAs) that require them to:
- Process personal data only on our documented instructions
- Ensure personnel are bound by confidentiality obligations
- Implement appropriate technical and organizational security measures
- Notify us promptly of any personal data breaches
- Assist us in responding to data subject rights requests
- Return or delete all personal data upon termination of services
- Submit to audits and inspections as required by GDPR Article 28(3)(h)
Where sub-processors are located outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, primarily through Standard Contractual Clauses (SCCs) approved by the European Commission.
Current sub-processors
| Sub-processor | Purpose | Location | Data types | Safeguards |
|---|---|---|---|---|
| Supabase | Database, authentication, storage, and edge functions (portal, forms, CRM) | United States (AWS) | Account data, Form submissions, Uploaded documents, Auth credentials | Standard Contractual Clauses (SCCs), SOC 2 Type II, encryption at rest and in transit |
| Resend | Transactional email delivery (contact, careers, booking notifications and replies) | United States | Email addresses, Message content, Delivery metadata | SCCs, TLS in transit, DPA in place |
| Netlify | Web hosting, CDN, and serverless functions | United States / Global CDN | Access logs, IP addresses, Request metadata | SCCs, SOC 2 Type II, TLS in transit, DPA in place |
| Cloudflare (Turnstile) | Bot protection / CAPTCHA on public forms | Global (edge) | IP address, Challenge tokens, Browser signals | SCCs, privacy-preserving challenge (no third-party tracking cookies), DPA in place |
| Spline | Interactive 3D scene rendering assets embedded on marketing pages | United States | Access logs, IP address (asset fetch) | TLS in transit; loaded only for cosmetic scene assets |
| Microsoft (Graph API) | Meeting scheduling and calendar availability for the booking flow | European Union / United States | Name, Email address, Meeting metadata | SCCs, ISO 27001, encryption at rest and in transit, DPA in place |
| Plausible Analytics | Privacy-first, cookieless website analytics — no consent required; loaded on every page | European Union | Aggregated page views, Referrer, Device class (no personal identifiers) | EU-hosted, no cookies, no cross-site tracking, GDPR-aligned by design |
Changes to sub-processors
We review our sub-processor list regularly. If we add or replace a sub-processor that processes personal data, we will notify affected clients via email at least 30 days in advance, where required by our Data Processing Agreement or applicable law.
Clients may object to a new sub-processor by contacting our Data Protection Officer within 14 days of notification. If we cannot address your concerns, you may terminate the affected services without penalty, subject to the terms of your service agreement.
Questions about this policy?
Our legal team is here to help. Reach out for any privacy, compliance, or legal inquiries.
Office
Jakarta, Indonesia
Response Time
Ack: 3×24h / Fulfill: 14 days
Office Hours
Mon–Fri, 09:00–18:00 WIB