Legal

Sub-processors

Last updated July 8, 2026

Genorah Labs engages third-party service providers ("sub-processors") to assist in delivering our services. These sub-processors may process personal data on our behalf in accordance with our instructions and applicable data protection laws, including GDPR Article 28 and Indonesian PP No. 71/2019.

All sub-processors are bound by Data Processing Agreements (DPAs) that require them to:

  • Process personal data only on our documented instructions
  • Ensure personnel are bound by confidentiality obligations
  • Implement appropriate technical and organizational security measures
  • Notify us promptly of any personal data breaches
  • Assist us in responding to data subject rights requests
  • Return or delete all personal data upon termination of services
  • Submit to audits and inspections as required by GDPR Article 28(3)(h)

Where sub-processors are located outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, primarily through Standard Contractual Clauses (SCCs) approved by the European Commission.

Current sub-processors

Sub-processor Purpose Location Data types Safeguards
Supabase Database, authentication, storage, and edge functions (portal, forms, CRM) United States (AWS) Account data, Form submissions, Uploaded documents, Auth credentials Standard Contractual Clauses (SCCs), SOC 2 Type II, encryption at rest and in transit
Resend Transactional email delivery (contact, careers, booking notifications and replies) United States Email addresses, Message content, Delivery metadata SCCs, TLS in transit, DPA in place
Netlify Web hosting, CDN, and serverless functions United States / Global CDN Access logs, IP addresses, Request metadata SCCs, SOC 2 Type II, TLS in transit, DPA in place
Cloudflare (Turnstile) Bot protection / CAPTCHA on public forms Global (edge) IP address, Challenge tokens, Browser signals SCCs, privacy-preserving challenge (no third-party tracking cookies), DPA in place
Spline Interactive 3D scene rendering assets embedded on marketing pages United States Access logs, IP address (asset fetch) TLS in transit; loaded only for cosmetic scene assets
Microsoft (Graph API) Meeting scheduling and calendar availability for the booking flow European Union / United States Name, Email address, Meeting metadata SCCs, ISO 27001, encryption at rest and in transit, DPA in place
Plausible Analytics Privacy-first, cookieless website analytics — no consent required; loaded on every page European Union Aggregated page views, Referrer, Device class (no personal identifiers) EU-hosted, no cookies, no cross-site tracking, GDPR-aligned by design

Changes to sub-processors

We review our sub-processor list regularly. If we add or replace a sub-processor that processes personal data, we will notify affected clients via email at least 30 days in advance, where required by our Data Processing Agreement or applicable law.

Clients may object to a new sub-processor by contacting our Data Protection Officer within 14 days of notification. If we cannot address your concerns, you may terminate the affected services without penalty, subject to the terms of your service agreement.

Questions about this policy?

Our legal team is here to help. Reach out for any privacy, compliance, or legal inquiries.

Office

Jakarta, Indonesia

Response Time

Ack: 3×24h / Fulfill: 14 days

Office Hours

Mon–Fri, 09:00–18:00 WIB