{
  "version": "2026-04-24",
  "processors": [
    {
      "name": "Amazon Web Services (AWS)",
      "role": "Primary cloud infrastructure",
      "purpose": "RDS (PostgreSQL primary database), S3 (object storage for telemetry), EC2/EKS (compute), CloudWatch (operational logs), VPC and IAM (network and access control).",
      "dataCategories": [
        "account_data",
        "billing_data",
        "telemetry_data",
        "audit_data",
        "consent_data"
      ],
      "location": "Ireland (eu-west-1) primary; per-tenant regions for telemetry storage, for example ap-south-1.",
      "transferMechanism": "SCCs incorporated into AWS GDPR DPA",
      "dpaUrl": "https://aws.amazon.com/compliance/gdpr-center/"
    },
    {
      "name": "AWS Cognito",
      "role": "Identity provider",
      "purpose": "OIDC sign-in for portal users. xScaler does not store passwords for SSO users; Cognito holds password hashes for any users on the local-credentials path created via Cognito.",
      "dataCategories": [
        "account_data"
      ],
      "location": "per Cognito user pool region.",
      "transferMechanism": "SCCs (AWS GDPR DPA)",
      "dpaUrl": "https://aws.amazon.com/compliance/gdpr-center/"
    },
    {
      "name": "Stripe Payments Europe, Ltd.",
      "role": "Billing and payment processing",
      "purpose": "Subscription management, invoice generation, payment-method storage, tax handling.",
      "dataCategories": [
        "billing_data",
        "account_data"
      ],
      "location": "EU + US",
      "transferMechanism": "SCCs incorporated into Stripe DPA",
      "dpaUrl": "https://stripe.com/legal/dpa"
    },
    {
      "name": "Zoho Corporation B.V.",
      "role": "Customer support ticketing",
      "purpose": "Inbound and outbound support communication, ticket history, attachments uploaded by customers.",
      "dataCategories": [
        "support_data",
        "account_data"
      ],
      "location": "per Zoho EU data center (configurable)",
      "transferMechanism": "SCCs incorporated into Zoho DPA",
      "dpaUrl": "https://www.zoho.com/gdpr.html"
    },
    {
      "name": "Amazon SES",
      "role": "Transactional email delivery",
      "purpose": "Outbound delivery of account-related email: invitations, email change verifications, alert notifications.",
      "dataCategories": [
        "account_data",
        "support_data"
      ],
      "location": "per SES region; documented per env in the operator runbook.",
      "transferMechanism": "SCCs incorporated into AWS GDPR DPA",
      "dpaUrl": "https://aws.amazon.com/compliance/gdpr-center/"
    }
  ]
}
