Sub-processors
Last updated:
This is an informational translation. The binding version is the Polish original: Podmioty przetwarzające.
What this list covers
To operate HotDesks we use selected providers of infrastructure and technical services. Where a provider processes, on our behalf, data entrusted by a client, we conclude data protection arrangements with it and treat it as a sub-processor within the meaning of Art. 28(4) GDPR.
This list covers only providers that come into contact with data entrusted by a client within the app.hotdesks.pl application. The rules of entrustment, including the procedure for notifying changes to this list, are set out in Annex 1 to the Terms of Service.
Sub-processors
| Provider | Service and purpose | Categories of data | Location of processing | Basis for transfer outside the EEA |
|---|---|---|---|---|
| Microsoft Corporation | Hosting of the application and database in Azure services | All data entered into the application by the client and its users | Azure North Europe region | Not applicable, processing within the EEA |
| Twilio Inc. (SendGrid) | Sending e-mail messages from the application, including invitations and notifications | E-mail address, first name and surname, content of the notification | Data centres in the European Union (EU Data Residency) | Not applicable, processing within the EEA |
| Functional Software, Inc. d/b/a Sentry | Application error monitoring | Technical data about the error and internal identifiers of the user and the company, without first name, surname or e-mail address | Servers in the European Union (Frankfurt, Germany), retention up to 90 days | Not applicable, processing within the EEA |
| reCAPTCHA protecting the login and registration forms in the application | IP address, device and browser parameters | Google’s global infrastructure; processing may take place outside the EEA | EU-US Data Privacy Framework or standard contractual clauses, in accordance with the terms applicable to the given service | |
| Firebase Cloud Messaging, delivery of push notifications to the application | The device token and the internal user identifier used in the device group name, together with the content of the notification: the number or name of the booked resource, the location name and the time. Without first name, surname, e-mail address or vehicle registration number | Google’s global infrastructure; processing may take place outside the EEA | EU-US Data Privacy Framework or standard contractual clauses, in accordance with the Firebase Data Processing and Security Terms |
The Google entity providing a given service depends on the product, the region and the applicable contractual terms. For clients in the European Economic Area this may be in particular Google Ireland Limited, Google LLC or another relevant Google group entity. The details follow from the terms applicable to the given service.
What this list does not cover
Integrations with Microsoft Entra ID and Exchange Online. Signing in with a company account and the room calendar integration operate within the directory and tenant belonging to the client. In that respect the client relies on its own agreement with Microsoft, and HotDesks does not entrust data there as a processor.
Tools on the hotdesks.pl site. Google Tag Manager, Google Analytics and Google Ads operate solely on the marketing site and concern visitor data, in respect of which CodeSpirit is the controller rather than the client. They are therefore not sub-processors of data entrusted by a client. They are described in the Privacy Policy and in the cookie policy.
Changes to this list
We inform clients in advance of any intended addition or replacement of a sub-processor, on the terms set out in Annex 1 to the Terms of Service. A client may raise a reasoned objection concerning data protection.
Questions about this list, including those from IT departments and data protection officers, may be sent to support@hotdesks.pl.