LEGAL & COMPLIANCE

Sub-Processor List

Effective Date: January 2026

SFL Tech ("SFL", "we", "our", "us") engages carefully selected third-party service providers ("Sub-Processors") to support the delivery, maintenance, and improvement of our services. We are committed to transparency, security, and regulatory compliance. This page identifies the categories of Sub-Processors we use and the nature of services they provide in connection with our technology, consulting, and managed services operations.

This page should be read in conjunction with our:

  • Privacy Policy
  • Data Processing Addendum (DPA) and Cookie Policy

1. Our Approach to Sub-Processors

Before engaging any Sub-Processor, SFL Tech:

  • Conducts due diligence and risk assessment
  • Reviews security certifications (e.g., ISO 27001, SOC 2 where applicable)
  • Ensures contractual data protection obligations are in place
  • Requires confidentiality commitments
  • Implements appropriate safeguards for international data transfers

All Sub-Processors are contractually required to process personal data only for specified business purposes and in compliance with applicable data protection laws.

2. Categories of Sub-Processors

Below are the categories of Sub-Processors used by SFL Tech in support of its services.

A. Cloud Infrastructure & Hosting Providers

Purpose: Secure hosting, storage, compute services, and infrastructure management.

Data Processed May Include:

  • Customer system data
  • Contact information
  • Application logs
  • Operational datasets

Examples of Services Provided:

  • Infrastructure-as-a-Service (laaS)
  • Backup and disaster recovery
  • Virtual server hosting
  • Database hosting

Data may be processed in regional data centers depending on client configuration.

B. Email & Communication Service Providers

Purpose: Transactional emails, customer communications, internal collaboration.

Data Processed May Include:

  • Names
  • Email addresses
  • Communication content
  • Metadata

These providers support operational notifications, support communications, and marketing communications where applicable.

C. Analytics & Performance Monitoring Providers

Purpose: Website performance monitoring, usage analytics, system diagnostics.

Data Processed May Include:

  • IP addresses
  • Browser/device information
  • Usage data
  • Log files

These tools help improve system stability, security, and user experience.

D. Customer Support & Helpdesk Platforms

Purpose: Ticketing, issue tracking, customer service management.

Data Processed May Include:

  • Customer contact details
  • Support tickets
  • Communication records
  • Technical logs

These platforms support SFL's managed services and CARE support operations.

E. CRM & Marketing Automation Platforms

Purpose: Customer relationship management, communications, marketing engagement.

Data Processed May Include:

  • Business contact information
  • Job title
  • Company details
  • Interaction history

These systems are used strictly for legitimate business communications and marketing activities in accordance with GDPR and CCPA/CPRA.

F. IT Security & Monitoring Providers

Purpose: Threat detection, endpoint security, vulnerability monitoring.

Data Processed May Include:

  • Log data
  • System access records
  • Security alerts

These providers support cybersecurity posture and incident response capabilities.

G. Professional Services & Advisory Partners

Purpose: Legal, accounting, compliance, and advisory support. Access to personal data (if any) is limited and controlled, and only where necessary for compliance or contractual obligations.

3. International Data Transfers

Where Sub-Processors operate outside the European Economic Area (EEA), United Kingdom, or other jurisdictions with data transfer restrictions:

  • Standard Contractual Clauses (SCCs) or equivalent safeguards are implemented.
  • Transfers comply with GDPR Chapter V requirements.
  • Additional technical and organizational measures may apply where necessary.

4. Sub-Processor Updates

SFL Tech may update this list periodically. If you are a customer and wish to:

  • Receive notice of new Sub-Processors
  • Object to a proposed Sub-Processor (where contractually permitted)
  • Request further information regarding safeguards

Please contact: connectwithus@sfltech.ai

5. Security & Compliance Standards

All Sub-Processors must:

  • Maintain appropriate technical and organizational security measures
  • Limit access to authorized personnel
  • Notify SFL Tech of security incidents without undue delay
  • Comply with applicable data protection laws

SFL Tech remains responsible for ensuring that Sub-Processors meet contractual and regulatory obligations.

6. Contact Information

For questions regarding our Sub-Processors or data protection practices:
SFL Tech
Email: connectwithus@sfltech.ai