Chamelix

Subprocessors

Last updated: 19/08/2026

ArizenLab S.r.l.s., which operates the Chamelix Platform, uses a small number of third-party service providers ("subprocessors") to operate the Platform. This page lists the subprocessors that may process personal data on our behalf, the purpose of each, the categories of data involved, and the status of the data-protection agreements in place.

The set of subprocessors below is derived from the Platform's actual integrations. The Region column states where data is actually stored and processed, verified against the real configuration of our accounts rather than against a provider's marketing material.

An EU region does not mean "no transfer". Several providers keep data inside the European Union while being US companies: their support and administration functions may reach it from the United States. For those, we state both the storage region and the contractual safeguard covering that remote access.

Current subprocessors

| Provider | Purpose | Data processed | Region | Transfer safeguard | | --- | --- | --- | --- | --- | | Vercel Inc. (Delaware, USA) | Application hosting | Request data, application logs | Frankfurt, Germany (EU). The CDN serving static assets remains global | 2021 Standard Contractual Clauses (Modules 2 and 3, per processing role), incorporated in the Vercel DPA, covering the CDN and administrative access from the US | | Databricks, Inc. / Neon | Database | All persisted personal data, including membership and audit records | Frankfurt, Germany (EU) | Neon DPA, which incorporates the Databricks master agreement, covering administrative access from the US | | Google Ireland Ltd / Google LLC (Firebase, Cloud Storage) | Private file storage | Profile images and user-uploaded attachments | Milan, Italy (EU) | Google Cloud DPA with Standard Contractual Clauses; Google LLC participates in the EU-US Data Privacy Framework | | Functional Software, Inc. (Sentry) | Error monitoring | Error events (PII-scrubbed), pseudonymized identifiers | EU region (Germany) | EU-US Data Privacy Framework as the primary safeguard, Standard Contractual Clauses as fallback (Sentry DPA) | | Plus Five Five, Inc. (Resend) | Transactional email delivery | Email address, message content | United States — no EU region available | EU-US Data Privacy Framework (certified) and Standard Contractual Clauses (Modules 2 and 3, per processing role) (Resend DPA) | | Meta Platforms Ireland Ltd (WhatsApp Cloud API) | Transactional messages, where enabled by an organization | Phone number (hashed at rest), message template parameters | United States | Meta's European Data Transfer Addendum, applicable to transfers originating in the EU/EEA | | Google Ireland Ltd (OAuth, Maps, Analytics) | Social login, address lookup, consent-based analytics | Email/profile (login), address strings (maps), pseudonymous usage (analytics, consent only) | United States | Standard Contractual Clauses; Google LLC participates in the EU-US Data Privacy Framework | | Stripe Payments Europe Ltd | Payments and subscription billing | Billing identity, customer identifiers | — | Integration not active. Payments are disabled on the Platform; no data is sent to Stripe |

We may also use an SMTP provider as a fallback for email delivery; where this is active it processes the same categories as our primary email subprocessor.

Integrations and channels you enable

Some data flows depend on your choice, or your organization's, rather than ours:

  • Sign in with Google: if you choose Google sign-in instead of email and password, Google receives the authentication request on your instruction.
  • WhatsApp reminders: the channel is enabled per organization in its own settings; where disabled, no data reaches Meta.

In these cases data reaches the provider because you or your organization asked for it, and disabling the feature stops the flow. We still list them in the table above, with their safeguards, for completeness.

Changes to this list

When we add or replace a subprocessor, we update this page and provide business customers with the prior notice agreed in their Data Processing Addendum. If you are a business customer and would like to be notified of subprocessor changes, contact us at the address below.

Change log

  • 19/08/2026 — Simplified purpose descriptions and removed internal technical details; added the user-enabled integrations section. No provider changes.
  • 11/08/2026 — Storage regions verified against the actual provider account configuration.

Contact

Questions about subprocessors: app@chamelix.it

The operating system for local organizations — bookings, members, documents and reminders in one place.

Via Padova 20, 36010 Zanè (VI), Italia

app@chamelix.it

VAT: 04578500243

© 2025-2026. All rights reserved