Document control
| Item | Detail |
|---|---|
| Document | Sub-processors and where data goes (document id: subprocessors) |
| Version | 1.1 |
| Status | Draft pending legal review |
| In force from | xxxxxxx |
| Last updated | xxxxxxx |
| Published by | xxxxxxx ("Procura") |
| Contact | privacy@procuraksa.com |
1. What this page is
Procura uses a small number of outside providers to run the platform. Where a provider handles personal data on Procura's behalf, it acts as a sub-processor under the Data Processing Addendum. This page lists the providers that are in use today, what each does, what data it sees and where, and says plainly which services are not used.
2. Providers in use
| Provider | What it does for Procura | Data involved | Location | Status |
|---|---|---|---|---|
| Render | Hosts the application and its PostgreSQL database. | All data held on the platform: users and organisations, RFQs, encrypted bids, purchase orders, invoices, messages, sessions and the audit trail. | Frankfurt, Germany (European Union), outside the Kingdom | In use |
| SendGrid | Delivers e-mail: sign-in codes and notifications. | The recipient's e-mail address and the content of the message, such as the sign-in code or the notification text. | The provider's own infrastructure. Procura does not choose the region. | In use |
| Google (sign-in) | Optional "Sign in with Google" for people who choose it. | The browser sends Google the sign-in request. Procura receives a signed token that confirms the person's Google e-mail address, and checks it against Google's published public keys. | Google's own infrastructure | In use where enabled; optional for the user |
| Google (fonts) | The pages load their typefaces from Google Fonts. | The visitor's IP address and browser details reach Google when a page loads. | Google's own infrastructure | In use on the pages |
3. Services not used
| Service | Position |
|---|---|
| Payments | None. The platform holds no funds and runs no payment gateway. It records subscription invoices and payment instructions, and payment is made by bank transfer. |
| SMS | None. No text messages are sent. |
| Commercial-registry lookup | None. The registry check is simulated and sends nothing to any registry. |
| Third-party analytics and advertising | None. Measurement is Procura's own counter and runs only if the visitor allows it. |
The platform's code can be set up to use other providers for e-mail, SMS and payments. None of them is switched on. This page is updated before any is.
4. Where data goes
Personal data held on the platform is stored with Render in Frankfurt, so it is held outside the Kingdom. Hosting inside the Kingdom is planned. E-mail passes through SendGrid, and Google sees a visitor's IP address when fonts load and the sign-in request when a person uses Google sign-in. The Privacy Policy and the Data Processing Addendum say how personal data is protected, including when it is transferred abroad.
5. Changes to this list
The list changes when the platform changes. Before a new provider handles personal data, or before any service in section 3 is switched on, Procura updates this page and gives notice to organisation administrators, by e-mail or in the platform. An organisation that objects can write to privacy@procuraksa.com, and the Data Processing Addendum says what follows. Earlier versions of this page are kept and are available on request. Today the notice is given by hand. An automatic notice is planned.
6. Version
This is version 1.0. The Arabic text is the authoritative text, and the English text is provided for convenience. Questions go to privacy@procuraksa.com.