GIORIZZ
Documento attualmente in ingleseQuesto documento legale è mantenuto in un'unica versione di riferimento in lingua inglese. Una traduzione italiana certificata è in fase di preparazione. Per il testo legale integrale e attuale, fai riferimento alla versione inglese: Leggi la versione in inglese →

Elenco dei Sub-responsabili del Trattamento

Last updated: March 2026

Pursuant to GDPR Article 28 and applicable data protection legislation

1. Overview

GIORIZZ S.r.l. (“we”, “us”, “our”) engages the following sub-processors to assist in the delivery of our luxury chauffeur booking platform and related services. Each sub-processor has been assessed for compliance with applicable data protection requirements and is bound by a Data Processing Agreement (DPA) in accordance with GDPR Article 28.

This page is maintained as a living document. We will notify registered users and agency partners of any changes to this list at least 30 days before the new sub-processor begins processing personal data, as required by our Privacy Policy and Agency Terms.

2. Current Sub-processors

Sub-processorPurposeData CategoriesLocationTransfer Mechanism
Stripe, Inc.Payment processing, invoicing, and fraud preventionPayment card data (tokenised), billing address, transaction amounts, invoice recordsUnited States (with EU data residency option)EU SCCs (Commission Decision 2021/914)
Supabase, Inc. (hosted on AWS)Database hosting, authentication, and row-level securityAccount data, booking records, driver profiles, agency data, communication logsEU (AWS eu-central-1, Frankfurt)EU data residency (no transfer outside EEA)
Resend, Inc.Transactional email delivery (booking confirmations, invoices, account notifications)Email address, name, email content (booking details)United StatesEU SCCs (Commission Decision 2021/914)
Twilio, Inc.SMS notifications (booking updates, OTP verification)Phone number, message content (booking status, OTP codes)United States (with EU processing available)EU SCCs (Commission Decision 2021/914)
Vercel, Inc.Web application hosting, serverless function execution, edge CDNIP address, request metadata, server-side rendered page dataGlobal edge network (primary: US East)EU SCCs (Commission Decision 2021/914)
Cloudflare, Inc.Security (Turnstile CAPTCHA), DDoS protection, CDNIP address, browser fingerprint (anonymised), CAPTCHA interaction dataGlobal edge networkEU SCCs (Commission Decision 2021/914)

3. Data Processing Details

Stripe, Inc.

PurposePayment processing, invoicing, and fraud prevention
Data CategoriesPayment card data (tokenised), billing address, transaction amounts, invoice records
Data SubjectsCustomers (B2C), agency partners (B2B)
Processing LocationUnited States (with EU data residency option)
Transfer MechanismEU SCCs (Commission Decision 2021/914)
DPA StatusExecuted
CertificationsPCI DSS Level 1, SOC 1/2, ISO 27001

Supabase, Inc. (hosted on AWS)

PurposeDatabase hosting, authentication, and row-level security
Data CategoriesAccount data, booking records, driver profiles, agency data, communication logs
Data SubjectsCustomers, chauffeur partners, agency partners, concierge accounts
Processing LocationEU (AWS eu-central-1, Frankfurt)
Transfer MechanismEU data residency (no transfer outside EEA)
DPA StatusExecuted
CertificationsSOC 2 Type II, ISO 27001 (AWS infrastructure)

Resend, Inc.

PurposeTransactional email delivery (booking confirmations, invoices, account notifications)
Data CategoriesEmail address, name, email content (booking details)
Data SubjectsCustomers, chauffeur partners, agency partners
Processing LocationUnited States
Transfer MechanismEU SCCs (Commission Decision 2021/914)
DPA StatusExecuted
CertificationsSOC 2 Type II

Twilio, Inc.

PurposeSMS notifications (booking updates, OTP verification)
Data CategoriesPhone number, message content (booking status, OTP codes)
Data SubjectsCustomers, chauffeur partners
Processing LocationUnited States (with EU processing available)
Transfer MechanismEU SCCs (Commission Decision 2021/914)
DPA StatusExecuted
CertificationsSOC 2 Type II, ISO 27001, PCI DSS

Vercel, Inc.

PurposeWeb application hosting, serverless function execution, edge CDN
Data CategoriesIP address, request metadata, server-side rendered page data
Data SubjectsAll website visitors
Processing LocationGlobal edge network (primary: US East)
Transfer MechanismEU SCCs (Commission Decision 2021/914)
DPA StatusExecuted
CertificationsSOC 2 Type II, ISO 27001

Cloudflare, Inc.

PurposeSecurity (Turnstile CAPTCHA), DDoS protection, CDN
Data CategoriesIP address, browser fingerprint (anonymised), CAPTCHA interaction data
Data SubjectsAll website visitors (signup flow)
Processing LocationGlobal edge network
Transfer MechanismEU SCCs (Commission Decision 2021/914)
DPA StatusExecuted
CertificationsSOC 2 Type II, ISO 27001, PCI DSS

4. International Transfer Mechanisms

Where personal data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place in compliance with GDPR Chapter V (Articles 44–49):

  • EU Standard Contractual Clauses (SCCs) — Commission Implementing Decision (EU) 2021/914, used for transfers to the United States and other countries without an EU adequacy decision
  • UK International Data Transfer Agreement (IDTA) — or UK Addendum to EU SCCs, as approved by the ICO, for transfers involving UK personal data
  • Swiss Addendum — EU SCCs with Swiss-specific modifications recommended by the FDPIC, for transfers involving Swiss personal data
  • ANPD Standard Contractual Clauses — in force since August 2025, for transfers involving personal data of Brazilian data subjects under the LGPD
  • Adequacy Decisions — where the European Commission, UK Government, or other relevant authority has issued an adequacy decision for the destination country, transfers proceed without additional contractual safeguards

We regularly review the legal landscape and will update transfer mechanisms as required by supervisory authority guidance or court rulings.

5. Change Notification Process

In accordance with GDPR Article 28(2) and our contractual obligations, we follow this process when engaging a new sub-processor or making material changes to an existing sub-processor relationship:

StepActionTimeline
1Vendor due diligence and security assessmentBefore engagement
2DPA execution with new sub-processorBefore processing begins
3Notification to registered users and agency partners via email30 days before processing begins
4Update this sub-processor list pageSame day as notification
5Objection window for agency partners30 days from notification

Right to object: Agency partners under a Data Processing Agreement may object to the engagement of a new sub-processor within 30 days of notification. If no reasonable resolution can be reached, the agency partner may terminate the affected services in accordance with the Agency Terms.

6. Our Obligations

For each sub-processor, GIORIZZ ensures:

  • Written DPA imposing equivalent data protection obligations to those in our own processing agreements (GDPR Art 28(4))
  • Due diligence on the sub-processor’s technical and organisational security measures before engagement
  • Ongoing monitoring of sub-processor compliance through audit rights, certifications review, and incident response procedures
  • Liability — GIORIZZ remains fully liable for the performance of its sub-processors (GDPR Art 28(4))
  • Data minimisation — each sub-processor receives only the minimum personal data necessary for its designated processing purpose
  • Incident response — sub-processors are contractually required to notify GIORIZZ of any personal data breach within 24 hours of discovery

7. Audit Rights

In accordance with GDPR Article 28(3)(h), controllers and their authorised representatives have the right to audit GIORIZZ’s use of sub-processors. For agency partners, audit rights are governed by Section 9.2 of the Agency Terms.

Audit requests should be directed to:

  • Email: info@giorizz.com
  • Subject: Sub-processor Audit Request — [Organisation Name]

8. Contact

For questions about our sub-processors or to subscribe to change notifications:

Data Protection Emailinfo@giorizz.com
General Supportinfo@giorizz.com
Postal AddressGIORIZZ S.r.l., Via Alcibiade 8, Siracusa (SR), Italy

Related documents: