To run Qoyla, we rely on a small set of trusted vendors. Here is every one of them, what they handle, and where they sit. We keep the list short on purpose, and we vet each one before they touch any data.
Every subprocessor is bound by data-protection terms no less protective than our own. We give customers advance notice before adding a new one, so you can object on reasonable grounds. See the DPA for the full mechanism.
Core infrastructure
| Subprocessor | What they do | Data handled | Region |
|---|---|---|---|
| Cloud Hosting Provider | Primary application and database hosting | All service data (encrypted) | EU · NG region |
| Object Storage | Encrypted document and export storage | Exports, attachments | EU |
| CDN & Edge | Content delivery and DDoS protection | Request metadata | Global |
Financial connectivity
| Subprocessor | What they do | Data handled | Region |
|---|---|---|---|
| Open Banking Aggregator | Licensed read-only account connectivity | Account & transaction data | NG |
| Identity Verification | KYC and identity checks | Identity documents | NG · EU |
| Payments Rail Partner | Executes approved instructions via your bank | Instruction metadata | NG |
Operations & communications
| Subprocessor | What they do | Data handled | Region |
|---|---|---|---|
| Email & Notifications | Transactional email and push delivery | Email, device tokens | EU |
| Support Platform | Customer support conversations | Contact details, messages | EU |
| Product Analytics | Privacy-respecting, aggregate usage analytics | De-identified usage | EU |
Vendor names are generalised on this public page; the specific legal entities are named in the contractual subprocessor schedule available to customers under the DPA.
Subscribe and we will email you whenever we propose adding or replacing a subprocessor, before it goes live, so you always have time to review.