Current register
| Provider | Purpose and data | Location/transfer position | Role |
|---|---|---|---|
| Google Cloud | Region-selected compute, networking, databases, and encrypted metadata storage. | EU or US region selected for content; provider support and metadata may involve other approved locations under contractual safeguards. | Subprocessor for hosted infrastructure. |
| Cloudflare | Firewall, denial-of-service protection, load balancing, and regional edge handling. | Configured regional controls keep decrypted XBRL content inside the selected EU or US boundary. | Subprocessor for hosted network security. |
| Supabase | Authentication and user-directory services for platform and management accounts, including user ID, email, authentication credential and password verifier, confirmation and recovery state, administrator metadata, sessions, and sign-in/security events. Supabase does not receive submitted XBRL files or validation results through this integration. | Account and authentication records are stored in the selected Supabase project region; limited support and operational processing may occur in other locations under Supabase’s contractual transfer safeguards. | Processor/service provider for EasyBRL account data and subprocessor for customer-authorized user account data. |
| Stripe | Checkout, payment method, invoices, subscriptions, refunds, and fraud prevention. | Global payment infrastructure with contractual transfer safeguards. | Processor/service provider for EasyBRL and independent controller where required for payment compliance. |
| Google advertising and analytics | Consented website measurement, advertising, device/browser and interaction data; never XBRL files, validation results, portal content, or API keys. | May process globally under Google’s applicable safeguards. | Independent controller or provider for consented website activity; not an enterprise API subprocessor. |
Change notice
EasyBRL will give enterprise customers at least 30 days’ advance notice before authorizing a new subprocessor to process Customer Data. Notice may be sent to the account email or portal and will identify the provider, purpose, and processing location.
Objections
A customer may object during the notice period on reasonable data-protection grounds by emailing [email protected]. The parties will try to use a commercially reasonable alternative. If none is available, the customer may terminate the affected service and receive a prorated refund of its unused prepaid portion.
Transfer safeguards
EasyBRL uses data-processing agreements and, where required, the EU Standard Contractual Clauses, UK transfer addendum, regional controls, encryption, access restrictions, and provider transfer documentation. A customer may request relevant contractual information subject to confidentiality.
Contact
Questions about this document can be sent through the contact form or to [email protected].