PROIEX Service Providers and Transaction Recipients
Document key: service_provider_list
Document version: 1.1
Effective date: [PUBLICATION DATE]
This list explains the principal external organisations that may receive personal data when [PROIEX EU LEGAL NAME] operates the PROIEX website, accounts and transaction workflows. The provider used in a particular verification or transaction is shown in the relevant interface. A listed optional provider does not receive your data merely because it appears here.
“Processor” means a provider generally acting on PROIEX's instructions. Some providers also act as an independent controller for limited purposes described in their own notice. Transaction professionals such as a notary or bank normally determine their own regulated processing and are not PROIEX subprocessors for that activity.
Identity and trust services
| Provider | Purpose and data | Role and principal location | Transfer/safeguard | Provider information |
|---|---|---|---|---|
| Persona Identities, Inc. | Optional identity and proof-of-address verification; identity/contact data, document images, selfie/liveness/biometric data, device/fraud signals and result | Processor for instructed verification; United States and configured data locations, including Germany | [CONFIRM PROIEX CONTRACT, DATA REGION, DPF/SCC AND SUBPROCESSORS] | https://withpersona.com/legal/privacy-policy |
| Didit Identity Spain, S.L. | Optional identity and proof-of-address verification; identity/contact data, document images, selfie/liveness/biometric data, device/fraud signals and result | Processor for customer verification and a controller for identified security/model/legal purposes; Spain/European data plane, with Didit group or subprocessor access as contracted | EEA processing where configured; [CONFIRM CONTRACT, SUBPROCESSORS, SCC AND ANY US ACCESS] | https://didit.me/terms/privacy-policy/ |
| Docusign International (EMEA) Ltd / [ACTUAL CONTRACTING DOCUSIGN ENTITY] | Electronic/QES workflow, identity verification associated with signing, documents, signatory data and audit trail | Processor/service provider and independent trust-service roles where applicable; Ireland and contracted global infrastructure | Docusign BCRs and [CONFIRM CONTRACTED REGION/DPA] | https://www.docusign.com/privacy |
| notarity GmbH / assigned partner notary | Online appointment/notarial technology where enabled; identity, contact, document, appointment and audiovisual/session information | notarity's role and the independent notary's controller role must be confirmed per workflow; Austria and partner-notary location | EEA unless a disclosed partner/location requires another mechanism | https://notarity.com/webapp-privacy/ |
PROIEX uses either Persona or Didit for a given verification, not both automatically. The current implementation stores normalised provider results in the same PROIEX user fields. For mortgage-document workflows, PROIEX may retrieve and retain full-size identity-document and proof-of-address copies even when the provider has its own retention schedule.
Before Didit is used in production, PROIEX must replace Didit's provider default of unlimited verification-data retention with an approved finite application-level period and test per-session deletion. Before either provider is enabled, PROIEX must record the selected biometric legal basis, retention, data region and subprocessor/transfer terms.
Didit's current notice also describes model training and cross-customer fraud prevention using anonymised or pseudonymised data derived from verification activity, with an opt-out route. PROIEX must assess that independent purpose, the effectiveness of anonymisation, the opt-out and the contracted settings before launch and must communicate any applicable choice in the provider-specific verification notice. Persona's current processor notice states that it does not use verification personal data for AI/model training; that promise must be verified against the signed PROIEX configuration and contract.
Platform, communications and website services
| Provider | Purpose and data | Role/location | Required launch confirmation | Provider information |
|---|---|---|---|---|
| [DATABASE/HOSTING LEGAL ENTITY] | Hosts the PROIEX database, APIs, application and backups; all data necessary for those systems | Processor; [COUNTRIES AND DATA CENTRES] | Article 28 DPA, locations, subprocessors, encryption, deletion/backup cycle, incident notice and SCC/TIA if outside EEA | [PRIVACY/DPA URL] |
| [CPANEL/FILE-HOSTING LEGAL ENTITY] | Stores property, KYB, professional-credential, identity, mortgage, construction-milestone and transaction files and provides signed download links | Processor; [COUNTRIES] | DPA, access logging, isolation, signed-link expiry, backup/deletion, no public paths, transfer mechanism | [PRIVACY/DPA URL] |
| [SMTP/TRANSACTIONAL EMAIL LEGAL ENTITY] | Sends OTP, account, invitation, status and support email; email, name, message and delivery metadata | Processor; [COUNTRIES] | DPA, suppression handling, authentication, retention and subprocessors | [PRIVACY/DPA URL] |
| Amazon Web Services EMEA SARL / [ACTUAL CONTRACTING ENTITY] | AWS SNS telephone/OTP messaging where enabled; telephone, message/OTP metadata and delivery status | Processor; selected AWS region plus contracted support/subprocessors | Confirm region, DPA, data-protection terms, sender identity and SMS downstream carriers | https://aws.amazon.com/privacy/ |
| Usercentrics A/S (Cookiebot) | Consent interface, preference storage and proof of choices; consent identifier, IP/device and choice data as configured | Processor; Denmark and disclosed subprocessors | Confirm DPA, domain configuration, retention and transfers | https://www.cookiebot.com/en/privacy-policy/ |
| Simple Analytics B.V. | Aggregate website audience measurement; standard configuration states no cookies, persistent identifiers or stored IP addresses | Service provider; Netherlands | Confirm the live script uses the documented no-personal-data configuration and no custom events contain personal data | https://docs.simpleanalytics.com/privacy |
| tawk.to, Inc. | Optional live support; IP/device data, contact details and chat contents | Processor for PROIEX chat and controller for limited service purposes; United States/global subprocessors | Prior consent/request gating, DPA, DPF/SCC/TIA, retention and operator-access controls | https://www.tawk.to/privacy-policy/ |
| [WORDPRESS HOST / CMS LEGAL ENTITY] | Hosts public editorial content used by the PROIEX frontend | Processor/controller as contracted; [COUNTRIES] | Confirm whether requests expose visitor IP/device data to the CMS and document DPA, logs and cookies | [PRIVACY/DPA URL] |
Maps, environmental information and document translation
| Provider | Purpose and data | Role/location | Required launch confirmation | Provider information |
|---|---|---|---|---|
| Google Ireland Limited / Google Cloud EMEA Limited / [ACTUAL CONTRACT ENTITY] | Maps, geocoding, nearby places, pollen/air-quality features and Gemini-powered document translation; IP/device data, coordinates/addresses, requests and any document text sent for translation | Processor or independent controller depending on product and contract; EEA/global Google infrastructure | Product-specific terms and DPA, region and logging settings, no model-training/retention assumptions, SCC where needed, functional-cookie consent for embeds | https://policies.google.com/privacy |
| Walk Score / [ACTUAL CONTRACTING ENTITY] | Optional neighbourhood/walkability score; property coordinates/address and request metadata | Provider role/location to confirm | Contract, privacy terms, retention and whether browser data is sent directly | https://www.walkscore.com/professional/privacy.php |
| Klapty / another seller-selected virtual-tour host | Displays a virtual tour linked by the seller; visitor IP/device data and interaction with the external embed | Usually independent controller for its site/embed; location varies | Do not auto-embed an unapproved seller URL; apply allow-list, security review and functional-consent rule | Provider notice linked with the tour |
The buyer translation feature can send the contents of a user-selected property, transaction or supervisor report document to Google's Gemini API. The interface must warn the user before transmission, identify the destination, and prevent translation of identity, credit, income or other restricted documents unless the privacy and contractual assessment expressly permits it.
Payments, banks and transaction participants
| Recipient | Purpose and data | Role | Information shown to the user |
|---|---|---|---|
| Token.io / [ACTUAL TOKEN CONTRACTING ENTITY AND OPEN-BANKING PROVIDERS] | Payment initiation/status and, where separately enabled, account-information functionality; transaction amount/reference, bank selection, payment status and limited account details | Regulated provider/independent controller for its service and processor only where contractually specified | Exact entity, regulated status, terms, privacy notice and bank redirect before initiation |
| [PARTNER BANK LEGAL NAME] | Mortgage application/assessment only when an outbound transfer is actually implemented and requested | Independent controller | Bank identity, data package, legal bases, notice and decision/review route before transmission |
| [ASSIGNED ALBANIAN NOTARY / NOTARY OFFICE] | Notarial checks, escrow, legal reservation, sale/mortgage instruments and disbursement | Independent professional controller | Name, office, regulator/contact, fees if any, document access and privacy notice before appointment |
| [LICENSED ALBANIAN INTERMEDIARY / PROIEX ALBANIA ENTITY] | Seller mediation, local transaction coordination and buyer representation where separately authorised | Independent or joint controller as documented; not assumed to be an EU-entity processor | Identity, certificate/registration, authority, data-sharing role and contact in the mediation/transaction documents |
| [BUYER-APPOINTED PROIEX AGENT] | Acts under the buyer's separate transaction-specific power of attorney | Authorised recipient and representative; employment alone does not create the authority | Identity, employer, scope and duration appear in the power of attorney and transaction agreement |
| [BUYER-APPOINTED INDEPENDENT CONSTRUCTION SUPERVISOR] | Reviews agreed off-plan construction milestones and, where applicable, attends a site inspection; receives relevant property, milestone, developer-evidence, appointment and participant-contact data | Independent service provider and potentially an independent controller for professional records the supervisor determines to create or retain; ordinarily Albania for Albanian sites | Identity, qualifications, fixed fee, assignment scope, data access, report limitations and applicable terms are shown before appointment |
The mortgage-document collection feature does not itself mean PROIEX has submitted an application to a bank. A bank is added to this list and identified in-product before any real outbound submission.
Provider governance
Before a provider is enabled, PROIEX records its exact legal entity, service, data categories and subjects, controller/processor allocation, Article 28 or data-sharing terms, locations, subprocessors, transfer mechanism, security evidence, retention/deletion configuration, incident commitments and exit plan. Material subprocessor or purpose changes are assessed before use and reflected here where they affect users.
For the current provider details or a copy of an applicable transfer safeguard with confidential material redacted, contact privacy@proiex.com.
Last updated: [LAST UPDATED DATE]