Legal & Trust Center

Subprocessors & Third-Party Services

Categories of providers used to deliver the service.

Version
1.0
Effective date
17 August 2026
Last updated
17 August 2026
Document owner
the Groundmaster project, with responsibility assigned to its legal and compliance function
Applicable jurisdiction
Portugal, European Union
Permanent URL
https://www.groundmaster.pt/legal/subprocessors
Providers are listed by category and function. Named entities and processing locations are confirmed by the operating legal entity and are provided on request under the Data Processing Terms; bracketed fields are placeholders pending that confirmation.

1.How we select and control providers

Providers are assessed for security, data protection, reliability and, where relevant, transfer safeguards before use. Each is engaged under written terms that impose confidentiality, security and processing restrictions no less protective than the Data Processing Terms, and access is limited to what the provider needs to perform its function.

2.Provider categories

CategoryFunction performedData categoriesRegion
Cloud hosting and application runtimeRunning the application, request routing, edge deliveryAll Content processed in the course of requests, technical metadatathe European Economic Area (EEA), where technically available; any processing by third-party subprocessors outside the EEA is subject to appropriate GDPR safeguards, including Standard Contractual Clauses where applicable
Managed database and file storagePersistent storage of records and uploaded documents, backupsWorkspace Content, uploaded documents, audit datathe European Economic Area (EEA), where technically available; any processing by third-party subprocessors outside the EEA is subject to appropriate GDPR safeguards, including Standard Contractual Clauses where applicable
Authentication and identityAccount authentication, session and token management, federated sign-in where enabledIdentity and credential metadatathe European Economic Area (EEA), where technically available; any processing by third-party subprocessors outside the EEA is subject to appropriate GDPR safeguards, including Standard Contractual Clauses where applicable
Transactional email deliveryAccount, security and notification messagesName, email address, message content[provider regions]
AI model inferenceGenerating AI-assisted suggestions, summaries and retrieval answers on requestPrompt content and the retrieved context needed for the request[provider regions]
Monitoring, logging and error diagnosticsAvailability monitoring, performance measurement, error diagnosisTechnical metadata, diagnostic events[provider regions]
Security and abuse preventionTraffic filtering, rate limiting, bot and abuse mitigationRequest metadata, IP address[provider regions]
Billing and payment processingSubscription billing, invoicing and payment handling where applicableCommercial contact and billing data[provider regions]
Support toolingHandling and tracking support requestsSupport correspondence and attachments[provider regions]
Backup and disaster recoveryStorage of backup copies and restoration testingBackup copies of workspace Contentthe European Economic Area (EEA), where technically available; any processing by third-party subprocessors outside the EEA is subject to appropriate GDPR safeguards, including Standard Contractual Clauses where applicable

3.Changes and objections

We will give notice before adding or replacing a category of provider that processes Customer Data. Customers may object on reasonable data protection grounds; where an objection cannot be resolved, the affected functionality may be limited or the Subscription may be terminated for the affected part.

4.Requesting the current list

A current list of named providers, their functions and their processing locations is available on request through the legal requests page.

Change history

VersionDateChange
1.017 August 2026Initial category-based provider inventory.
Contact

Questions about this document can be sent to groundmaster.web@gmail.com. Formal legal, privacy, security and regulatory requests should follow the routes described in the legal requests page. Fields shown as bracketed placeholders are pending confirmation by the operating legal entity and do not constitute a statement of fact.

Related documents