Palladin data recipients
Pre-launch draft. Requires qualified-counsel review before publication; it has not entered into force. The Polish version is binding, without limiting mandatory consumer rights.
This inventory separates evidenced code and supplier selection from unverified contracts and deployments. It does not establish an executed DPA, chosen region or lawful transfer. Exact contracting entities, locations and safeguards must be identified before production. Contact: patryk.roguszewski@palladin.io.
1. Integrations present in code
| Provider and service | Role and data | Location and verification status |
|---|---|---|
| AWS — infrastructure, storage and Amazon SES | intended processor of application data: encrypted Vaults, account, logs and public catalogues; SES: e-mail, message content and delivery events, including confirmation links and security alerts | AWS selected by the owner; contracting entity, actual region, retention and DPA unconfirmed. We do not assume eu-west-1 or absence of non-EEA access |
| Google/Firebase — FCM | notification-delivery processor: token, platform, generic message and opaque identifiers; no Vault/Entry names or secrets | Firebase selected; precise entities, international flows and terms need confirmation |
| Apple — APNs | push delivery to Apple devices through FCM; token and limited payload as above; applicable terms determine its role | Apple infrastructure; entity, terms and flow safeguards need confirmation |
| PostHog | intended processor of selected events: pseudonymous account/waitlist or random page ID, event and limited technical data. No secrets, replay, autocapture or person profiles | client transport restricted to EU; this alone proves neither storage/log region nor absence of non-EEA access. DPA, retention, backend objections and launch conditions remain open |
| Netlify — landing/CDN and waitlist proxy | intended processor of entrusted data: IP and request; the form forwards e-mail and language to the API. Proxy code neither stores nor logs e-mail | code integration exists; exact function region, logs, entity and DPA unverified |
| Google — sign-in | identity provider; identifier, e-mail and profile needed for sign-in. Google’s policy governs its own purposes; it is not automatically Palladin’s processor | the only registered OAuth provider in the current backend; applicable terms and transfers need verification |
| Google Fonts | recipient of direct app-panel font requests, including IP and browser data; this does not provide Vault contents. The informational website and legal pages serve fonts from their own hosting, without connecting to Google Fonts | external connection remains in the panel; basis, terms and necessity need approval or removal of that connection before launch |
| Have I Been Pwned / Pwned Passwords | independent password-check recipient: five-character SHA-1 prefix and connection data including IP, not the full password or hash. We do not automatically classify it as a processor | direct client/API connection; terms and flow location need verification |
Entry contents and presentation reach infrastructure as ciphertext. Separate features disclose a public-icon hostname and value-free form-map domain, login URL and definition. Local export and explicitly authorized Agents or websites may receive plaintext; user selection alone does not make those recipients Palladin subprocessors.
2. Selected future payments and unconfirmed services
Apple App Store, Google Play and Paddle are selected for the first paid release, but billing integrations are not ready. The relevant seller/platform and independent controller will be identified before purchase. Data will include account and transaction identifiers, Plan, entitlements, period and required payment/invoice information, never Vault keys. This does not establish provider approval of Palladin or execution of every agreement.
RevenueCat is not a confirmed integration. Discord is not an existing support channel or confirmed subprocessor. Any activation requires fresh role, data and terms assessment. No implemented external crash-reporting or advertising network was found; this description does not replace checking the actual launch configuration.
3. Transfers and changes
Before a non-EEA transfer, establish the basis for the particular recipient and flow. Adequacy applies only within its scope; DPF requires a covered certified organization and data, and Canadian adequacy covers relevant PIPEDA-regulated processing. Other cases require SCCs or another GDPR Chapter V mechanism, transfer assessment and appropriate safeguards. EU hosting does not rule out foreign access.
Request copies of actually applied safeguards and location information through the contact above, subject to necessary protection of others’ data and security. Subprocessor changes require list updates and notice to B2B Customers under the DPA; independent-controller recipients are not automatically subject to subprocessor authorization.