gigiii
Log inCreate an account

Sub-processors and Service Providers

Last updated: September 29, 2026

Scope of this list

This list identifies third parties that may process personal data in connection with gigiii. Some act as sub-processors where gigiii processes data on a member's documented instructions; others support processing for which gigiii is an independent controller. Their inclusion does not determine the legal role in every data flow.

Location information describes the documented production configuration or provider service location. Content delivery, support, security operations and a provider's own sub-processors can involve additional locations. Where a transfer outside the EEA occurs, gigiii relies on the applicable transfer mechanism in the provider agreement, such as an adequacy decision or the EU Standard Contractual Clauses. We do not state that a provider is EU-only unless that has been confirmed for the relevant service.

Current providers

ProviderProcessing purpose and dataDocumented location / transfer note
Vercel Inc. (vercel.com)Application hosting, serverless functions, CDN, private file storage, and consented Vercel Analytics / Speed Insights. May process platform requests, files, logs and performance data.Functions and Blob storage: Frankfurt, Germany (fra1, AWS Europe Central 1 / eu-central-1). CDN delivery is global.
Neon Tech Inc. (neon.tech)Managed PostgreSQL database for account, profile, booking, event and operational records.AWS Europe Central 1, Frankfurt, Germany (eu-central-1).
Cloudflare, Inc. (cloudflare.com)DNS and scheduled Worker requests used for notification delivery; may process operational request and security metadata.Global network; no EU-only processing representation is made.
Google LLC (google.com)Google OAuth; Google Places requests for location/address search; and, after analytics consent, Google Tag Manager and Google Analytics 4. Google receives the data sent with the relevant sign-in, Places or analytics request.Provider-operated global infrastructure, including possible processing outside the EEA. Applicable safeguards depend on the Google service and agreement.
Microsoft Corporation (microsoft.com)Microsoft Entra ID authentication when enabled and Microsoft Clarity analytics/session diagnostics after analytics consent.Provider-operated infrastructure; the applicable tenant/service configuration and transfer mechanism govern location.
GitHub, Inc. (github.com)GitHub OAuth when enabled; authorised user problem reports and Sentry incident metadata may be copied to private GitHub Issues for triage.GitHub may process data in the United States and other locations used by it and its sub-processors.
Sentry (sentry.io)Error, performance and operational telemetry. Session replay is disabled in the application.gigiii is configured for Sentry's German/EU ingest region; event data is intended to reside in Frankfurt, Germany. Some account, organisation and integration metadata may be processed in the United States.
Resend (resend.com)Transactional email, magic-link authentication, delivery status and related webhooks.Sending is configured for the EU West region; account, support and sub-processor processing may involve the United States or other locations.
Loops (loops.so)Marketing-consent contact sync: email, user ID, name, role/group and subscription state.Provider-controlled location and transfers; confirm the current Loops DPA and sub-processor schedule before asserting a residence country.
Spamblock (spamblock.io)Public contact forms and anti-spam checks; receives submitted form fields and related anti-abuse data. Previously submitted registration-interest records remain stored.Provider-controlled location and transfers; confirm contractual location and safeguards before asserting a residence country.
pretix GmbH (pretix.eu)Paid-event ticketing, organiser OAuth connection, checkout and ticket/order information. The selected seller is merchant of record and configures its own payment providers in pretix.pretix GmbH is established in Karlsruhe, Germany. Payment providers chosen by a seller are not selected by gigiii and are not gigiii sub-processors.
CARTO (carto.com)Client-side basemap tiles for maps; receives requests such as IP address and device/network information.CARTO's tile infrastructure and associated processing may be global; do not treat its use as EU-only without provider confirmation.
OpenStreetMap Foundation / Nominatim (openstreetmap.org)Server-side locality and venue-coordinate lookup fallback; receives a location search query.Public service; provider-controlled processing location.
OpenRegister GmbH (openregister.de)Optional German company-register lookup for buyer business-verification assistance; receives company-name and location search terms.Provider-controlled location. This provider is used only when the optional feature is enabled.

Conditional providers

ProviderProcessing purpose and dataDocumented location / transfer note
Meta Platforms (meta.com)An event organizer may use Meta Pixel on gigiii-hosted public event pages after separate Analytics and Marketing cookie consent. Meta may receive browser/network details, the event URL and allowlisted conversion parameters, but not RSVP or ticket purchaser contact details from gigiii.Provider-operated infrastructure may process data outside the EEA. The organizer's applicable Meta terms and transfer safeguards must be reviewed before this integration is enabled.

The application supports a legacy SMTP email fallback. It is not enabled as a named production provider in the repository. No SMTP provider should be activated for production until it has been added to this list with its purpose, location and transfer safeguards.

Developer-only content-enrichment tools (for example Unsplash and OpenAI) are not listed because they are not part of the marketplace runtime and must not receive marketplace personal data. Any production use involving personal data requires review and an update to this list before enablement.

Changes and objections

For processing covered by our limited processor terms, we will give at least 30 days' prior notice by email and on this page before adding or replacing a sub-processor. Controllers may object on reasonable data-protection grounds within that period. If a justified objection cannot be resolved, the Controller may stop using or terminate the affected feature as described in the Data Protection Roles and Limited Processor Terms.

Contact

For questions about this list, contact gdpr@gigiii.com or hello@gigiii.com.

gigiii

gigiii is a private B2B marketplace for local entertainers and talent buyers.

Plans and pricing · Help·Contact·Privacy·Terms·Cookies