Legal
Third-Party Services & Subprocessors
This disclosure separates providers used for QASA-operated account, commerce, licensing, download, and support services from integrations that a self-hosted customer chooses and controls.
- Effective:
- October 1, 2026
- Last updated:
- October 1, 2026
1. How to read this list
A Subprocessor processes personal data on QASA's behalf when QASA acts as a processor for a customer. Some listed providers instead act as independent controllers under their own terms, or process QASA's controller data. A provider is used only where the relevant feature is enabled.
This page does not turn a customer-selected provider into QASA's Subprocessor. The limited circumstances in which QASA acts as a processor are described in our Data Processing Addendum.
2. Providers for QASA-operated services
Paddle
Purpose: merchant of record, checkout, payments, tax, fraud screening, refunds, subscriptions, and buyer support. Data: purchaser identity, billing and transaction details, device and fraud signals. Role/location: generally an independent controller; international processing, including the United States and Europe.
Amazon Web Services
Purpose: secure software-release storage and delivery, transactional email where configured, media storage, and secrets management. Data: account/download identifiers, release requests, email delivery data, or support data depending on the service. Location: configured AWS region, with US regions used by default configuration.
Google reCAPTCHA
Purpose: bot, fraud, and abuse prevention on public and account forms. Data: IP address, browser/device signals, interaction data, and requested page. Role/location: Google applies its own privacy terms; global processing.
Sentry
Purpose: optional backend error and performance monitoring. Data: scrubbed error, request, environment, and diagnostic details. Secrets and known sensitive fields are configured for redaction. Location: region associated with QASA's configured Sentry project.
Infrastructure and email hosting
Purpose: host QASA-operated website, API, license service, MongoDB/Redis workloads, and support or transactional email.Data: account, licensing, support, security-log, and operational data. The exact provider and region may change as infrastructure evolves; material Subprocessor changes are handled under the DPA notice process.
3. Customer-controlled self-hosted providers
The following are not QASA Subprocessors when a self-hosted customer supplies the account, credentials, endpoint, or configuration. Customer contracts with them directly and determines what data is sent:
- Amazon SES or a customer SMTP host: email delivery and related events;
- Arkesel: SMS delivery and delivery-status webhooks;
- Meta WhatsApp Cloud API: WhatsApp templates, messages, and webhooks;
- Google Firebase Cloud Messaging: web or mobile push delivery and device tokens;
- OpenRouter and selected model providers: optional AI generation, rewriting, translation, and journey assistance;
- customer hosting, DNS, CDN, storage, monitoring, and backup providers; operation of the self-hosted environment; and
- customer-configured external endpoints: retrieval of dynamic template or journey data.
Customers must assess these providers, configure appropriate data regions and contracts, and disclose them in their own privacy and subprocessor materials.
4. Bundled infrastructure software
Customer deployment packages may include or reference MongoDB, Redis, Node.js, and other open-source or source-available components. Running those components locally does not by itself send customer data to the component publisher. Their licenses and any optional hosted services remain separate. See the third-party notices supplied with the release.
5. Updates and objections
We update this page when our provider practices materially change. Where the DPA applies, we aim to post a material new Subprocessor at least 15 days before it begins processing Customer Personal Data when reasonably practicable.
Customers may raise a reasonable data-protection objection during that period by emailing support@thesendvelo.com with the organization, affected service, and grounds for objection.
Questions about this document?
Contact support@thesendvelo.com. QASA Solutions is located at 5th Mankralo Link, Mataheko, Accra, Ghana.