Processors and Subprocessors
SofiaPulse Robots Inc. ·
1. What this page is
SofiaPulse engages four service providers, counted by legal entity. Some are used for more than one function and appear more than once below. Only two are involved in delivering advertising to the public, and neither holds any identifier for a person to whom an advertisement is shown.
This page lists all of them, with the legal entity engaged, the country under whose law that entity operates, and the mechanism relied on for any transfer of personal information out of the European Economic Area or the United Kingdom.
Processor or subprocessor
Which term applies depends on SofiaPulse’s own role, which differs by service:
- Where SofiaPulse acts as a controller — as it does for the advertising described in section 3 of the Privacy Policy — the providers below are its processors.
- Where SofiaPulse acts as a processor on a client’s documented instructions, the same providers are its subprocessors, engaged with that client’s authorisation under Article 28(2) GDPR.
The obligations SofiaPulse imposes on them are the same either way. The distinction matters for which contract governs and to whom notice of a change is owed.
SofiaPulse publishes this list in full rather than describing categories of recipients, so that the statements made in its Privacy Policy and Legitimate Interest Claim can be verified against named providers. An advertiser, agency, or publisher whose agreement with SofiaPulse requires advance notice of changes to this list may write to [email protected] to be added to the notification list.
2. Ad serving
These providers are involved in delivering the Ads described in section 3 of the SofiaPulse Privacy Policy. SofiaPulse is the controller for this processing, and each provider below is its processor.
| Provider | Purpose and data | Entity and transfer mechanism |
|---|---|---|
| Cloudflare | Edge compute, ad delivery, creative and asset storage, and transcoding for the domains listed in the device storage disclosure other than t.sofiapulse.com. SofiaPulse’s own software runs on this edge infrastructure and derives a geographic area — country, region and city — from the IP address when the Ad is selected and when the creative assets and data forming part of it are returned, against a licensed database held locally; the address is used in memory and discarded, and is not sent to any geolocation service. No identifier is set or stored. Requests originating in the EEA are ordinarily served from EEA edge locations, so this derivation ordinarily takes place within the EEA. |
Cloudflare, Inc. — United States. EU–US Data Privacy Framework, the UK Extension and the Swiss–US DPF, as certified by Cloudflare. Standard Contractual Clauses (EU) 2021/914 with the UK Addendum are additionally incorporated in Cloudflare's Data Processing Addendum. |
| Google Cloud | Compute and hosting for the tracking endpoint (t.sofiapulse.com), which records delivery and interaction events, and storage for the resulting records. SofiaPulse’s own software runs on this infrastructure and derives a geographic area — country, region and city — from the IP address, against a licensed database held locally, so that events can be reported by market; the address is processed in memory and discarded, is not sent to any geolocation service, and is not written to any SofiaPulse dataset or retained by Google on SofiaPulse’s behalf. This derivation runs in the Montréal region. Each event record holds campaign, creative, format, publisher domain, country, region and city, device type, brand, model and browser, and the event type — and carries no identifier, no IP address and no user-agent string. |
Google LLC — United States. EU–US Data Privacy Framework, the UK Extension and the Swiss–US DPF; Google LLC and its wholly-owned US subsidiaries are certified. Standard Contractual Clauses are additionally incorporated in the Google Cloud data processing terms. |
No other provider is involved in serving an Ad. No demand-side platform, exchange, data provider, identity resolution vendor, or measurement vendor receives personal information from SofiaPulse for that party’s own purposes. Where an advertiser instructs SofiaPulse to include a third-party measurement or verification tag in a creative, that tag is the advertiser’s and operates under the advertiser’s own disclosures, not those of SofiaPulse. SofiaPulse relays the consent parameters contained in such a tag unchanged, as described in section 4 of the Privacy Policy.
A note on the Montréal region. It applies to the event and reporting step only; the derivations carried out when an Ad is selected and when its creative assets are returned happen at the edge, ordinarily within the EEA for EEA traffic. In either case the region determines where the computation happens. It does not determine which law the provider answers to. The transfer mechanism stated above is selected by reference to the legal entity SofiaPulse contracts with, not by reference to the location of that entity’s infrastructure.
3. Platform and client applications
These providers host the SofiaPulse platform and the front-facing applications used by clients — advertisers, agencies, and publishers — to configure campaigns, review creative, and access reporting. This is separate from ad serving. The personal information concerned is that of client personnel who hold accounts, not of individuals who view an Ad; campaign reporting accessed through these applications is aggregate and does not identify an individual.
| Provider | Purpose and data | Entity and transfer mechanism |
|---|---|---|
| Vercel | Hosting and delivery of client-facing web applications. IP address and standard web server logs; account identifiers and session data for signed-in client users. | Vercel Inc. — United States. EU–US Data Privacy Framework certification, covering transfers from the EU, the UK and Switzerland. |
| Firebase Authentication | Identity provider service handling sign-in to the Applications. Supported identity providers are Google and Microsoft; an account holder authenticates with whichever of those holds their account, and that provider acts for the account holder rather than on SofiaPulse’s behalf. Name, email address, and a stable account identifier, together with sign-in events. No password is received by SofiaPulse. | Google LLC — United States. EU–US Data Privacy Framework, the UK Extension and the Swiss–US DPF. |
| Cloudflare | Compute, storage, and delivery for the SofiaPulse platform and its internal services, and front-end delivery of the Applications. IP address and request metadata; account identifiers and session data for signed-in client users. | Cloudflare, Inc. — United States. As section 2. |
| Google Cloud | Data warehousing and analytics supporting campaign reporting, and other operational services. Event records and the aggregate campaign and delivery data compiled from them. No identifier for any person who viewed an Ad is present in either. | Google LLC — United States; processing in the Montréal region. As above. |
4. Website and communications
These providers relate to the SofiaPulse marketing website and to business correspondence. They are not involved in delivering Ads.
| Provider | Purpose and data | Entity and transfer mechanism |
|---|---|---|
| Webflow | Hosting and content management for sofiapulse.com. IP address and standard web server logs for visitors to the Website. | Webflow, Inc. — United States. EU–US Data Privacy Framework, the UK Extension and the Swiss–US DPF, as certified by Webflow. Standard Contractual Clauses are additionally offered for exports from the UK or EEA. |
| Google Analytics | Measurement of Website usage. Property G-M0B1K1LKM8. IP address, cookie identifiers, and page interaction data for Website visitors only. | Google LLC — United States. EU–US Data Privacy Framework, the UK Extension and the Swiss–US DPF. |
| Google Workspace | Email and calendar for the sofiapulse.com domain, used for correspondence and for communications that have been requested. Name, email address, and the content of the correspondence. | Google LLC — United States. As above. |
SofiaPulse operates no customer relationship management platform, no third-party marketing automation service, and no third-party error tracking, application performance monitoring, or log aggregation service. Internal tools are built in-house and run on the infrastructure listed above; they introduce no additional processor.
5. How SofiaPulse engages them
Each provider is engaged under a written agreement that meets the requirements of Article 28 GDPR, including obligations of confidentiality, security, assistance with data subject requests, notification of any subprocessor of its own, and deletion or return of data at the end of the engagement.
Providers are given only the information needed to perform their designated function. SofiaPulse does not authorise any of them to use or disclose personal information for their own marketing or for any other purpose of their own.
Transfers out of the EEA and the UK
Where SofiaPulse makes personal information available to a provider established outside the EEA or the UK, SofiaPulse is the exporter and Chapter V of the GDPR applies to that disclosure. The mechanism relied on is stated against each provider above and is selected by reference to the provider’s legal entity, not the location of its infrastructure.
Where the mechanism is a certification under the EU–US Data Privacy Framework, SofiaPulse verifies that the certification is active and covers the relevant data types before engaging the provider, and re-verifies it at each annual review of this page. Where a certification lapses or is withdrawn, SofiaPulse executes Standard Contractual Clauses with that provider and updates this page.
Where the mechanism is the Standard Contractual Clauses in Implementing Decision (EU) 2021/914, they are executed in the module appropriate to the relationship, together with the UK International Data Transfer Addendum, and supported by a transfer impact assessment covering the destination country’s law on government access and the supplementary measures in place.
SofiaPulse notes that these clauses were drafted for exporters established in the European Union. A dedicated set for exporters subject to the GDPR under Article 3(2) has been announced by the European Commission but not yet adopted. Pending adoption, SofiaPulse applies the existing clauses as the closest available Article 46 safeguard.
The transmission of an ad request from a user’s device in the EEA or the UK to SofiaPulse is not itself a transfer under Chapter V, because it is made by the data subject’s own device rather than by an exporter. This is explained in section 10 of the Privacy Policy.
Clients transferring to SofiaPulse
A client established in the EEA or the UK transferring personal information to SofiaPulse in Canada may rely on the European Commission’s adequacy decision for Canada (Decision 2002/2/EC) in respect of organisations subject to the Personal Information Protection and Electronic Documents Act in their commercial activities, and on the corresponding United Kingdom adequacy regulations. No Article 46 safeguard is required for that transfer.
6. Changes to this list
SofiaPulse will update this page whenever a provider is added, removed, or changed, or whenever a transfer mechanism changes, and will record the change below. Where an agreement with a client requires advance notice of a new provider, SofiaPulse gives that notice at least 30 days before the new provider begins processing, and the client may object within that period.
| Date | Change |
|---|---|
| 3 September 2026 | First publication. |
Questions about anything on this page: [email protected].