Last Updated: 23 September 2025
Effective Date: Upon UK Launch
Overview
This page lists third-party subprocessors that Nollie engages to assist in providing our Service. These subprocessors may process End-Customer Data on behalf of our Business Subscribers (venues).
We conduct due diligence on all subprocessors and ensure they maintain appropriate security measures and comply with applicable data protection laws through contractual agreements.
Notification of Changes
We will update this list when adding or removing subprocessors. Business Subscribers will be notified of material changes via:
- Email notification to account administrators (14 days advance notice)
- Updates to this webpage
- In-app notifications where applicable
Business Subscribers may object to new subprocessors within 7 days of notification by contacting: support@nollie.ai
Current Subprocessors
Core Infrastructure
| Subprocessor | Purpose | Data Processed | Location | Entity |
|---|---|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure and hosting | All Service data including End-Customer Data | UK (primary), with failover to Ireland | Amazon Web Services EMEA SARL |
| Cloudflare | Content delivery network and DDoS protection | Cached content, IP addresses for security | Global (data processed at edge locations) | Cloudflare, Inc. |
AI and Analytics
| Subprocessor | Purpose | Data Processed | Location | Entity |
|---|---|---|---|---|
| OpenAI | AI-powered insights and recommendations | Masked/tokenized End-Customer Data (PII removed) | United States | OpenAI, LLC |
| Mixpanel | Product analytics | Usage data, feature adoption metrics | EU (data residency) | Mixpanel, Inc. |
| Google Analytics | Product Analytics | Usage data | United States | Google, Inc. |
| Microsoft Clarity | Product Analytics | Usage data, behavioural data | United States | Microsoft, Inc |
Communications
| Subprocessor | Purpose | Data Processed | Location | Entity |
|---|---|---|---|---|
| Twilio (SendGrid) | Email communications | Email addresses, email content | EU/United States | Twilio Ireland Limited |
| Twilio | SMS communications | Phone numbers, message content | EU/United States | Twilio Ireland Limited |
| WhatsApp Business | Messaging platform | Phone numbers, message content | Ireland/United States | Meta Platforms Ireland Limited |
Payment Processing
| Subprocessor | Purpose | Data Processed | Location | Entity |
|---|---|---|---|---|
| Stripe | Payment processing for subscriptions | Venue billing information (no End-Customer payment data) | Ireland/United States | Stripe Payments Europe, Limited |
| Square | POS integration support | Transaction references only (no payment data) | United Kingdom | Square International Ltd. |
Business Operations
| Subprocessor | Purpose | Data Processed | Location | Entity |
|---|---|---|---|---|
| HubSpot | CRM and marketing automation | Venue contact information, usage data | Ireland/United States | HubSpot Ireland Limited |
Integration Partners
| Subprocessor | Purpose | Data Processed | Location | Entity |
|---|---|---|---|---|
| ResDiary | Reservation system integration | Booking data, customer details | United Kingdom | ResDiary Ltd |
| Various POS Providers | Point-of-sale integrations | Transaction data, customer identifiers | Varies by provider | Per integration agreement |
Subprocessor Security Standards
All subprocessors are required to:
- Implement appropriate technical and organizational security measures
- Comply with applicable data protection laws
- Maintain confidentiality of all data
- Only process data according to our documented instructions
- Assist with data subject rights and regulatory compliance
- Delete or return data upon termination
- Allow for audits and inspections as required
Data Processing Agreements
We maintain executed Data Processing Agreements (DPAs) with all subprocessors that include:
- Standard Contractual Clauses for international transfers
- Security requirements and breach notification procedures
- Limitations on data use and retention
- Audit and compliance provisions
- Sub-subprocessor restrictions
Special Categories
AI Model Providers
For AI processing, we implement additional safeguards:
- PII Masking: Personal identifiers are replaced with tokens before processing
- Purpose Limitation: AI providers cannot use data for model training without explicit consent
- Data Minimization: Only necessary data attributes are shared
- Retention Limits: Processed data is not retained beyond immediate processing needs
High-Risk Processors
For processors handling sensitive operations, we conduct:
- Enhanced due diligence
- Annual security reviews
- Regular compliance audits
- Incident response testing
International Data Transfers
Where data is transferred outside the UK/EEA, we ensure appropriate safeguards through:
- Standard Contractual Clauses (UK/EU versions as applicable)
- Adequacy decisions where available
- Supplementary measures based on transfer risk assessments
- Technical safeguards including encryption and pseudonymization
Objection Process
Business Subscribers may object to the appointment of new subprocessors by:
- Sending written objection to privacy@nollie.ai within 7 days
- Providing specific concerns about the subprocessor
- Working with us to address concerns or find alternatives
If we cannot resolve objections and the subprocessor is essential to Service delivery, Business Subscribers may terminate their subscription without penalty.
Audit Information
Business Subscribers may request:
- Copies of relevant DPA excerpts (confidential terms redacted)
- Security certifications (ISO 27001, SOC 2, etc.)
- Summary audit reports
- Additional information about specific subprocessors
Requests should be sent to: privacy@nollie.ai
Updates and Version History
Core Infrastructure
| Date | Change | Notification |
|---|---|---|
| 22 Sep 2025 | Initial publication | N/A |
| [Future] | Updates logged here | Email + 14 days notice |
Contact
For questions about our subprocessors or data processing practices:
Email: privacy@nollie.ai Data Protection Officer: Jordan Foord Address: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
This list is incorporated by reference into our Data Processing Agreement and forms part of our contractual commitments to Business Subscribers