Legal

Subprocessor List

AVENIQUE SUBPROCESSOR LIST

Last Updated: July 16, 2026

No third party processes Avenique personal data before it has a row here with appropriate contractual safeguards. We will update this list before onboarding a new subprocessor and, where required, provide advance notice.

For each named provider below, we also link their public privacy notice so you can review how they describe their own practices. Where a vendor is not yet named publicly, we will add their privacy link when that vendor is disclosed.

Emergency and Temporary Subprocessors

To ensure platform security, prevent active fraud, mitigate critical system outages, or maintain services during vendor failures, BafaTech may temporarily engage alternative, industry-standard subprocessors (such as backup SMS gateways, alternative CDNs, or secondary hosting providers), provided that: (a) the emergency subprocessor is bound by a Data Processing Agreement meeting our security and data protection standards before it processes any personal data; (b) the emergency subprocessor processes only the minimum data necessary to maintain the affected service; and (c) we update this directory within ten (10) business days of the emergency engagement beginning, whether or not the transition becomes permanent.

Active Subprocessors

1. Supabase Inc.

  • Function: Database, storage, Edge Functions, authentication infrastructure.
  • Data categories: Service data including waitlist entries, profiles, messages, and verification metadata (not raw government ID images).
  • Processing location: United States (configured project region).
  • Transfer safeguards: Standard Contractual Clauses / applicable transfer mechanisms; NDPA Part IX contractual safeguards for Nigerian users.
  • Privacy notice: supabase.com/privacy

2. Resend (Plus Five Five, Inc.)

  • Function: Transactional email (including waitlist confirmation, contact-form acknowledgments, and service notices).
  • Data categories: Email address and message content required to send the email.
  • Processing location: United States.
  • Transfer safeguards: Contractual safeguards / SCCs as applicable.
  • Privacy notice: resend.com/legal/privacy-policy

3. Google LLC (Firebase)

  • Function: Push notification delivery (FCM) and related device tokens.
  • Data categories: Push tokens, device identifiers.
  • Processing location: United States.
  • Transfer safeguards: SCCs / DPF as applicable; NDPA Part IX safeguards for Nigerian users.
  • Privacy notice: policies.google.com/privacy

4. Approved liveness / verification vendor

  • Function: Selfie and liveness verification processing.
  • Data categories: Biometric data (selfie, facial geometry), governed by our Biometric Information Policy.
  • Processing location: As disclosed in the vendor DPA on file.
  • Transfer safeguards: SCCs plus explicit consent where required; NDPA s.30 explicit consent plus Part IX safeguards for Nigerian users.
  • Privacy notice: Published here when the vendor is named.
  • Note: Raw government ID images, when ID verification is enabled, are hosted by the verification vendor; Avenique retains results and integrity signals only.

5. SMS / OTP delivery provider

  • Function: Phone authentication one-time codes.
  • Data categories: Phone number and OTP delivery metadata.
  • Processing location: As configured with the provider.
  • Transfer safeguards: Contractual safeguards / SCCs as applicable.
  • Privacy notice: Published here when the provider is named.

6. Apple Inc. / Google LLC (in-app purchases)

  • Function: Payment processing for Premium membership.
  • Data categories: Transaction data (each acts as an independent controller for payment processing; listed for transparency).
  • Processing location: Global.
  • Privacy notices: Apple: apple.com/legal/privacy; Google: policies.google.com/privacy
  • Note: Premium never bypasses verification, the contact window, or safety rules.

7. Cloudflare, Inc. (Turnstile)

  • Function: Bot detection and abuse prevention for public website forms.
  • Data categories: IP address, browser and device signals, challenge telemetry, website hostname, and a short-lived verification token.
  • Processing location: Global Cloudflare network.
  • Transfer safeguards: Cloudflare Data Processing Addendum and applicable Standard Contractual Clauses.
  • Privacy notice: cloudflare.com/privacypolicy
  • Note: Turnstile is used only for security. It is not used for advertising or cross-context behavioral tracking.

Rules

  • Biometric Special Handling: The verification vendor may only process biometric data under the purpose limitations and destruction schedule in the Biometric Information Policy (raw selfies within 72 hours of a decision; facial geometry templates within 30 days of successful verification, unless a risk review is pending; any face-derived ban signal no later than three years after a permanent ban is imposed).
  • No Advertising Networks: We do not engage ad-tech subprocessors for cross-context behavioral advertising.
  • Message Content: Subprocessors may process message content only for delivery, security, and Trust & Safety moderation, never for advertising.

Contact us

Choose a topic and send a message. We’ll route it to the right team.