Sub-processors
IUX-SUBPROC — version 1.3 — in force since 08/15/2026
List of the sub-processors required by art. 1.2 of the DPA.
Sub-processors
Published pursuant to art. 1.2 of the Data Processing Agreement. Verbatim extract of Annex 3 of the DPA (IUX-EN-31, v1.2, corpus v1.2-RC (2026-08-11)): the authoritative text is the DPA itself.
Annex 3 — Sub-processors
A3.1 Published list
The list of Sub-processors in force is published on the Sub-processor Page at https://www.industryux.com/legal/sub-processors, which states for each of them the identity, the registered office, the service entrusted, the place of processing, the categories of data concerned and the transfer tool where applicable, together with the date of the last update. The page allows subscription to change notifications by electronic mail. Changes are governed by Article 8.
A3.2 Sub-processors authorised as at the version date
As at the date of this Annex no external sub-processor is active. Customer Personal Data is processed exclusively by the internal operations function of the Provider, described in the table below. The engagement of any external Sub-processor is subject to the thirty days' prior notice under Article 8.3 and to the Customer's right of objection under Article 8.4, and the Sub-processor is named — with its identity, registered office, service entrusted, place of processing, categories of data concerned and transfer tool — in that notice and on the Sub-processor Page before it begins to process Customer Personal Data.
Sub-processor | Service entrusted | Place of processing | Categories of data | Transfer tool |
|---|---|---|---|---|
DEVIBRAIN S.R.L. — internal operations function | hosting, backup, monitoring, second-level support of the Enterprise Online environments on infrastructure operated directly by the Provider | Bergamo, Italy (EEA) | all the data described in Annex 1 | not applicable, no transfer |
A3.3 Statements
As at the version date no third party has access to Customer Personal Data. Remote inference is disabled by default and no Customer Personal Data is transmitted to a supplier outside the EEA in the absence of the express instruction and the safeguards provided for in Article 15.3; a supplier of remote inference becomes a Sub-processor only once it has been named in accordance with Article A3.2. Where the VPS deployment model is activated, the supplier of the infrastructure is engaged as a Sub-processor in accordance with Articles 8.3 and 16.5. In the On-Premise deployment model no Sub-processor is engaged, the data remaining on the Customer's systems.
A3.4 Suppliers of the Provider as controller
The following suppliers are not Sub-processors within the meaning of this DPA, since they process data in respect of which the Provider acts as controller under Article 2.2. They are listed here for transparency and are described in the Privacy Policy.
Supplier | Service | Place of processing | Role |
|---|---|---|---|
Nexi Payments S.p.A. | acceptance and processing of card payments for self-service subscriptions | Italy (EEA) | independent controller for the payment transaction, processor for the data transmitted by the Provider |
Integrity fingerprint (SHA-256) of the frozen copy:
f40b83f8f2e308e118b2f966879de34f2e485f09727bae590f34e50a64a742e3