Last updated: 08 July, 2025

Sub-processors and Third-Party Providers

Introduction

Personr Pty Ltd (“Personr”) and its affiliates may engage trusted third-party service providers (the “sub-processors”) to support certain functions necessary for the delivery of our services and operation of our business. These sub-processors may process personal information on our behalf, in accordance with our contractual obligations and applicable privacy laws, including:

The Privacy Act 1988 (Cth) and Australian Privacy Principles (APPs); 

The General Data Protection Regulation (EU/UK GDPR); 

The California Consumer Privacy Act (CCPA); and

The Biometric Information Privacy Act (BIPA).

Purpose and Scope

When acting as a data processor (under the GDPR), agent (under the Australian Privacy Principles), or service provider (under the CCPA), Personr ensures that any sub-processor it engages:

Acts only on documented instructions from Personr or its clients;

Processes personal information strictly for the purpose of delivering the contracted services; and

Is bound by written agreements that impose obligations equivalent to those set out in Personr’s own data protection commitments.

Sub-processors may access personal information from individuals undergoing verification or via our clients, but only to the extent necessary to fulfil their assigned roles. Where biometric or sensitive data is involved (eg. identity verification), sub-processors are required to meet heightened standards consistent with BIPA and Article 9 of the GDPR.

Sub-Processor Selection and Oversight

Before engaging a sub-processor, Personr conducts robust due diligence to evaluate:

Security and privacy controls;

Legal and regulatory compliance (including cross-border safeguards); and

Their ability to meet contractual, operational, and technical standards.

All sub-processors are subject to data processing agreements that include confidentiality obligations, access limitations, data handling protocols, breach notification requirements, and, where applicable, international data transfer mechanisms such as Standard Contractual Clauses (SCCs) or the UK Addendum.

Engagement and Disclosure

Sub-processors may be engaged globally depending on the specific Personr product or service in use, and not all sub-processors are involved in every client relationship. Personr maintains a list of active sub-processors along with a description of the services they provide and will update this list as needed.

We do not provide individual notice to clients when we add, remove, or replace sub-processors. Instead, we:

Maintain a list of sub-processors on our website;

Encourage clients to monitor the list regularly for updates; and

Consider a client’s continued use of our services as acceptance of the use of listed and future sub-processors.

By continuing to use Personr services, you acknowledge and agree to the engagement of these sub-processors under the terms of this policy.

Cross-Border Data Transfers

Where sub-processors are located outside of the jurisdiction where the data subject resides (eg. transfers from the EU/UK to Australia or the U.S), Personr ensures that appropriate safeguards are in place in accordance with Chapter V of the GDPR or APP 8 under the Australian Privacy Act. This includes the use of SCCs, UK Addendum, or reliance on adequacy decisions where applicable.

A list of sub-processors, including the services they support and descriptions of their processing activities, can be found below.

Name
Relevant Personr Service
Privacy information
Amazon AWS
Hosting infrastructure and secure cloud storage
Google Cloud
Cloud-based compute, AI services, and storage
Google Workspace
Internal team collaboration (Docs, Drive, Gmail)
Intercom
Customer support, onboarding, and live chat
Pipedream
Workflow automation and system integrations
Cloudflare
DNS management, caching, and DDoS protection
Slack
Internal team communication and collaboration
Twilio
SMS and email notifications for verification
Fingerprint
Device fingerprinting and fraud detection
Datazoo
Contributes to data source matching
Microblink
Document scanning and ID verification
ComplyAdvantage
AML screening, sanctions, and PEP monitoring
Department of Home Affairs/ID Match
Government identity verification (DVS)
Hubspot
CRM, sales pipeline, and marketing automation
Xero
Accounting, invoicing, and financial reporting
Stripe
Payment processing and billing management
Fireflies
Internal meeting transcription and summarisation