Who processes your data for us
For an order to work we need a few outside services: a payment must go through, a message must arrive, an invoice must be kept. Here you read which kinds of companies see your data along the way, why they see it, where they keep it and what they are not allowed to do with it.
Why this list is public
The Union’s regulation on the protection of personal data requires it to be clear who works on the controller’s instructions. Many platforms keep that hidden in a contract. We write it down publicly, because someone who gives an address and a telephone number should know how far that data travels. If this list changes, this text changes with it, and the date of the last change stands at the foot of the page.
Which kinds of services we use
Six kinds: the payment service, which reserves the amount and settles the invoice; the text-message and notification service, which can tell you the professional is on the way; the email service, which sends confirmation and invoice; the hosting, on which platform and database run; the accounting service, which keeps invoices as long as the law requires; and audience measurement without tracking, which only tells us how many people opened a page. There are no other kinds, and each kind receives only the data without which it cannot do its work.
What each one sees — and does not
The payment service sees the name, the email and the amount, but neither your address nor the nature of the work. The text-message service sees the number and the short text, without address and without sum. The email service sees the address and the content of the letter. The hosting holds the database, yet nobody there reads it: access is limited and logged. The accounting service sees the invoices, because an invoice must carry a name and an address. Audience measurement sees no person, only numbers. The address of the visit is shown to the confirmed professional alone, and only after confirmation.
Where the data sits
The database and the documents sit on servers within the European Economic Area. If a service must process data outside it, that happens only under the Commission’s standard clauses or an adequacy decision, and only after we have checked what the company there actually sees. We place no part of the platform in a country that has neither of those two routes.
What a service may not do
Each of these companies works on our written instructions, under a contract in line with Article 28. None may therefore: use the data for its own advertising, sell it, pass it to a third party without our consent, keep it longer than we say, or use it for any purpose other than the one requested. Each company must report a breach at once, and its staff is bound to confidentiality. Where a company falls short, the contract ends and the service is replaced.
How we choose and change a service
Before a company touches the data we look at three things: which data it truly needs, where it keeps them and what it does in the event of an incident. If an answer does not fit, we take another company. When we change a service or add a new kind, it stands on this page before the change takes effect, at least twenty days in advance, so that you have time to object. In a failure that allows no waiting, we change at once and write the change down within seven days.
What you can do
You may ask at any time which data about you sits with which service, and you receive an answer within a month, without having to give a reason. If a change does not suit you, write to us: where the work is impossible without that service, we say so honestly and show what it means for your orders. If you believe something is going wrong, you may turn to the National Commission for Data Protection in Luxembourg. The address for any request stands in the legal notice.