Skip to content

Sub-Processors

CampOne processes personal data of your guests on your behalf (you as controller, CampOne as processor). To deliver the service we use the sub-processors listed below. Each entry documents location, data category, and contractual basis.

As of: 2026-04-28. We notify you in writing before any change to this list — to opt out of routine updates or to ask for additional context, contact privacy@campone.ch.

ProviderRoleData categoriesLocationContractual basisStatus
SupabasePostgreSQL hosting + object storage (S3)All application + booking data, mediaAWS Frankfurt region (eu-west-1, Ireland) — EU/EEAEU SCCs + DPADPA signing in progress
RailwayBackend hosting (Django, workers)Application logs, transient request dataEU regionEU SCCs + DPADPA signing in progress
VercelFrontend hosting (CDN, edge)Request routing, cached content (no DB content)Global, primary cache EUEU SCCs + DPADPA signing in progress
StripePayment processingPayment-intent references (card data stays at Stripe)Switzerland / IrelandStripe Data Processing Agreementactive
Booking.com (OTA integration)Distribution channelBooking + guest data for OTA-side reservations onlyNetherlandsOTA contractactive when integration is enabled
Per-tenant SMTP (your provider of choice)Email deliveryRecipient address, booking-confirmation contentdepends on providerContract directly between you and the SMTP providertenant-owned contract
Groq (optional AI assistant)LLM inference for customer-support chatChat messages within the sessionUSAEU SCCs (pending)only on explicit per-tenant activation
Anthropic (optional AI assistant)LLM inference for customer-support chat (alternative to Groq)Chat messages within the sessionUSAEU SCCs (pending)only on explicit per-tenant activation

For transfers to the USA we rely on the EU Standard Contractual Clauses combined with additional technical measures:

  • TLS 1.2+ encryption in transit for every transfer.
  • Application-level encryption of sensitive data with Fernet (AES-128-CBC + HMAC-SHA256), independent of the provider’s storage security — see Architecture & Controls.
  • EU data residency for the database. US-based providers see only cache content (Vercel) or explicitly enabled features (AI assistant).
  • Pseudonymisation of guest data in logs and audit trails where technically meaningful.

A machine-readable version of this list is available at /legal/sub-processors.json — suitable for procurement automation and third-party risk tooling.

DateChange
2026-04-28Initial publication. DPA signing status will be kept current here.