Skip to content
DATA PROCESSING — SUB-PROCESSORS

Who touches
your data.

About this page

Under GDPR Article 28(2), we must publish the complete list of sub-processors that process personal data on our behalf, with their category, purpose, region, and DPA reference. This is that list. It is the canonical public version of our internal DPA document.

We commit to providing at least 30 days' advance notice before adding a new sub-processor — by updating this page and, for users with an active account, by an in-app banner. Material changes also bump the privacy-policy version, which triggers a re-consent prompt at next login.

Current sub-processors

Sub-processorPurposeData categoryRegionDPA
Amazon Web Services (Amplify Hosting, Cognito, DynamoDB, S3 + CloudFront)App backend — web + API hosting, sign-in, account and project data, image storage and deliveryAccount email, name, uploaded photos, generated images, chat messages, all request/response data, geo IPUS (us-east-1) + global CDNLink
Amazon Web Services (Rekognition)Automated content-safety screening of uploaded room photos and generated outputsImage bytes (analysed and discarded, not retained)US (us-east-1)Link
Google Firebase (Cloud Messaging) + Google Play IntegrityAndroid push-notification delivery and Android app-integrity attestationDevice push token, app-integrity verdictUSLink
KIE.ai (Kiengage Ltd.)AI image generation and photo understanding (room-type detection, layout analysis, furniture cataloguing)Image input, prompt textUSLink
Google (Gemini models, accessed via KIE.ai)Operates the image and vision models that run the generation and photo-understanding requestsImage input, prompt textUSLink
Ideogram (accessed via KIE.ai)Operates the inpainting model used for selective edits (masked regions only)Image input, mask image, prompt textUSLink
Adapty Tech, Inc.In-app purchase analytics + receipt validationAnonymous device id, purchase eventsUSLink
Apple App Store / StoreKitiOS paymentsApple ID hash, purchase dataApple-controlledLink
Google PlayAndroid paymentsGoogle account hash, purchase dataGoogle-controlledLink
Zoho (ZeptoMail / Zoho Mail)Transactional email sending + support inbox hosting (welcome, password reset, design-emailed-to-you, support@)Email address, message contentUS/EULink
StripeWeb subscription billingLast 4 of card, billing address, countryGlobalLink
Google Analytics (GA4)Web product analytics (loaded only after cookie consent)Redacted page paths, first-party analytics cookie (_ga)US/GlobalLink

Last updated: 2026-08-29. Subscribe to changes by emailing privacy@intirear.design with the subject “Subscribe to sub-processor updates”.

Retention summary

  • Account data: retained while active. Deleted within 30 days of request (Art. 17).
  • Generated images: retained until you delete them or close your account.
  • Source room uploads: 365 days from upload (auto-deleted via S3 lifecycle rule).
  • Inpainting masks: 7 days from creation.
  • Crash and error reports: 30 days (stored first-party, auto-expiring — no third-party crash SDK).
  • Server access logs: 30 days on AWS (Amplify/CloudWatch).
  • Analytics events: 180 days from the event, then auto-expired. Account deletion severs the linkage within that window rather than erasing the row (user-id replaced with “anonymized”), because the rows are aggregate counts.
  • Audit logs (moderation, opt-outs, admin actions): 7 years for legal-defence retention.

EU Representative (Art. 27)

Soyuz Ventures Ltd is established in the United Kingdom. Where GDPR Article 27 applies to our processing of EU/EEA personal data, EU/EEA data subjects and supervisory authorities can use the Article 27 contacts below, kept in sync with the contact block on /privacy. As a UK-established controller we are not required to appoint a separate UK Article 27 representative.

EU representative
Art. 27 contact for EU/EEA data subjects
eu-rep@intirear.design
Controller / sub-processor disputes
privacy@intirear.design

International transfers

EU → US transfers are governed by Standard Contractual Clauses (SCCs) included in each sub-processor's DPA, supplemented (where the sub-processor processes personal data of EU residents in the US) by technical and organisational measures consistent with the European Data Protection Board's recommendations under Schrems II.

UK transfers rely on the UK International Data Transfer Addendum to the SCCs. Swiss transfers rely on the Swiss-FDPIC-recognised SCCs. We do not transfer personal data to any country lacking an EU Commission adequacy decision or an equivalent transfer mechanism.