Who touches
your data.
About this page
Under GDPR Article 28(2), we must publish the complete list of sub-processors that process personal data on our behalf, with their category, purpose, region, and DPA reference. This is that list. It is the canonical public version of our internal DPA document.
We commit to providing at least 30 days' advance notice before adding a new sub-processor — by updating this page and, for users with an active account, by an in-app banner. Material changes also bump the privacy-policy version, which triggers a re-consent prompt at next login.
Current sub-processors
| Sub-processor | Purpose | Data category | Region | DPA |
|---|---|---|---|---|
| Amazon Web Services (Amplify Hosting, Cognito, DynamoDB, S3 + CloudFront) | App backend — web + API hosting, sign-in, account and project data, image storage and delivery | Account email, name, uploaded photos, generated images, chat messages, all request/response data, geo IP | US (us-east-1) + global CDN | Link |
| Amazon Web Services (Rekognition) | Automated content-safety screening of uploaded room photos and generated outputs | Image bytes (analysed and discarded, not retained) | US (us-east-1) | Link |
| Google Firebase (Cloud Messaging) + Google Play Integrity | Android push-notification delivery and Android app-integrity attestation | Device push token, app-integrity verdict | US | Link |
| KIE.ai (Kiengage Ltd.) | AI image generation and photo understanding (room-type detection, layout analysis, furniture cataloguing) | Image input, prompt text | US | Link |
| Google (Gemini models, accessed via KIE.ai) | Operates the image and vision models that run the generation and photo-understanding requests | Image input, prompt text | US | Link |
| Ideogram (accessed via KIE.ai) | Operates the inpainting model used for selective edits (masked regions only) | Image input, mask image, prompt text | US | Link |
| Adapty Tech, Inc. | In-app purchase analytics + receipt validation | Anonymous device id, purchase events | US | Link |
| Apple App Store / StoreKit | iOS payments | Apple ID hash, purchase data | Apple-controlled | Link |
| Google Play | Android payments | Google account hash, purchase data | Google-controlled | Link |
| Zoho (ZeptoMail / Zoho Mail) | Transactional email sending + support inbox hosting (welcome, password reset, design-emailed-to-you, support@) | Email address, message content | US/EU | Link |
| Stripe | Web subscription billing | Last 4 of card, billing address, country | Global | Link |
| Google Analytics (GA4) | Web product analytics (loaded only after cookie consent) | Redacted page paths, first-party analytics cookie (_ga) | US/Global | Link |
Last updated: 2026-08-29. Subscribe to changes by emailing privacy@intirear.design with the subject “Subscribe to sub-processor updates”.
Retention summary
- Account data: retained while active. Deleted within 30 days of request (Art. 17).
- Generated images: retained until you delete them or close your account.
- Source room uploads: 365 days from upload (auto-deleted via S3 lifecycle rule).
- Inpainting masks: 7 days from creation.
- Crash and error reports: 30 days (stored first-party, auto-expiring — no third-party crash SDK).
- Server access logs: 30 days on AWS (Amplify/CloudWatch).
- Analytics events: 180 days from the event, then auto-expired. Account deletion severs the linkage within that window rather than erasing the row (user-id replaced with “anonymized”), because the rows are aggregate counts.
- Audit logs (moderation, opt-outs, admin actions): 7 years for legal-defence retention.
EU Representative (Art. 27)
Soyuz Ventures Ltd is established in the United Kingdom. Where GDPR Article 27 applies to our processing of EU/EEA personal data, EU/EEA data subjects and supervisory authorities can use the Article 27 contacts below, kept in sync with the contact block on /privacy. As a UK-established controller we are not required to appoint a separate UK Article 27 representative.
- EU representative
- Art. 27 contact for EU/EEA data subjects
eu-rep@intirear.design - Privacy contact
- privacy@intirear.design
- Controller / sub-processor disputes
- privacy@intirear.design
International transfers
EU → US transfers are governed by Standard Contractual Clauses (SCCs) included in each sub-processor's DPA, supplemented (where the sub-processor processes personal data of EU residents in the US) by technical and organisational measures consistent with the European Data Protection Board's recommendations under Schrems II.
UK transfers rely on the UK International Data Transfer Addendum to the SCCs. Swiss transfers rely on the Swiss-FDPIC-recognised SCCs. We do not transfer personal data to any country lacking an EU Commission adequacy decision or an equivalent transfer mechanism.