Scope
Providers supporting GenderAPI
This register distinguishes DPA subprocessors that can process Customer Personal Data from operational providers used for GenderAPI's separate controller activities. A provider processes only the categories necessary for the relevant function. Conditional providers are used only when the customer selects or interacts with that function.
Google Analytics, Google Tag Manager and Google Ads are consent-based website measurement services and are described separately in the Privacy Policy. The private GenderAPI-operated AI is not a third-party subprocessor.
Provider Register
| Provider | Purpose | Data categories | Processing location | Role and use |
|---|---|---|---|---|
| Cloudflare | Network delivery, traffic security and bot protection | Network identifiers, request headers and security telemetry | Global, including the United States | DPA subprocessor · core infrastructure |
| DigitalOcean | Application, database and file-processing hosting | Customer data processed through the Service, account data and technical logs | United States | DPA subprocessor · core infrastructure |
| iyzico | Card-payment processing | Customer, order, transaction, device and payment information | Türkiye and provider-authorized locations | Operational provider · card payments only |
| Binance | USDT payment and transaction verification | Transaction identifiers, amount, currency and wallet or account information | Provider-authorized locations | Operational provider · cryptocurrency payments only |
| Twilio SendGrid | Transactional registration, verification and password-recovery email | Recipient email address, message content and delivery metadata | United States and provider-authorized locations | Operational provider · transactional email only |
| Google Workspace / Gmail | Manual customer support | Contact details, support-message content, attachments and message metadata | Provider-authorized locations | Operational provider · when email support is used |
| Chatra | Live customer support | Contact details, conversation content and technical session metadata | Provider-authorized locations | Operational provider · when live support is used |
The precise contracting entity and processing locations can depend on the applicable provider account and service configuration. Provider-authorized locations may include subprocessors disclosed under that provider's own data-protection terms.
Change Notices
GenderAPI will provide at least 30 days' advance notice through this page, the Service or the customer's account email before adding or replacing a provider that will process Customer Personal Data under the Data Processing Agreement. The page's “Last updated” date records the current register version.
A customer may submit a reasonable, documented data-protection objection during the notice period under the procedure in the Data Processing Agreement.
Contact
For subprocessor questions or DPA requests, contactsupport@genderapi.io.