Download the immutable Markdown source.
Version: 2026-09-07-beta.10 As of: 7 September 2026 Processor: Brillnet Piotr Adamski, ul. Henryka Sienkiewicza 73/6, 90-057 Łódź, NIP 7321779060, REGON 101551294 Contact and objection: privacy@ariveno.com
This English translation is provided for convenience. The binding text of this document is the Polish original of the same version (
2026-09-07-beta.10), available at https://ariveno.pl/legal/subprocessors.
1. How to read this list
- A direct subprocessor processes, on behalf of Ariveno, data entrusted by the salon. It is covered by the general authorisation under the Data Processing Agreement.
- A separate controller or a provider with a mixed role processes specific data for its own legal or billing purposes and is not a subprocessor of Salon Client data in the full scope.
- A provider chosen by the salon enters into a relationship directly with the salon. Ariveno only technically connects the Service with that provider in accordance with the salon's instructions.
- The location "EU" means the configuration of the primary resource, not an unconditional guarantee that no support, network or further provider will cause a technical transfer outside the EEA.
2. Direct subprocessors
2.1 Cloudflare
| Field | Information |
|---|---|
| Entity | Cloudflare, Inc. and the relevant group companies acting under the agreement with Ariveno |
| Headquarters | United States |
| Purpose | Workers hosting, D1 databases, private R2 objects, Durable Objects, queues, workflows, network, security, Turnstile, logging and primary transactional e-mail |
| Data | organisation, team, Salon Client, booking and appointment data; files; settings; technical and security data; content and metadata of primary transactional e-mail |
| Scope actually used | the D1, R2 and Durable Objects resources for organisations are configured for the EU jurisdiction; queues contain no PII content, only technical identifiers; the global network and support may operate outside the EEA |
| Transfer mechanism | the applicable adequacy decision/DPF, Standard Contractual Clauses and supplementary measures in accordance with the Cloudflare Customer DPA |
| Status | active, primary |
Provider documents:
- Cloudflare Customer DPA — the provider's current version;
- Cloudflare subprocessor list.
Cloudflare is a provider necessary for the operation of the Ariveno core. Refusing to accept its use means the Service cannot be provided in the current architecture.
2.2 Resend
| Field | Information |
|---|---|
| Entity | Plus Five Five, Inc., operator of the Resend service |
| Address | 2261 Market Street #5039, San Francisco, CA 94114, USA |
| Purpose | solely emergency dispatch of transactional e-mail messages after confirmed rejection or unavailability of the primary Cloudflare Email Service |
| Data | recipient's e-mail address, first name, salon brand, content of the transactional message and technical dispatch metadata |
| Ariveno restrictions | no automatic failover on unknown status; idempotency preventing duplicates; Ariveno does not add tracking pixels; no marketing campaigns |
| Transfer mechanism | EU–US Data Privacy Framework and/or Standard Contractual Clauses in accordance with the Resend DPA |
| Status | conditionally active, failover only |
Provider documents:
The list of Resend's further providers is broader than the elements used directly by Ariveno and may change. Ariveno limits the use of Resend to emergency transactional e-mail, but cannot present this path as processing exclusively within the EEA.
3. Entities that are not direct subprocessors of salon data in the full scope
3.1 Stripe
| Field | Information |
|---|---|
| Entity | the relevant Stripe group company indicated in Stripe Checkout and in the terms of the Operator's account, including Stripe Payments Europe, Limited, where applicable |
| Role | a payment provider whose role depends on the operation, including a separate controller of payer data for part of its payment and regulatory obligations |
| Purpose | Checkout, subscription, invoice status, payment webhook, fraud prevention |
| Data | billing account data, plan, amount, currency, subscription and payment identifiers, payment method data collected directly by Stripe |
| Exclusion | Ariveno does not transfer to Stripe any Salon Client, booking, appointment or schedule data and does not store full card data |
Stripe is not presented on this list as a direct subprocessor of the Salon Client database. Its own roles and obligations arise from Stripe's documents and payment law.
3.2 Ministry of Finance / KSeF
The National e-Invoicing System and the competent public authorities receive invoice data on the basis of the law and the actions of the Customer or the Operator. They are not a subprocessor of Ariveno. The scope depends on the applicable KSeF rules.
3.3 The Operator's e-mail and support providers
Correspondence to the support@, privacy@ and security@ addresses may be processed by the provider of the Operator's mailbox. Content should be limited to the data needed for the report; passwords, keys and unnecessary Salon Client data should not be sent. If a report contains Entrusted Data, the Operator treats the provider in accordance with subprocessor obligations and updates this list before using it regularly for such handling.
4. Provider chosen directly by the salon
SMSAPI / LINK Mobility Poland
| Field | Information |
|---|---|
| Entity | SMSAPI, a service of LINK Mobility Poland sp. z o.o. or the relevant operator indicated in the salon's agreement |
| Role | an additional provider/processor chosen and paid for directly by the salon |
| Purpose | sending optional SMS messages concerning appointments |
| Data | phone number, SMS content and delivery metadata |
| Condition | the salon itself creates the account, accepts the provider's terms, enters its own access credentials and is responsible for the legal basis of the messages |
Ariveno is a technical connector. SMS does not work until the salon itself enables the channel. SMSAPI is not a direct subprocessor engaged by Ariveno on behalf of all salons.
5. Technical components that are not recipients
Libraries run within Ariveno's infrastructure, e.g. Better Auth, are not separate data recipients merely because their code is used in the application. An external entity becomes a recipient only when it actually receives data or remotely provides a processing service.
In the current configuration, Ariveno does not use:
- Google Analytics;
- Google Ads;
- Meta Pixel;
- session recording tools;
- external AI model providers;
- marketing automation platforms;
- WhatsApp.
Enabling such a tool requires a prior assessment of the role, legal basis, transfer, retention and an update of the documents.
6. Changes and objection
- Ariveno will give notice of an intention to add or replace a direct Subprocessor at least 30 days in advance, by e-mail or in the Panel.
- The notice will indicate the entity, country, purpose, data and transfer mechanism.
- The salon may raise a justified objection within 30 days to privacy@ariveno.com.
- Ariveno and the salon will try to mitigate the risk, e.g. by disabling a feature or through a different configuration. If there is no reasonable solution, the salon may terminate the Service affected by the change before it is implemented.
- An urgent change forced by an incident or the discontinuation of a provider may be implemented faster, if it is necessary for security or continuity. Ariveno will give notice of it without undue delay and will provide the right to terminate the Service.
7. Version history
| Version | Date | Change |
|---|---|---|
2026-09-07-beta.10 | 2026-09-07 | Updated the Privacy Policy to cover ariveno.pl and ariveno.com; no changes to the subprocessor list. |
2026-09-02-beta.9 | 2026-09-02 | Removed Google Ads from the active configuration and recipient list; Ariveno uses first-party cookie-free analytics in line with the product baseline. |
2026-09-02-beta.8 | 2026-09-02 | Added EUR prices for businesses from EU countries other than Poland and the EU VAT/reverse-charge requirement in the Terms and Beta Terms; no change to the subprocessor list. |
2026-09-01-beta.7 | 2026-09-01 | Restored Resend (Plus Five Five, Inc.) as the emergency transactional e-mail provider, in line with the canonical product specification and the actual service configuration; EmailLabs (Vercom S.A.) is not an active emergency provider. Updated the as-of date of the list and supplemented the version history with beta.5 and beta.6. |
2026-08-29-beta.6 | 2026-08-29 | Unified the default retention of Salon Client data at 180 days and indicated the precedence of the salon's active configuration (changes in the Terms of Service, the Privacy Policy and the Data Processing Agreement); no substantive changes to the subprocessor list. |
2026-07-29-beta.5 | 2026-07-29 | Clarified the one-time trial period of the first subscription and the reuse of the subscription slot after permanent deletion of a salon (changes in the Terms of Service and the Public Beta Terms); no substantive changes to the subprocessor list. |
2026-07-29-beta.4 | 2026-07-29 | Added Google Ads as a separate controller of voluntary trial measurement; excluded Entrusted Data, Ariveno identifiers, personalisation and remarketing. |
2026-07-28-beta.3 | 2026-07-28 | Replaced the emergency provider Resend with the EmailLabs service provided by Vercom S.A.; updated the location, transfers and provider documents. |
2026-07-24-beta.2 | 2026-07-24 | Separated direct subprocessors, providers with a separate role and SMSAPI chosen by the salon; clarified transfers and the emergency use of Resend. |
Previous versions are available on request at privacy@ariveno.com.