Appearance
Subprocessor List
Effective Date: 2026-07-09 · Document ID: SL-MMA-001 · Contact: info@mapsted.com · Contact UsVersion: 1.0
Document ID: SL-MMA-001 Contact: privacy@mapsted.com
Purpose
This Subprocessor List fulfils Mapsted Corp.'s obligations under GDPR Article 28(4) and equivalent provisions of UK GDPR, Canada's PIPEDA, Québec's Act Respecting the Protection of Personal Information in the Private Sector (Law 25 / Bill 64), and the California CCPA/CPRA. It lists third-party entities that may process personal data on Mapsted Corp.'s behalf in connection with the delivery of the Mapsted Maps JavaScript API.
This list covers personal data processed as part of the Service — i.e., data arising from map sessions served to end users of Licensee applications, and data arising from Licensee developer interactions with Mapsted's API and documentation. It does not cover Mapsted Corp.'s internal HR, finance, or corporate systems.
Audit rights cross-reference: Licensees' audit rights with respect to subprocessor compliance are governed by the applicable section of the Data Processing Addendum (DPA-MMA-001) incorporated into the applicable Commercial Agreement.
Current Subprocessors
Google Cloud Platform
| Field | Detail |
|---|---|
| Subprocessor | Google LLC (operating as Google Cloud Platform) |
| Legal name and address | Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA |
| Purpose | Cloud infrastructure hosting for Mapsted's backend services (maps.mapsted.com, deploy.mapsted.com, filer.mapsted.com, and associated compute, storage, and networking) |
| Data categories | IP addresses, API request logs, map session data, building-data assets |
| Processing locations | United States — us-central1 (Iowa), us-east1 (South Carolina); Canada — northamerica-northeast1 (Montréal), northamerica-northeast2 (Toronto) |
| Transfer mechanism | EU SCCs 2021, Module 2 (Controller-to-Processor); Transfer Impact Assessment (TIA) completed and available to Licensees upon written request to privacy@mapsted.com |
| UK transfer instrument | UK International Data Transfer Addendum (IDTA), version B1.0 |
| Québec Law 25 — PIA | Privacy Impact Assessment under s. 70.1 of Law 25 completed; summary available to affected Licensees upon written request to privacy@mapsted.com |
| Export controls (EAR/ITAR) | Building spatial data (floor plans, point clouds, routing graphs) for airport and defence clients (e.g., Adani Airports) transferred to or processed by GCP may implicate the U.S. Export Administration Regulations (EAR) and/or the International Traffic in Arms Regulations (ITAR); export classification is required per Licensee vertical prior to processing |
| Sub-subprocessors | See Google Cloud sub-processor list: https://cloud.google.com/terms/subprocessors |
| Data retention | Server access logs: thirty (30) days; API-key audit logs: twelve (12) months; building-data assets: retained for the duration of the applicable Commercial Agreement and deleted within thirty (30) days of termination |
| DPA / contract status | Google Cloud Data Processing Agreement in place |
| Subprocessor DPA URL | https://cloud.google.com/terms/data-processing-addendum |
Cloudflare
| Field | Detail |
|---|---|
| Subprocessor | Cloudflare, Inc. |
| Legal name and address | Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA |
| Purpose | CDN edge delivery for the npm package CDN bundle (mapi.mapsted.com, served by Cloudflare CDN fronting GCP origin) and documentation site; DDoS mitigation; TLS termination |
| Data categories | IP addresses, HTTP request metadata (user-agent, referrer, path), TLS handshake data |
| Processing locations | Global edge network; where data-residency obligations apply, Mapsted Corp. will configure Cloudflare Data Localization Suite / Regional Services to restrict metadata processing to EEA/UK nodes before any Licensee relying on those obligations goes live. Current configuration is confirmed on request via privacy@mapsted.com |
| Supplementary measures | Cloudflare offers Data Localization Suite (DLS), Regional Services, and Customer Metadata Boundary (CMB) as supplementary data-residency controls. Activation of these controls for specific Licensee tenants is agreed in the Commercial Agreement and confirmed on request; do not rely on a blanket assertion of activation |
| Transfer mechanism | EU SCCs 2021, Module 2 (Controller-to-Processor); Transfer Impact Assessment (TIA) completed and available to Licensees upon written request to privacy@mapsted.com |
| UK transfer instrument | UK International Data Transfer Addendum (IDTA), version B1.0 |
| Québec Law 25 — PIA | Privacy Impact Assessment under s. 70.1 of Law 25 completed; summary available to affected Licensees upon written request to privacy@mapsted.com |
| Sub-subprocessors | See Cloudflare sub-processor list: https://www.cloudflare.com/gdpr/subprocessors/ — see also Cloudflare Logs / Logpush row below |
| Data retention | Edge request logs: thirty (30) days (default Cloudflare Logs retention); tile/asset cache: twenty-four (24) hours TTL |
| DPA / contract status | Cloudflare Data Processing Agreement in place |
| Subprocessor DPA URL | https://www.cloudflare.com/cloudflare-customer-dpa/ |
Cloudflare Logs / Logpush (secondary subprocessor)
| Field | Detail |
|---|---|
| Subprocessor | Cloudflare, Inc. (secondary processing role — log export) |
| Legal name and address | Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA |
| Purpose | If Cloudflare Logs or Logpush is configured, raw HTTP request logs (including IP addresses and request metadata) may be exported to a designated log destination (e.g., GCP Storage, S3, Datadog, Splunk) |
| Data categories | IP addresses, HTTP request logs, TLS metadata |
| Processing locations | Depends on Logpush destination configuration; Mapsted's current Logpush destinations are within GCP regions listed above (us-central1, northamerica-northeast1/2) |
| Transfer mechanism | Governed by the Cloudflare DPA and the transfer mechanism of the Logpush destination |
| Québec Law 25 — PIA | Covered by the Cloudflare PIA noted above; Logpush destinations within Canada are used where Québec resident data is at issue |
| Sub-subprocessors | Depends on Logpush destination |
| Data retention | Logpush destination retention: thirty (30) days for raw HTTP logs |
| DPA / contract status | Covered by Cloudflare DPA; Logpush destinations within GCP are covered by the Google Cloud DPA noted above |
| Subprocessor DPA URL | https://www.cloudflare.com/cloudflare-customer-dpa/ |
npm, Inc. (package distribution)
| Field | Detail |
|---|---|
| Subprocessor | npm, Inc. (a subsidiary of GitHub, Inc., a subsidiary of Microsoft Corporation) |
| Legal name and address | npm, Inc., c/o GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA. Current registered office confirmed via the GitHub Subprocessor List below |
| Purpose | Distribution of the @mapsted/maps-js-api npm package to Licensee developers via registry.npmjs.org |
| Data categories | Developer (Licensee) account data only; no end-user personal data is processed through npm |
| Processing locations | United States |
| Transfer mechanism | EU SCCs 2021, Module 2 (Controller-to-Processor) via GitHub/Microsoft Data Processing Agreement |
| CLOUD Act chain | Microsoft Corporation (ultimate parent of GitHub/npm) is subject to the U.S. Clarifying Lawful Overseas Use of Data Act (CLOUD Act), which may permit U.S. law enforcement to compel disclosure of data held by Microsoft and its subsidiaries (including GitHub and npm) regardless of storage location. Licensees subject to GDPR, UK GDPR, or Québec Law 25 should assess this chain in their own transfer-risk assessments |
| npm postinstall lifecycle hooks | The @mapsted/maps-js-api package does not include postinstall or other lifecycle scripts that execute code during npm install in Licensee environments |
| Québec Law 25 — PIA | Privacy Impact Assessment scoped to developer account data completed; summary available upon written request to privacy@mapsted.com |
| Sub-subprocessors | See GitHub/Microsoft sub-processor list: https://docs.github.com/en/site-policy/privacy-policies/github-subprocessors-and-cookies |
| Data retention | npm registry download metadata: twelve (12) months under npm's standard data retention policy |
| DPA / contract status | GitHub Data Protection Agreement in place covering npm services |
| Subprocessor DPA URL | GitHub Privacy Policy index: https://docs.github.com/en/site-policy/privacy-policies. The current Customer Data Protection Agreement is provided on request via the GitHub enterprise account channel |
Additional Subprocessors
The following categories of subprocessors may be added as the Service evolves. Mapsted will provide thirty (30) days' advance notice before any new subprocessor that may process personal data covered by the applicable Data Processing Addendum is added:
- Error monitoring / crash reporting service (if any) — DPA to be confirmed and listed upon activation.
- Email delivery service (for developer account notifications, Commercial Agreement communications) — DPA to be confirmed and listed upon activation.
- Analytics platform (for documentation site, if any) — DPA to be confirmed; personal data processing will be disclosed if applicable.
- Customer relationship management (CRM) (for commercial agreement management) — DPA to be confirmed; end-user data scope to be confirmed.
Change Notification
Mapsted Corp. will provide at least thirty (30) days advance notice before any new subprocessor is added that may process personal data covered by the applicable Data Processing Addendum. Notice will be published as an addendum to this page and communicated directly as specified in the applicable Data Processing Addendum.
Licensees acting as controllers retain statutory objection rights to new subprocessors under GDPR Article 28(2) and equivalent provisions, regardless of contractual status. Licensees may exercise their objection rights within the notice period by contacting privacy@mapsted.com. Where an objection cannot be resolved, the Licensee may terminate the affected services in accordance with the Commercial Agreement.
Change History
| Date | Change | Notified |
|---|---|---|
| 2026-07-09 | Initial list published | Publication |
Related documents
- Privacy Policy — PP-MMA-001
- Data Processing Addendum (DPA-MMA-001)
- Legal Hub