AMS Solutions d.o.o. · Frenkova ulica 23, 6280 Ankaran, Slovenia
Governing Article 28 GDPR Data Processing obligations for Tremble application sub-processors.
1. Scope & Obligations
Pursuant to Article 28 of Regulation (EU) 2016/679 (GDPR) and ZVOP-2, AMS Solutions d.o.o. maintains strict Data Processing Agreements with all technical service providers. Processors act strictly under documented instructions, enforce data confidentiality, maintain EU-standard encryption at rest and in transit, and assist in fulfilling data subject rights.
2. System Sub-processors (Annex 1)
| Provider | Service | Location | Transfer Instrument |
|---|---|---|---|
| Google Cloud / Firebase | Firestore, Auth, FCM, Crashlytics, Functions | EU (europe-west1) | Google Cloud DPA |
| Google LLC (Places API) | Location autocomplete | EU | Google Cloud DPA |
| Cloudflare Inc. | R2 Storage (media & avatars), Pages, Workers | EU / Global | Cloudflare DPA + SCC |
| Upstash Inc. | Redis REST (rate limiting & TTL) | EU | Upstash DPA |
| Sentry (Functional Software) | Crash & error reporting | EU hosting | Sentry DPA + SCC |
| Resend Labs Inc. | Transactional email | US / EU | Resend DPA + SCC |
| RevenueCat Inc. | In-App Subscriptions (App Store / Google Play) | US | RevenueCat DPA + SCC |
| Apple Inc. / Google LLC | APNs, Sign In with Apple, App Stores | Global / EU | Standard Contractual Clauses |
3. International Data Transfers
For data transfers outside the EEA (e.g. RevenueCat, Apple Inc., Sentry), AMS Solutions d.o.o. relies on EU Standard Contractual Clauses (SCCs) pursuant to EU Commission Decision 2021/914 and/or the EU-U.S. Data Privacy Framework (DPF) certifications.