Subprocessor Disclosure

Last updated: July 1, 2026

Hafinen Limited (“Hafinen”, “we”, “us”) uses carefully selected third-party service providers (“Subprocessors”) to support the delivery, security, reliability, and functionality of the Hafinen platform.

This page identifies the subprocessors currently authorized to process Customer Data or Personal Data in connection with Hafinen’s Services.

This disclosure forms part of Hafinen’s data protection and compliance framework and should be read together with our Privacy Policy, Terms of Service, and Data Processing Addendum (DPA).

What is a Subprocessor?

A Subprocessor is a third-party vendor engaged by Hafinen to process data on behalf of our customers in order to deliver our Services.

Subprocessors may support cloud infrastructure, email delivery, SMS delivery, payment processing, content delivery, DDoS protection, backups, API delivery, and system reliability.

Hafinen performs reasonable due diligence before engaging subprocessors.

Current Subprocessors

SubprocessorPurposeProcessing Regions
Amazon Web Services (AWS)Cloud infrastructure and hostingSouth Africa, United Kingdom
ContaboCloud infrastructure and backupsUnited States, Netherlands, United Kingdom, Germany
CloudflareCDN, security, DDoS mitigation, cachingGlobal
Mailgun TechnologiesTransactional email delivery and notificationsGermany, Belgium
Africa’s Talking International LimitedSMS notifications and deliveryKenya
Safaricom LimitedMobile money payment processingKenya
StripePayment processing for global self-service customersUnited States
PaystackPayment processing for self-service customers in AfricaKenya

Categories of Data Processed

Depending on the Services used, subprocessors may process limited categories of Customer Data, including account information, authentication metadata, email delivery metadata, billing records, payment transaction data, support logs, infrastructure logs, API logs, webhook delivery logs, and notification records.

Subprocessors do not receive access to Customer Data beyond what is necessary for their specific service function.

International Data Transfers

Because Hafinen serves customers globally, Customer Data may be processed across multiple jurisdictions.

Where data transfers occur internationally, Hafinen implements appropriate contractual and organizational safeguards consistent with applicable privacy laws.

Security and Compliance

Hafinen requires subprocessors to maintain reasonable security and privacy standards appropriate to the services they provide.

Where applicable, Hafinen enters into contractual agreements requiring confidentiality, security controls, lawful processing, breach reporting obligations, and data protection compliance.

Changes to Subprocessors

Hafinen may add, remove, or replace subprocessors as our Services evolve.

Where required by law or contract, Hafinen will provide notice of material changes.

Customers may contact Hafinen regarding any concerns about newly added subprocessors.

Contact

For questions regarding Hafinen subprocessors or data protection:

Hafinen Limited 107 Lower Kabete Road Westlands, Nairobi, Kenya Email: [email protected]

Sie können wählen, welche optionalen Cookies Hafinen verwenden darf, um Ihr Erlebnis zu verbessern. Unbedingt notwendige Cookies und Sicherheitscookies sind immer aktiviert, da sie für die Authentifizierung, Plattformsicherheit, Betrugsprävention und den zuverlässigen Betrieb der Dienste unerlässlich sind. Sie können Ihre Einstellungen jederzeit aktualisieren.

Unbedingt notwendige Cookies

Diese Cookies sind für den sicheren und zuverlässigen Betrieb von Hafinen unerlässlich. Sie unterstützen Kontoauthentifizierung, Anmeldesitzungen, CSRF-Schutz, sichere Sitzungskontinuität, Lastausgleich und andere Kernfunktionen der Plattform. Da diese Cookies für die Funktion der Dienste erforderlich sind, können sie nicht deaktiviert werden.

Sicherheitscookies

Diese Cookies tragen zum Schutz Ihres Kontos und der Dienste bei, indem sie verdächtige Aktivitäten erkennen, unbefugten Zugriff verhindern, Missbrauch eindämmen, API-Anfragen validieren, Ratenbegrenzung unterstützen und die Plattformintegrität aufrechterhalten. Diese Cookies sind aus Sicherheitsgründen erforderlich und können nicht deaktiviert werden.

Funktionale Cookies

Funktionelle Cookies erinnern sich an Ihre Präferenzen und personalisieren Ihr Erlebnis. Sie können Sprache, Zeitzone, Thema, Barrierefreiheitseinstellungen, Schnittstellenanpassungen und Dashboard-Einstellungen speichern, sodass Sie diese nicht jedes Mal konfigurieren müssen, wenn Sie die Dienste nutzen.

Analyse-Cookies

Analysecookies helfen uns zu verstehen, wie die Dienste genutzt werden, damit wir Benutzerfreundlichkeit, Leistung und Zuverlässigkeit verbessern können. Sie sammeln Informationen wie Funktionsakzeptanz, Seiteninteraktionen, Navigationsmuster, Browserkompatibilität, Absturzberichte und Leistungsmetriken. Soweit möglich werden diese Informationen aggregiert oder anonymisiert.

Leistungscookies

Leistungscookies verbessern die Geschwindigkeit, Stabilität und Reaktionsfähigkeit der Dienste. Sie unterstützen Caching, Optimierung der Inhaltsbereitstellung, Verkehrsausgleich, Asset Loading und andere Technologien, die dazu beitragen, ein konsistentes und zuverlässiges Benutzererlebnis zu bieten.

Kommunikations-Cookies

Kommunikations-Cookies unterstützen dienstbezogene Interaktionen wie die Zustellung von Benachrichtigungen, die Verfolgung von E-Mail-Ereignissen, SMS-Bestätigungen und andere betriebliche Kommunikationsabläufe, die die Art und Weise verbessern, wie wir Sie während der Nutzung der Dienste auf dem Laufenden halten.