Subprocessor Disclosure

Last updated: July 1, 2026

Hafinen Limited (“Hafinen”, “we”, “us”) uses carefully selected third-party service providers (“Subprocessors”) to support the delivery, security, reliability, and functionality of the Hafinen platform.

This page identifies the subprocessors currently authorized to process Customer Data or Personal Data in connection with Hafinen’s Services.

This disclosure forms part of Hafinen’s data protection and compliance framework and should be read together with our Privacy Policy, Terms of Service, and Data Processing Addendum (DPA).

What is a Subprocessor?

A Subprocessor is a third-party vendor engaged by Hafinen to process data on behalf of our customers in order to deliver our Services.

Subprocessors may support cloud infrastructure, email delivery, SMS delivery, payment processing, content delivery, DDoS protection, backups, API delivery, and system reliability.

Hafinen performs reasonable due diligence before engaging subprocessors.

Current Subprocessors

SubprocessorPurposeProcessing Regions
Amazon Web Services (AWS)Cloud infrastructure and hostingSouth Africa, United Kingdom
ContaboCloud infrastructure and backupsUnited States, Netherlands, United Kingdom, Germany
CloudflareCDN, security, DDoS mitigation, cachingGlobal
Mailgun TechnologiesTransactional email delivery and notificationsGermany, Belgium
Africa’s Talking International LimitedSMS notifications and deliveryKenya
Safaricom LimitedMobile money payment processingKenya
StripePayment processing for global self-service customersUnited States
PaystackPayment processing for self-service customers in AfricaKenya

Categories of Data Processed

Depending on the Services used, subprocessors may process limited categories of Customer Data, including account information, authentication metadata, email delivery metadata, billing records, payment transaction data, support logs, infrastructure logs, API logs, webhook delivery logs, and notification records.

Subprocessors do not receive access to Customer Data beyond what is necessary for their specific service function.

International Data Transfers

Because Hafinen serves customers globally, Customer Data may be processed across multiple jurisdictions.

Where data transfers occur internationally, Hafinen implements appropriate contractual and organizational safeguards consistent with applicable privacy laws.

Security and Compliance

Hafinen requires subprocessors to maintain reasonable security and privacy standards appropriate to the services they provide.

Where applicable, Hafinen enters into contractual agreements requiring confidentiality, security controls, lawful processing, breach reporting obligations, and data protection compliance.

Changes to Subprocessors

Hafinen may add, remove, or replace subprocessors as our Services evolve.

Where required by law or contract, Hafinen will provide notice of material changes.

Customers may contact Hafinen regarding any concerns about newly added subprocessors.

Contact

For questions regarding Hafinen subprocessors or data protection:

Hafinen Limited 107 Lower Kabete Road Westlands, Nairobi, Kenya Email: [email protected]

You can choose which optional cookies Hafinen may use to enhance your experience. Strictly necessary and security cookies are always enabled because they are essential for authentication, platform security, fraud prevention, and the reliable operation of the Services. You can update your preferences at any time.

Strictly Necessary Cookies

These cookies are essential for Hafinen to operate securely and reliably. They support account authentication, login sessions, CSRF protection, secure session continuity, load balancing, and other core platform functionality. Because these cookies are required for the Services to function, they cannot be disabled.

Security Cookies

These cookies help protect your account and the Services by detecting suspicious activity, preventing unauthorized access, mitigating abuse, validating API requests, supporting rate limiting, and maintaining platform integrity. These cookies are required for security and cannot be disabled.

Functional Cookies

Functional cookies remember your preferences and personalise your experience. They may store language, timezone, theme, accessibility settings, interface customisations, and dashboard preferences so you do not need to configure them each time you use the Services.

Analytics Cookies

Analytics cookies help us understand how the Services are used so we can improve usability, performance, and reliability. They collect information such as feature adoption, page interactions, navigation patterns, browser compatibility, crash reports, and performance metrics. Where possible, this information is aggregated or anonymised.

Performance Cookies

Performance cookies improve the speed, stability, and responsiveness of the Services. They support caching, content delivery optimisation, traffic balancing, asset loading, and other technologies that help deliver a consistent and reliable user experience.

Communication Cookies

Communication cookies support service-related interactions such as notification delivery, email event tracking, SMS confirmations, and other operational communication workflows that enhance how we keep you informed while using the Services.