Subprocessor Disclosure

Last updated: July 1, 2026

Hafinen Limited (“Hafinen”, “we”, “us”) uses carefully selected third-party service providers (“Subprocessors”) to support the delivery, security, reliability, and functionality of the Hafinen platform.

This page identifies the subprocessors currently authorized to process Customer Data or Personal Data in connection with Hafinen’s Services.

This disclosure forms part of Hafinen’s data protection and compliance framework and should be read together with our Privacy Policy, Terms of Service, and Data Processing Addendum (DPA).

What is a Subprocessor?

A Subprocessor is a third-party vendor engaged by Hafinen to process data on behalf of our customers in order to deliver our Services.

Subprocessors may support cloud infrastructure, email delivery, SMS delivery, payment processing, content delivery, DDoS protection, backups, API delivery, and system reliability.

Hafinen performs reasonable due diligence before engaging subprocessors.

Current Subprocessors

SubprocessorPurposeProcessing Regions
Amazon Web Services (AWS)Cloud infrastructure and hostingSouth Africa, United Kingdom
ContaboCloud infrastructure and backupsUnited States, Netherlands, United Kingdom, Germany
CloudflareCDN, security, DDoS mitigation, cachingGlobal
Mailgun TechnologiesTransactional email delivery and notificationsGermany, Belgium
Africa’s Talking International LimitedSMS notifications and deliveryKenya
Safaricom LimitedMobile money payment processingKenya
StripePayment processing for global self-service customersUnited States
PaystackPayment processing for self-service customers in AfricaKenya

Categories of Data Processed

Depending on the Services used, subprocessors may process limited categories of Customer Data, including account information, authentication metadata, email delivery metadata, billing records, payment transaction data, support logs, infrastructure logs, API logs, webhook delivery logs, and notification records.

Subprocessors do not receive access to Customer Data beyond what is necessary for their specific service function.

International Data Transfers

Because Hafinen serves customers globally, Customer Data may be processed across multiple jurisdictions.

Where data transfers occur internationally, Hafinen implements appropriate contractual and organizational safeguards consistent with applicable privacy laws.

Security and Compliance

Hafinen requires subprocessors to maintain reasonable security and privacy standards appropriate to the services they provide.

Where applicable, Hafinen enters into contractual agreements requiring confidentiality, security controls, lawful processing, breach reporting obligations, and data protection compliance.

Changes to Subprocessors

Hafinen may add, remove, or replace subprocessors as our Services evolve.

Where required by law or contract, Hafinen will provide notice of material changes.

Customers may contact Hafinen regarding any concerns about newly added subprocessors.

Contact

For questions regarding Hafinen subprocessors or data protection:

Hafinen Limited 107 Lower Kabete Road Westlands, Nairobi, Kenya Email: [email protected]

Deneyiminizi geliştirmek için Hafinen'in hangi isteğe bağlı çerezleri kullanabileceğini seçebilirsiniz. Kimlik doğrulama, platform güvenliği, dolandırıcılığın önlenmesi ve Hizmetlerin güvenilir şekilde çalışması için gerekli olmaları nedeniyle kesinlikle gereklidir ve güvenlik çerezleri her zaman etkinleştirilir. Tercihlerinizi istediğiniz zaman güncelleyebilirsiniz.

Kesinlikle Gerekli Çerezler

Bu çerezler Hafinen'in güvenli ve güvenilir bir şekilde çalışması için gereklidir. Hesap kimlik doğrulamasını, oturum açma oturumlarını, CSRF korumasını, güvenli oturum sürekliliğini, yük dengelemeyi ve diğer temel platform işlevlerini desteklerler. Bu çerezler Hizmetlerin çalışması için gerekli olduğundan devre dışı bırakılamazlar.

Güvenlik Çerezleri

Bu çerezler, şüpheli etkinlikleri tespit ederek, yetkisiz erişimi önleyerek, kötüye kullanımı azaltarak, API isteklerini doğrulayarak, hız sınırlamasını destekleyerek ve platform bütünlüğünü koruyarak hesabınızın ve Hizmetlerin korunmasına yardımcı olur. Bu çerezler güvenlik açısından gereklidir ve devre dışı bırakılamaz.

Fonksiyonel Çerezler

İşlevsel çerezler tercihlerinizi hatırlar ve deneyiminizi kişiselleştirir. Dil, saat dilimi, tema, erişilebilirlik ayarları, arayüz özelleştirmeleri ve kontrol paneli tercihlerini saklayabilirler; böylece Hizmetleri her kullandığınızda bunları yapılandırmanıza gerek kalmaz.

Analiz Çerezleri

Analitik çerezleri, Hizmetlerin nasıl kullanıldığını anlamamıza yardımcı olur, böylece kullanılabilirliği, performansı ve güvenilirliği geliştirebiliriz. Özellik benimseme, sayfa etkileşimleri, gezinme modelleri, tarayıcı uyumluluğu, kilitlenme raporları ve performans ölçümleri gibi bilgileri toplarlar. Mümkün olduğunda bu bilgiler toplu hale getirilir veya anonimleştirilir.

Performans Çerezleri

Performans çerezleri Hizmetlerin hızını, kararlılığını ve yanıt verebilirliğini artırır. Tutarlı ve güvenilir bir kullanıcı deneyimi sunmaya yardımcı olan önbelleğe alma, içerik dağıtım optimizasyonu, trafik dengeleme, varlık yükleme ve diğer teknolojileri desteklerler.

İletişim Çerezleri

İletişim çerezleri, bildirim teslimi, e-posta olay takibi, SMS onayları gibi hizmetle ilgili etkileşimleri ve Hizmetleri kullanırken sizi bilgilendirme şeklimizi geliştiren diğer operasyonel iletişim iş akışlarını destekler.