1. Introduction
1.1 This Subprocessor List forms part of the Data Processing Addendum (the "DPA") between FixAdmin Inc., a Florida corporation, with its principal place of business in the State of Florida, United States ("FixAdmin") and the business customer that has entered into the Agreement (the "Customer"). Where FixAdmin processes Customer Data — including personal data of the Customer's End Customers — on behalf of the Customer as its processor, FixAdmin engages the third-party subprocessors listed in Section 2 to deliver the Service. The Customer's execution of, or agreement to, the DPA constitutes a general written authorization for the engagement of these subprocessors.
1.2 Notice of changes. FixAdmin will give the Customer at least thirty (30) days' prior notice of the addition or replacement of any subprocessor of Customer Data, by email to the account owner and/or by notice within the Service, before the new subprocessor begins processing Customer Data.
1.3 Objection mechanism. The Customer may object to a new subprocessor on reasonable, documented data-protection grounds within the notice period, following the objection procedure set out in the DPA. If the parties cannot resolve the objection as provided in the DPA, the Customer may terminate the affected Subscription in accordance with the DPA.
1.4 Each subprocessor is bound by written terms imposing data-protection obligations consistent with those in the DPA. Data locations reflect each provider's infrastructure; the Service's primary hosting regions are the United States and Brazil (São Paulo) on Google Cloud, together with other regions operated by the providers listed below.
2. Subprocessors of Customer Data
| Entity | Service function | Personal data involved | Location / region |
|---|---|---|---|
| Google LLC | Cloud platform and hosting: Firebase / Google Cloud (Firestore database, Authentication, Cloud Storage, Cloud Functions, Hosting, Cloud Messaging (push), App Check / reCAPTCHA v3, Secret Manager) | All data stored and processed in the Service, including: Authorized User account data (name, email, phone, role/branches, optional profile photo, push tokens, optional 2FA phone, last login); End Customer records entered by the Customer (name, phone, device and fault description, amounts and balances, optional device unlock PIN/pattern, evidence photos and videos); company profile and marketplace listing data; encrypted WhatsApp access tokens | United States and Brazil (São Paulo) (Google Cloud); other Google regions per provider infrastructure |
| Cloudflare, Inc. | Reverse proxy, CDN and security layer for fixadmin.app; edge Web Analytics (Cloudflare Insights) | IP addresses and technical request metadata of visitors and Authorized Users whose traffic transits the Cloudflare network; aggregated analytics measurements | Global edge network; headquartered in the United States |
3. Third-party platform engaged directly by the Customer
3.1 Meta Platforms, Inc. The Customer holds its own WhatsApp Business Account under its direct agreement with Meta; FixAdmin transmits Customer Data to Meta solely on the Customer's instruction as part of the WhatsApp Features. Meta is not a subprocessor engaged by FixAdmin, and DPA §8.3 does not apply to Meta.
3.2 For transparency, the data flow to Meta is as follows:
| Entity | Platform function | Personal data transmitted | Location / region |
|---|---|---|---|
| Meta Platforms, Inc. | WhatsApp Business Cloud API (delivery of the Customer's WhatsApp messages to its End Customers; message status webhooks; on connection via coexistence, Meta synchronizes contacts and chat history from the Customer's WhatsApp Business App to the Cloud API); Facebook JS SDK (loaded only during Embedded Signup, web) | End Customer phone number and name; message template variables (which may include amounts and dates); free-text messages sent within the 24-hour service window; message delivery status data; the Customer's WhatsApp Business Account OAuth tokens; synchronized contacts and chat history where coexistence is used | United States and other Meta regions per provider infrastructure |
4. Service providers that are not subprocessors of Customer Data
The following providers support the Service but do not process Customer Data on the Customer's behalf; they are therefore not subprocessors under the DPA. Where indicated, FixAdmin acts as an independent controller of the data these providers process, as described in the Privacy Policy.
| Entity | Service function | Why it is not a subprocessor of Customer Data |
|---|---|---|
| Stripe, Inc. | Payment processing for FixAdmin Subscriptions (Stripe-hosted checkout) | Stripe processes billing data (administrator name, email, company identifier, payment transactions) for FixAdmin's own billing purposes, for which FixAdmin acts as controller. Payment card data is provided by the Customer directly to Stripe; FixAdmin never receives card numbers. No End Customer data is shared with Stripe. |
| Google LLC (telemetry, diagnostics and maps) | Google Analytics 4 (mobile: active; web: implemented but not currently collecting); Crashlytics (mobile crash reporting: user ID, company ID, screen route); Google Maps (web/Android/iOS map display) | Google also processes telemetry and diagnostics data (Google Analytics 4, Crashlytics) for which FixAdmin acts as controller, as described in the Privacy Policy; that processing is outside the scope of this Subprocessor List. Google Maps displays map content in the applications and is not used to process Customer Data on the Customer's behalf. |
| Resend, Inc. | Transactional email delivery for the Service (account verification, password reset, welcome, 2FA-related notices, deactivation and purge notices, contact-mailbox messages) | Resend processes only account-holder email addresses and transactional content for which FixAdmin is controller; no End Customer data. The Service does not store End Customer email addresses, and FixAdmin does not email End Customers. |
| Apple Inc. / Google (Google Play) | Distribution of the FixAdmin mobile applications through their respective app stores | App distribution only. These stores are not payment channels for the Service, and no Customer Data is processed by them on the Customer's behalf. |
| OpenStreetMap Foundation (Nominatim) | Server-side geocoding of marketplace store addresses | Receives only business store addresses chosen by the Customer for its public listing; no personal data of individuals and no user identity is transmitted. |
5. Version and date
5.1 This list was last revised in August 2026 (Version 4.0.2 — August 2026). The current version is published within the Service and at the address designated by FixAdmin. Questions and objections: [email protected].
5.2 Language. This List is drafted in English, which is the official and binding version and prevails in case of any conflict, to the maximum extent permitted by applicable law. The Spanish version published in the application and website is an official courtesy translation. Acceptance is recorded against the document version and language presented to the user.