1. How to read this list
A subprocessor processes Customer Personal Data on Decennium's behalf. Some services, especially payment, identity, and publication destinations selected by a Customer, may instead act as an independent controller or recipient for their own purposes. Identifying them here does not change the legal role imposed by law.
A provider only receives data needed for an enabled feature. A provider marked conditional is not authorised merely because its integration exists in code; the production release gate and Customer action must also enable it.
2. Core subprocessors
The following providers support the core Service:
- Google Cloud Platform and Firebase (applicable Google contracting entity): authentication infrastructure, cloud functions, database, object storage, security tooling, and operational logging. Data may be processed in configured cloud regions and other locations used for secure support and resilience.
- Google Cloud Vision API (conditional): OCR and SafeSearch inspection of generated media only when the media-approval runtime is enabled. Generated media and extracted visual signals may be processed in the Google Cloud project and provider locations applicable to that operation.
- Vercel Inc.: hosting, content delivery, web application execution, network security, and deployment logs for moduly.club. Processing may occur in the United States and Vercel's global edge locations.
- OpenAI, L.L.C. (conditional): business/API text or media generation only when the corresponding production provider switch is enabled. Relevant prompts, evidence excerpts, drafts, and requested media may be processed in the United States or other provider locations under the applicable enterprise/API data controls.
- Google Cloud Vertex AI (conditional): text, classification, extraction, or media operations only when selected as the production model provider. Processing uses the Google Cloud project and configured location applicable to the operation.
3. Payments and billing
Stripe (applicable Stripe group entity shown at Checkout or on the transaction record) processes payment, billing address, tax identifier, fraud-prevention, invoice, subscription, and refund data. Stripe acts as an independent controller for some regulated payment and fraud purposes and as a processor or service provider for limited billing operations.
Decennium does not receive or store full card numbers. Stripe's own privacy notice and Checkout terms apply to data entered on Stripe-hosted pages.
4. Customer-directed identity and publishing recipients
Google sign-in, Peqaboo sign-in, Meta platforms, Peqaboo publishing, and future channels are used only when a user selects the relevant identity or connector flow. Those providers receive the identifiers, scopes, content, audience settings, and publication data necessary for the requested action and may act as independent controllers under their own terms.
Peqaboo is operated by Decennium Platforms Limited. A Peqaboo connector does not merge Moduly and Peqaboo memberships, billing, or private workspaces; it authorises only the documented sign-in or publication scope.
5. Changes and objections
For a new subprocessor that will process Customer Personal Data, Decennium will normally give at least 30 days' advance notice through the workspace, account email, or this page plus a subscribed notice channel. An urgent security or legal replacement may take effect sooner, with notice as soon as reasonably practicable.
A Customer may object during the notice period on reasonable data-protection grounds by emailing privacy@decennium.app and identifying the affected workspace, provider, and grounds. The resolution process in the DPA applies.
6. Contact and change history
Privacy and DPA questions: privacy@decennium.app. General service questions: hello@decennium.app.
Release history — Version 1.0 text dated 14 July 2026: initial list for the standalone Moduly service. Provider activation remains subject to production configuration; an inactive conditional provider does not receive Customer Personal Data.