v2.4 · in force from 2026-04-12 · SICKW.COM
This document sets out the arrangements under Article 28 GDPR where IMEI API PRO S.R.L. ("Processor") processes personal data on behalf of a business customer ("Controller"), and lists our sub-processors.
2.1 For your account, billing and security data, we act as controller — see the Privacy Policy.
2.2 For data you submit through the service in order to obtain a result, we act as processor on your behalf, to the extent that data is personal data.
2.3 Device identifiers alone (IMEI, serial) are treated as technical identifiers, not as personal data, because we do not link them to a person.
We: process personal data only on your documented instructions (your use of the service being the instruction); ensure that people authorised to process it are bound by confidentiality; apply appropriate technical and organisational measures; assist you with data subject requests and with Articles 32–36 as far as we reasonably can; and, at your choice, delete or return the data at the end of the service, unless the law requires us to keep it.
| Sub-processor | Role | Location |
|---|---|---|
| Cloudflare, Inc. | CDN, WAF, DDoS protection | EU / US |
| Hosting provider (dedicated servers) | Application and database hosting | EU (France / Canada) |
| Amazon Web Services (SES) | Transactional e-mail delivery | US |
| Stripe Payments Europe Ltd. | Card payments | EU / US |
| Mollie B.V. | European payment methods | EU |
| Revolut Ltd. | Payments | EU / UK |
| Upstream data providers | Return the requested device information | Varies by service |
We will tell you of any intended change to this list and you may object on reasonable data-protection grounds.
Transfers outside the EEA rely on the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) or an adequacy decision, with supplementary measures where required.
Encryption in transit (TLS); hashed passwords; access control and least privilege; network-level filtering and rate limiting; audit logging of administrative actions; backups; separation of production and test data.
We will notify you without undue delay after becoming aware of a personal data breach affecting data we process for you, with the information we have available at that time.
We will make available the information reasonably necessary to demonstrate compliance with Article 28 and will allow an audit, on reasonable notice, no more than once a year, at your cost, subject to confidentiality and to not disrupting the service.
These arrangements apply for as long as we process personal data on your behalf, and survive termination for as long as we hold such data.