Sub-processors
Field 2 Service — list of sub-processors and third-party recipients
| Version | 1.0 |
|---|---|
| Published | 6 September 2026 |
| Links last checked | 6 September 2026 |
| Maintained by | Go Gadgets Ltd, Cupidstown, Kilteel, Co. Kildare, Ireland |
| Questions and objections | hello@field2service.com |
| Data protection contact | [[OWNER: privacy/DPO contact or statement that no DPO is required]] |
This page is referenced by, and forms part of, the Field 2 Service Data Processing Agreement (the "DPA"). Capitalised terms have the meanings given in the DPA.
How to read this page
We operate a general written authorisation for sub-processors under Article 28(2) GDPR. By accepting the DPA you authorise the sub-processors on this page, subject to the change-notice and objection rights in section 6.2 of the DPA and restated below.
The page is split by whose data is involved, because the two populations are separate:
- Section 1 — sub-processors that can reach your customers' data (Customer Personal Data). This is the list that matters for your own Article 28 assessment.
- Section 2 — processors that reach only your account-holder data, where Field 2 Service is the controller. Your customers' records never reach these.
- Section 3 — third parties that receive data but are not our sub-processors: they act as independent controllers, or they receive data because you configured them.
- Section 4 — third-party resources the staff application loads in the browser. No such resource is loaded by the customer portal, the public booking page or our marketing website.
- Section 5 — providers that appear in the product but that receive no personal data at all.
Most entries are conditional. If you leave the relevant feature switched off, no data reaches that sub-processor. The "Engaged when" column says which.
1. Sub-processors with access to Customer Personal Data
| Sub-processor | Service provided | Personal data received | Location | Transfer mechanism | Their DPA / privacy page |
|---|---|---|---|---|---|
| [[OWNER: hosting provider and data-centre location]] | Hosting of the application, the tenant databases and uploaded files | All Customer Personal Data, at rest and in transit | [[OWNER: hosting provider and data-centre location]] | [[OWNER: hosting provider and data-centre location]] — state the transfer mechanism with the provider; if the data centre is inside the EEA, no transfer safeguard is required | [[OWNER: hosting provider and data-centre location]] |
| Anthropic PBC | The in-app AI assistant, AI form-assist, AI scan and digest phrasing, and the customer-portal AI chat | Whatever the assistant needs for the turn: customer names, email addresses, phone numbers and full addresses; job titles, descriptions and notes; quote and invoice figures; engineer names and schedules; and photographs uploaded to the chat. Prompt caching (Anthropic only) briefly retains content provider-side to serve later turns in the same conversation | United States | Anthropic's Data Processing Addendum, read 6 September 2026, incorporates the EU Standard Contractual Clauses (Module Two and/or Module Three, as the relationship requires) and, in its Schedule 3, the UK Addendum. Anthropic's Commercial Terms of Service, section B, state that "Anthropic may not train models on Customer Content from Services". How long Anthropic retains API content beyond prompt caching is not established and is carried as an open item. Engaged only when this is the configured AI provider | DPA: https://www.anthropic.com/legal/data-processing-addendum · Commercial terms: https://www.anthropic.com/legal/commercial-terms · Privacy: https://www.anthropic.com/legal/privacy · Trust portal: https://trust.anthropic.com/ |
| X.AI LLC | The in-app AI assistant, AI form-assist, AI scan and digest phrasing, and the customer-portal AI chat | The same payload as the Anthropic row: customer names, email addresses, phone numbers and full addresses; job titles, descriptions and notes; quote and invoice figures; engineer names and schedules; and photographs uploaded to the chat. Prompt caching is not used with this provider | United States | xAI's Data Processing Addendum, read 6 September 2026, records xAI as a processor and incorporates the EU Standard Contractual Clauses (Module Two or Module Three, as the relationship requires), the UK Addendum, and Swiss FADP modifications. The data importer is named on the DPA as the xAI contracting entity. xAI's Enterprise FAQ, read 6 September 2026, states that "we do not use your business data, including inputs (prompts) or outputs (answers), for training our models" and that "Inputs and outputs are automatically deleted within 30 days, unless (a) otherwise agreed in writing, (b) xAI is legally required to retain them because, for example, they are flagged as potentially violating our Terms of Service or AUP." Engaged only when this is the configured AI provider | DPA: https://x.ai/legal/data-processing-addendum/ · Enterprise FAQ: https://x.ai/legal/faq-enterprise · Privacy: https://x.ai/privacy-policy/ · Europe privacy addendum: https://x.ai/legal/europe-privacy-policy-addendum/ |
| OpenAI OpCo, LLC / OpenAI Ireland Ltd. | The in-app AI assistant, AI form-assist, AI scan and digest phrasing, and the customer-portal AI chat | The same payload as the Anthropic row: customer names, email addresses, phone numbers and full addresses; job titles, descriptions and notes; quote and invoice figures; engineer names and schedules; and photographs uploaded to the chat. Prompt caching is not used with this provider | United States (OpenAI OpCo, LLC, 1455 3rd Street, San Francisco, CA 94158) and Ireland (OpenAI Ireland Ltd., where the customer is in the EEA or Switzerland) | OpenAI's Data Processing Addendum, effective 1 January 2026, read 6 September 2026, incorporates the EU Standard Contractual Clauses (Module Two and/or Module Three) and the UK Addendum. EEA and Swiss data are instructed to OpenAI Ireland Limited, with onward transfers on the Clauses or adequacy. OpenAI's enterprise privacy pages, read 6 September 2026, state that "We do not train our models on your organization's data by default" and that API data is not used to train as of 1 March 2023 unless the customer has opted in. API abuse-monitoring logs are retained for up to 30 days by default. Zero Data Retention is not in place on this account. Engaged only when this is the configured AI provider | DPA: https://openai.com/policies/data-processing-addendum/ · Enterprise privacy: https://openai.com/enterprise-privacy/ · API data: https://platform.openai.com/docs/guides/your-data · Privacy: https://openai.com/policies/privacy-policy |
| Twilio Inc. | Outbound SMS | The recipient's phone number and the full message body, which typically resolves to the customer's name and the job or appointment details | United States | Twilio's Data Protection Addendum, read 5 September 2026, incorporates the EU Standard Contractual Clauses and the ICO's International Data Transfer Agreement, and records that Twilio Inc. self-certifies under the EU-US Data Privacy Framework and its UK Extension. We rely on the Clauses and the Agreement, not on the certification | DPA: https://www.twilio.com/en-us/legal/data-protection-addendum · Privacy: https://www.twilio.com/en-us/legal/privacy · Their sub-processors: https://www.twilio.com/en-us/legal/sub-processors |
| Stripe — Stripe Payments Europe, Limited for accounts outside North and South America; Stripe, LLC / Stripe, Inc. in the United States | Card payments taken against your invoices through a hosted checkout page | The payment amount and currency, the invoice description used as the line-item name, the customer's email address where one is held, and reference metadata | Ireland (Stripe Payments Europe, Limited) and the United States | The Stripe Data Processing Agreement, read 5 September 2026, states that an account located outside North and South America enters the agreement with Stripe Payments Europe, Limited, and its Data Transfers Addendum covers restricted transfers through the EEA Standard Contractual Clauses and the UK International Data Transfer Addendum, as well as the EU-US Data Privacy Framework. We rely on the Clauses and the Addendum | DPA: https://stripe.com/legal/dpa · Privacy: https://stripe.com/privacy · Their service providers: https://stripe.com/legal/service-providers |
1.0 Destination countries
Customer Personal Data may be transferred to, and processed in, the following countries and territories, and no others: Ireland; the United States; and [[OWNER: hosting provider and data-centre location]].
This is a closed list of the destinations we choose, not an illustration. If a country is not named here, we do not send Customer Personal Data there, and none may be added except through the thirty-day change process in section 6. It does not cover transfers you direct — a webhook or API endpoint you configure, your own mail or SMS provider, or a payment provider you enable, whose entity and country are determined by it and by you. Those are the section 3 recipients, they are onward transfers made on your instruction under sections 4.6 and 8.5 of the DPA, and naming their destinations is yours to do where your own law requires it. Several laws require the destinations to be named rather than described — Singapore's transfer regulations require a transfer contract to specify the countries and territories; South Africa requires the onward-transfer restriction to be as strong as the original; Australia and Japan both expect the country to be named where that is practicable; and Canada expects customers to be told their data is processed abroad. The same list appears in section 15 of the Data Processing Agreement and the two must be kept in step.
1.1 Notes on section 1
- Only the configured AI provider is engaged. The three AI rows are alternatives, not a stack: the platform (super-admin) console names which of Anthropic PBC, X.AI LLC or OpenAI OpCo, LLC / OpenAI Ireland Ltd. is live, and Customer Personal Data is sent to that one alone. Switching the AI features off per company, or the platform recording a per-tenant opt-out, means no Customer Personal Data is sent to any AI provider. The customer-portal AI is separately gated, is off by default, and is read-only and scoped to the single signed-in customer. Images uploaded to the assistant are stored outside the web root and deleted after sixty minutes. Prompt caching is used only with Anthropic.
- Twilio is engaged only if you configure SMS. Every attempt is recorded in your own SMS log.
- Stripe is engaged only if you enable Stripe. Card numbers are entered by the payer directly on Stripe's hosted page; we never receive or store them.
- Stripe also acts on its own account. For fraud prevention, financial-crime compliance and its own regulatory obligations, Stripe processes payment data as an independent controller under its own privacy policy, in addition to acting as a processor for us. Read its privacy page.
- Your own mail and SMS providers are not in this section. Where you supply the credentials, you are choosing the recipient and it is not our sub-processor. Those entries are in section 3.
2. Processors of account-holder data only (Field 2 Service as controller)
Your customers' records never reach anything in this section. These providers see only the data of the people who hold or pay for a Field 2 Service account.
| Processor | Service provided | Personal data received | Location | Transfer mechanism | Their DPA / privacy page |
|---|---|---|---|---|---|
| Stripe (Stripe Payments Europe, Limited / Stripe, Inc.) | Our own subscription billing | The account holder's name, email address, billing details and subscription amounts | Ireland and the United States | As section 1 | https://stripe.com/legal/dpa · https://stripe.com/privacy |
| Our outbound mail relay | The account emails we send you: invitations, password resets, billing and suspension notices | Account-holder name and email address, and the content of those notices | [[OWNER: outbound mail relay provider, entity and country]] | [[OWNER: outbound mail relay provider, entity and country]] — state the transfer mechanism with the provider | [[OWNER: outbound mail relay provider, entity and country]] |
Destination countries for this section: Ireland and the United States, plus the country of the outbound mail relay once it is named. This section concerns account-holder data only, for which Field 2 Service is the controller; your customers' records never reach it.
3. Third parties that receive data but are not our sub-processors
| Recipient | What they receive, and why | Their role | Location | Transfer mechanism | Their terms / privacy page |
|---|---|---|---|---|---|
| PayPal | Where you enable PayPal, we create an order carrying the amount, the currency, the invoice description and our reference identifiers. No customer email address is sent in the order payload. | Independent controller. PayPal's Privacy Statement, read 5 September 2026, states that the controller of a payer's personal information is the PayPal entity established in the jurisdiction where that person resides. PayPal is not processing on our instructions | The PayPal entity for your jurisdiction | Governed by PayPal's own terms with the payer and with you as merchant, not by our DPA | Privacy: https://www.paypal.com/ie/legalhub/paypal/privacy-full · Their third parties: https://www.paypal.com/ie/legalhub/paypal/third-parties-list |
| Google Maps Platform — Google Ireland Limited / Google LLC | Address and postcode strings for geocoding and address validation, and job origin and destination addresses for travel-time and distance calculations. Engaged only where a Maps key is configured | Independent controller. Google Maps Platform is supplied under Google's Controller-Controller Data Protection Terms, read 5 September 2026, under which the parties are independent controllers — Google does not act as our processor for Maps Platform data | Ireland and the United States | Google's Controller-Controller terms provide for a "Data Transfer Solution" — the EU-US Data Privacy Framework and its UK Extension where applicable, with Controller Standard Contractual Clauses as the fallback | Controller terms: https://business.safety.google/controllerterms/ · Maps Platform terms: https://cloud.google.com/maps-platform/terms · Privacy: https://policies.google.com/privacy · Google Cloud DPA: https://cloud.google.com/terms/data-processing-addendum |
| Your own SMTP email provider | Delivery of the email you send through the Services — quotes, invoices, reminders, portal notifications. Recipient address, subject, message body and attached PDFs | A recipient you choose. You appoint this provider, using credentials you enter in Settings. We do not select it and we cannot vet it; we hold your credentials encrypted at rest and use them only to send your mail | Determined by the provider you choose | Your contract and transfer safeguard with them govern | The provider's own terms |
| Your own SMS account, where the SMS credentials you enter in Settings are your own account with the provider | The recipient's phone number and the full message body | A recipient you choose. The account is yours and the contract with the provider is yours | Determined by that account | Your contract and transfer safeguard with them govern | The provider's own terms |
| Any webhook or API endpoint you configure (for example Zapier) | The full record for the triggering event, including the complete customer record on customer events, delivered to whatever HTTPS URL you save | A recipient you choose. This is a controller-directed onward transfer. We do not select, vet or contract with the endpoint | Determined by you | Your responsibility as controller, including any transfer safeguard | The endpoint operator's own terms |
Destination countries for this section: Google Maps Platform — Ireland and the United States. For every other row the destination is determined by you or by the recipient, not by us, so we cannot and do not name it: you choose the mail provider, the SMS account and the webhook endpoint, and PayPal's Privacy Statement makes the PayPal entity established in the payer's own jurisdiction the controller of that payer's information. Those destinations fall outside the closed list in section 1.0 because the data does not reach them as a transfer by us under the DPA — if your own law requires you to name them, they are yours to name. ⚠ We have not independently verified PayPal's list of group entities or their countries.
4. Third-party resources loaded by the staff application in the browser
These are not sub-processors — no record from your database is sent to them — but the staff user's IP address and browser details reach the provider when the page loads. They are disclosed here so that the picture is complete.
The customer portal, the public booking page and our marketing website load none of these. Verified: no external URL appears in the portal layout, the booking widget or any marketing-site page.
| Resource | Where it loads | What the provider sees | Location | Their privacy page |
|---|---|---|---|---|
Google Fonts (fonts.googleapis.com, fonts.gstatic.com) | The staff application layout and the calendar page, for the brand wordmark typeface | Staff user's IP address and user agent | Ireland and the United States | https://fonts.google.com/faq#privacy · https://policies.google.com/privacy |
Google Maps JavaScript and Places (maps.googleapis.com) | Address autocomplete in the staff application, only when a Maps key is configured | Staff user's IP address and user agent, and the partial address being typed | Ireland and the United States | https://policies.google.com/privacy |
Google Maps embed (www.google.com/maps/embed) | The job-location map on a job page | Staff user's IP address and user agent, and the location shown | Ireland and the United States | https://policies.google.com/privacy |
Destination countries for this section: Ireland and the United States. These three resources are the only third parties the staff application contacts from the browser.
5. Providers that receive no personal data
The product can store credentials for these payment providers and will make a credential-verification call to confirm the credentials work. Those calls carry the credential only — no customer data — and no live checkout rail exists for any of them.
| Provider | Why it appears | Personal data received |
|---|---|---|
| Square | Credential verification only | None |
| Worldpay | Credential verification only | None |
| Checkout.com | Credential verification only | None |
| GoCardless | Credential verification only | None |
They are therefore not sub-processors and are not authorised as such. If any of them is ever wired to a live payment rail, it will be added to section 1 under the thirty-day notice in section 6 below.
6. Changes to this list, and your right to object
6.1 Notice
Before we add or replace a sub-processor that will have access to Customer Personal Data, we give you at least thirty (30) days' notice, by:
- updating this page, with a new version number and date and an entry in the change log below; and
- emailing the account contact we hold for you.
Where a change must be made urgently to protect the security or continuity of the Services, we may make it sooner and will notify you as quickly as possible; your objection right then runs from that notice.
6.2 Objecting
You may object on reasonable data-protection grounds by emailing hello@field2service.com within the thirty-day notice period, saying which sub-processor and why. We will respond within ten business days, and we will do one of the following:
- not appoint the sub-processor for your data;
- make a reasonable change to the Services or your configuration so that the sub-processor does not process your data — for example, leaving the dependent feature switched off for your account; or
- if neither is reasonably possible, tell you so, in which case you may terminate the affected part of the Services — or, if the sub-processor is essential to the Services as a whole, the subscription — without penalty, with a pro-rata refund of the fees you have paid for the unused period.
6.3 Staying informed
Email hello@field2service.com with "Sub-processor notices" in the subject line and we will add your address to the sub-processor notification list, in addition to your account contact. That list is held with the record described in section 6.4.
6.4 Our commitments on every sub-processor
Each sub-processor in section 1 or 2 that we appoint is engaged under a written contract imposing data protection obligations no less protective than those in our DPA, and we remain fully liable to you for its performance. The recipients in section 3 are not covered by that commitment, because you choose them and we do not contract with them.
For each sub-processor we record its legal entity, the service it provides, the categories of data it receives, its country, its own data protection terms, the transfer instrument relied on and the date we last checked it. Sections 1 to 3 of this page are that record, and the verification log in section 7 records when each provider's own document was last read — both are published rather than kept privately, so you can check the same facts we do. Section 8 is the change log for this page. Sections 7 and 8 are part of the published page, not internal notes, and they include entries recording recipients that have been removed; a removed recipient is stated in the past tense and receives nothing.
7. Verification log
Every non-AI URL on this page was fetched on 5 September 2026 and resolved successfully. The three AI providers' own published documents were read on 6 September 2026. The transfer-mechanism statements above record what each provider's own published document said on the date in its row.
| Checked | What was verified |
|---|---|
| 5 Sep 2026, re-checked 6 Sep 2026 | Anthropic DPA resolves; its "Standard Contractual Clauses" section incorporates SCC Module Two and/or Module Three by reference, and its Schedule 3 incorporates the UK Addendum |
| 5 Sep 2026, re-checked 6 Sep 2026 | Anthropic Commercial Terms, section B, state: "Anthropic may not train models on Customer Content from Services" |
| 6 Sep 2026 | xAI Data Processing Addendum resolves; xAI is a processor; EU SCCs Module Two or Module Three, the UK Addendum, and Swiss FADP modifications are incorporated. The data importer is named on the DPA as the xAI contracting entity. Legal entity X.AI LLC is named in xAI's Europe Privacy Policy Addendum |
| 6 Sep 2026 | xAI Enterprise FAQ (search snippet; the page accordion is JS-collapsed): "we do not use your business data, including inputs (prompts) or outputs (answers), for training our models." "Inputs and outputs are automatically deleted within 30 days, unless (a) otherwise agreed in writing, (b) xAI is legally required to retain them because, for example, they are flagged as potentially violating our Terms of Service or AUP." |
| 6 Sep 2026 | OpenAI Data Processing Addendum (effective 1 January 2026) resolves; contracting parties are OpenAI OpCo, LLC and, where the customer is in the EEA or Switzerland, OpenAI Ireland Ltd.; SCCs Module Two and/or Three and the UK Addendum; EEA/Swiss data instructed to OpenAI Ireland Limited with onward transfers on the Clauses or adequacy |
| 6 Sep 2026 | OpenAI enterprise privacy / API data pages: "We do not train our models on your organization's data by default"; API data not used to train as of 1 March 2023 unless opted in; API abuse-monitoring logs retained up to 30 days by default. Zero Data Retention is not claimed |
| 5 Sep 2026 | Twilio Data Protection Addendum resolves; the EU Standard Contractual Clauses and the ICO's International Data Transfer Agreement are deemed entered into and incorporated by reference, and Twilio Inc. states that it self-certifies under the EU-US Data Privacy Framework and its UK Extension |
| 5 Sep 2026 | Stripe DPA resolves; an account located outside North and South America enters the DPA with Stripe Payments Europe, Limited, and the Data Transfers Addendum covers restricted transfers through the EEA Standard Contractual Clauses and the UK International Data Transfer Addendum |
| 5 Sep 2026 | PayPal Privacy Statement resolves and identifies PayPal as the data controller of a payer's personal information |
| 5 Sep 2026 | Google's Controller-Controller Data Protection Terms resolve; clause 4.1 states that each party "is an independent controller of Controller Personal Data", and clause 4.2 provides a Data Transfer Solution with the Controller Standard Contractual Clauses as the fallback |
| 5 Sep 2026 | Google Fonts page resolves |
| 5 Sep 2026 | ipapi.co (Kloudend, Inc., United States) and Open-Meteo (OpenMeteo GmbH, Switzerland) removed 5 September 2026. They were reached only by a decorative topbar weather display in the staff application. That display was deleted from the application, and the two hosts were removed from its content-security policy, so neither company receives anything from any Field 2 Service surface. Recorded here as a change of fact, not as a current recipient |
What we have deliberately not claimed. We do not state that any provider holds a current EU-US Data Privacy Framework certification. Certifications are renewed annually and can lapse, and we have not verified any provider against the official list at https://www.dataprivacyframework.gov/list. Where the Framework is mentioned above, it is because the provider's own document mentions it — we rely on the Standard Contractual Clauses and the UK Addendum, which do not lapse.
8. Change log
| Version | Date | Change |
|---|---|---|
| 1.0 | 6 September 2026 | Section 1 AI row expanded from a single Anthropic entry to three selectable providers (Anthropic PBC, X.AI LLC, OpenAI OpCo, LLC / OpenAI Ireland Ltd.). Only the configured provider is engaged; the platform console names which. Per-company off switch and landlord per-tenant opt-out both mean no Customer Personal Data is sent to any AI provider |
| 1.0 | 5 September 2026 | First published list. Two browser-side recipients — ipapi.co (United States) and Open-Meteo (Switzerland) — were removed on 5 September 2026 together with the staff-application feature that reached them, before this list was first published. |