Sub-Processors and Service Providers
Effective August 1, 2026
D.I.T.C. LLC operating as DITC.io · www.ditc.io · Version 1.0
This page publishes the current list of third-party service providers engaged by D.I.T.C. LLC and SENDORA INC. in connection with the Platform. It is referenced from section 9.4 of the General Terms and Conditions and section 5 of the Privacy Policy.
Each provider is bound by a written data-processing agreement compliant with Article 28 GDPR / UK GDPR, or, where the provider acts as an independent controller, by the applicable contractual and regulatory framework. This list is not exhaustive and may be supplemented or amended as regulatory requirements or operational needs change. Material changes are notified in accordance with Section XI of the GTC.
1. Mandatory Compliance Providers
Engagement of these providers is mandated by applicable AML, KYC, and financial-crime regulation. Their use is a necessary condition of using the services.
| Provider | Location | Purpose | Legal basis |
|---|---|---|---|
| Sumsub (sumsub.com) | Global | Identity verification (KYC), liveness checks, document authentication, biometric data processing, ongoing customer due diligence | Legal obligation (AML/KYC) |
| Chainalysis (chainalysis.com) | Global | Blockchain analytics, cryptocurrency transaction monitoring, wallet risk scoring, screening of crypto wallet addresses for sanctions, fraud, and financial-crime indicators | Legal obligation (AML/sanctions) |
2. Infrastructure and Security
| Provider | Location | Purpose | Transfer mechanism |
|---|---|---|---|
| Cloudflare | Global | Security, performance, bot management, DDoS protection | Standard Contractual Clauses / DPF where certified |
| Cloud and hosting providers | Global | IT infrastructure, hosting, backup | Standard Contractual Clauses / adequacy where applicable |
3. Analytics and Marketing (consent-gated)
These providers are engaged only where you have given consent through the cookie banner. See the Cookie Policy.
| Provider | Location | Purpose | Transfer mechanism |
|---|---|---|---|
| Google LLC | Global | Website analytics and tag management | Standard Contractual Clauses / EU–US Data Privacy Framework where certified |
| Meta Platforms | Global | Marketing attribution | Standard Contractual Clauses / EU–US Data Privacy Framework where certified |
| Global | B2B marketing analytics | Standard Contractual Clauses / EU–US Data Privacy Framework where certified |
4. Settlement Entity and Upstream Payment Chain
The following parties are not sub-processors of DITC. They participate in the payment chain in their own right and, where they process personal data, do so as independent or joint controllers.
| Party | Location | Role |
|---|---|---|
| SENDORA INC. (FINTRAC MSB Registration No. C100000575) | Canada (Alberta) | Settlement Entity. Joint controller for onboarding, KYC/AML, transaction monitoring, fraud prevention and sanctions screening; separate controller for fund-holding, settlement, payout, rolling reserve and FINTRAC regulatory-reporting data. See Joint-Controller Arrangement. |
| Acquirers, sponsoring and correspondent banks, card schemes, processors, liquidity providers | Various | Card acquiring, scheme processing, clearing, correspondent banking, and liquidity, provided upstream of the Settlement Entity. Independent third parties. |
5. Questions
For questions about this list, the applicable data-processing agreements, or the transfer mechanisms relied on, contact privacy@ditc.io. A Transfer Impact Assessment summary is available on request.