Version 1.0 | Effective July 17, 2026 | Controlling language: English
This Notice supplements the AFICH Privacy Policy and Organizer Data Protection Addendum. It describes AFICH's subprocessor posture and international-transfer framework for platform services.
AFICH may use vetted service providers and subprocessors to operate the platform, including cloud hosting, database, storage, email, SMS, push notification, payment, payout, identity verification, fraud prevention, analytics, error monitoring, support, security, and AI-service providers.
AFICH requires subprocessors that handle personal data to provide contractual confidentiality, privacy, and security commitments appropriate to the service they provide.
Payment processing, connected-account onboarding, KYC, AML, sanctions screening, and money movement are handled by Stripe Connect or another configured payment provider. Those providers may act as independent controllers for some payment and compliance data under their own terms and notices.
Where AFICH acts as a processor or service provider under the DPA, AFICH will provide reasonable notice of material subprocessor changes when required by the DPA or applicable law. An organizer may object on reasonable data-protection grounds. If the objection cannot be resolved, AFICH may restrict or end the affected service as permitted by the governing agreement.
AFICH and its providers may process data in the United States and other countries. Where GDPR, UK GDPR, Swiss, or similar transfer rules require safeguards, AFICH uses appropriate mechanisms such as adequacy decisions, EU Standard Contractual Clauses, the UK Addendum or IDTA, Swiss addenda, data-processing terms, or other lawful transfer mechanisms available for the provider and region.
Completed SCC annexes, technical and organizational measures, and transfer-impact details may be provided through AFICH's legal or security review process where reasonably required for an organizer's compliance review.
AFICH may provide reasonable security and subprocessor information under NDA or equivalent confidentiality controls for enterprise, organizer, or regulator review, subject to security, customer confidentiality, and provider restrictions.
The English-language version is the official and controlling text. Localized versions are provided for convenience only.