SFL Tech ("SFL", "we", "our", "us") engages carefully selected third-party service providers ("Sub-Processors") to support the delivery, maintenance, and improvement of our services. [cite: 401] We are committed to transparency, security, and regulatory compliance. This page identifies the categories of Sub-Processors we use and the nature of services they provide in connection with our technology, consulting, and managed services operations. [cite: 402]
This page should be read in conjunction with our: [cite: 403]
Before engaging any Sub-Processor, SFL Tech: [cite: 407]
All Sub-Processors are contractually required to process personal data only for specified business purposes and in compliance with applicable data protection laws. [cite: 413]
Below are the categories of Sub-Processors used by SFL Tech in support of its services. [cite: 415]
Purpose: Secure hosting, storage, compute services, and infrastructure management. [cite: 417, 418]
Data Processed May Include: [cite: 419]
Examples of Services Provided: [cite: 424]
Data may be processed in regional data centers depending on client configuration. [cite: 429]
Purpose: Transactional emails, customer communications, internal collaboration. [cite: 431, 432]
Data Processed May Include: [cite: 433]
These providers support operational notifications, support communications, and marketing communications where applicable. [cite: 438]
Purpose: Website performance monitoring, usage analytics, system diagnostics. [cite: 440, 441]
Data Processed May Include: [cite: 442]
These tools help improve system stability, security, and user experience. [cite: 447]
Purpose: Ticketing, issue tracking, customer service management. [cite: 449, 450]
Data Processed May Include: [cite: 451]
These platforms support SFL's managed services and CARE support operations. [cite: 456]
Purpose: Customer relationship management, communications, marketing engagement. [cite: 458, 459]
Data Processed May Include: [cite: 460]
These systems are used strictly for legitimate business communications and marketing activities in accordance with GDPR and CCPA/CPRA. [cite: 465]
Purpose: Threat detection, endpoint security, vulnerability monitoring. [cite: 467, 468]
Data Processed May Include: [cite: 469]
These providers support cybersecurity posture and incident response capabilities. [cite: 473]
Purpose: Legal, accounting, compliance, and advisory support. Access to personal data (if any) is limited and controlled, and only where necessary for compliance or contractual obligations. [cite: 475, 476, 477]
Where Sub-Processors operate outside the European Economic Area (EEA), United Kingdom, or other jurisdictions with data transfer restrictions: [cite: 479]
SFL Tech may update this list periodically. If you are a customer and wish to: [cite: 484, 485]
Please contact: connectwithus@sfltech.ai [cite: 489]
All Sub-Processors must: [cite: 491]
SFL Tech remains responsible for ensuring that Sub-Processors meet contractual and regulatory obligations. [cite: 496]
For questions regarding our Sub-Processors or data protection practices: [cite: 498]
SFL Tech [cite: 499]
Email: connectwithus@sfltech.ai [cite: 500]

Where CargoWise meets disciplined execution. We deliver integrated, scalable and robust technology solutions to the logistics industry.