CODEFY SUBPROCESSORS & TECHNOLOGY PROVIDERS
Version: 1.0
Effective Date: 1st August 2025
Last Updated: 1st August 2026
This page identifies material third party technology providers that Codefy Hub For IT Solutions, trading as Codefy Hub, may use in providing Codefy Hub and Codefy ERP services.
Some providers listed below act as Subprocessors, meaning they may process Customer Personal Data on Codefy's behalf.
Other providers may act as independent technology providers, controllers, payment processors, customer selected integrations or providers whose role depends on the particular Service being used.
Not every provider is used for every Customer.
1. Relationship to the Codefy DPA
Where Codefy processes Customer Personal Data on behalf of a Customer, Codefy's use of Subprocessors is governed by the Codefy Data Processing Addendum.
The Customer generally authorizes Codefy to appoint Subprocessors necessary to provide the Services, subject to the DPA, applicable law and applicable notification or objection rights.
This list should be read together with:
Codefy Hub Privacy Policy
Codefy Mobile Application Privacy Notice
Codefy Data Processing Addendum
Codefy ERP Service Terms
2. Current Core Subprocessors
| Provider | Service | Purpose | Information potentially processed | Products | Processing location |
|---|---|---|---|---|---|
| Supabase | Hosted database, authentication, storage, realtime and backend infrastructure | Store and process Customer Data, authenticate users, provide database and application services | Account data, Customer Data, ERP records, transportation records, documents, application data and other information stored by Customer | Codefy ERP and related services | Depends on the Codefy project region and infrastructure configuration |
| Vercel | Web application, API and deployment infrastructure | Host the main Codefy web application, API routes, server side application logic and related deployment infrastructure | Account data, Customer Data and technical request information processed through the hosted web application and APIs | Codefy Hub, Codefy ERP and related web services | Depends on the configured Vercel deployment regions and infrastructure |
| Fly.io | Fleet tracking gateway hosting where enabled | Host the separate WebSocket gateway used for live transportation tracking | Gateway session data, authorized active trip context, limited tracking updates, technical connection metadata and related operational data | Codefy ERP Transportation and live tracking | Depends on the configured gateway deployment region and infrastructure |
| Damoov Pte. Ltd. | Telematics and tracking | Driver and vehicle tracking, trip detection, telematics, fleet visibility and related functionality | Pseudonymous device identifiers, GPS coordinates, timestamps, speed, heading, accuracy, motion and related telematics information | Codefy ERP Transportation and Driver App | Damoov states that processing may occur in Singapore, Germany and the United States |
Supabase is used extensively throughout Codefy's backend architecture, including service role access to Customer ERP data, while the application's dependency inventory includes Supabase authentication and database SDKs. Supabase currently describes its hosted platform as including Postgres databases, authentication, storage, realtime infrastructure and configurable project regions.
The applicable Supabase processing location depends on the production project region and infrastructure configuration used for the relevant Codefy Service.
Vercel
The current Codefy web application is built as a Next.js application and may be deployed through Vercel or a similar hosting provider.
Where Vercel is used, it may process requests, responses, logs, deployment artifacts, environment configuration and server side application processing necessary to operate the Service.
Vercel region and infrastructure details depend on Codefy's production deployment configuration and Vercel's applicable platform architecture.
Fly.io
The current Codefy transportation architecture includes a separate fleet tracking gateway intended to run outside the main Vercel deployment.
The gateway validates short-lived session tokens, communicates with the main Codefy application through an internal secret, connects server side to the telematics provider and sends limited tracking information to authorized browser clients.
The gateway processing location depends on the production deployment configuration used for the relevant Service.
Damoov
Damoov is currently integrated directly into Codefy's transportation architecture.
Codefy creates and maintains tenant specific Damoov integrations and stores Damoov instance and device identifiers necessary to provide tracking.
Codefy's tracking gateway can receive and normalize:
GPS coordinates;
speed;
heading;
accuracy;
timestamps;
and provider device identifiers,
and associate that telematics information with authorized Codefy trip and vehicle information.
Damoov's current privacy policy states that it processes institutional telematics information primarily using pseudonymous DeviceTokens and acts as processor for institutional clients. It states that data may be processed in Singapore, Germany or the United States.
Codefy's current use of Damoov is governed by Damoov's applicable service agreement and privacy documentation. Damoov retention may depend on service configuration and applicable contractual arrangements, so Codefy will describe retention according to its actual configured arrangement rather than treating a public default as universal for every Customer.
3. AI Technology Providers
Codefy ERP may provide AI enabled functionality.
AI providers are feature specific providers. They are used only when the relevant AI functionality is enabled and invoked. The provider used may depend on the applicable Codefy configuration, selected AI feature and model availability.
| Provider | Purpose | Possible information | When used | Status |
|---|---|---|---|---|
| OpenAI | AI inference, analysis, generation and automation | User prompts and information intentionally supplied to an enabled AI feature | Only when applicable Codefy AI functionality invokes OpenAI services | Feature specific Subprocessor |
| OpenRouter | AI model routing or model access | Information submitted to an AI function routed through the applicable service | Only where the applicable Codefy AI configuration uses OpenRouter | Feature specific provider |
Codefy seeks to transmit only information reasonably necessary to perform the requested AI functionality. Customers should not provide unnecessary sensitive Personal Data to general purpose AI features.
OpenAI and OpenRouter do not receive all ERP data merely because they are listed here. They receive only information transmitted by the applicable AI workflow.
4. Mapping and Location Technology
Codefy currently contains both Google Maps related and MapLibre technology dependencies.
Google Maps Platform
Where Google Maps functionality is used, Google may receive information necessary to provide map functionality, potentially including IP addresses, search queries and latitude or longitude coordinates depending on the specific API used.
Use of Google Maps Platform may require appropriate privacy notice and consent where end user location is processed.
| Provider | Purpose | Possible information | Role |
|---|---|---|---|
| Maps, geocoding, navigation or location based functionality | Search requests, IP address, coordinates and technical request information depending on the API | Technology provider, role depends on the applicable Google Maps service |
MapLibre
MapLibre is open source mapping technology that may be included in the application.
Using an open source library locally does not inherently mean Customer Personal Data is transmitted to an external MapLibre organization.
If Codefy uses a separate map tile, geocoding or location service through MapLibre, that provider should be listed where it materially processes Customer Personal Data.
5. Payment Processing
Where Codefy uses Paymob for payment processing, Paymob may process information necessary to complete the payment transaction.
| Provider | Purpose | Possible information | Role |
|---|---|---|---|
| Paymob | Payment processing, subscription billing or transaction services where enabled | Customer identity, billing details, transaction amount, transaction reference and payment information required by Paymob | Payment provider, role depends on applicable payment arrangement |
Where complete payment card credentials are collected directly by Paymob or another payment provider, Codefy will not intentionally store full payment card credentials in Codefy ERP. Codefy may receive transaction references, status information, invoice details or limited payment metadata necessary for billing and reconciliation.
6. Authentication Providers
Codefy may use Supabase Auth for application authentication.
Supabase currently provides authentication and user management as part of its hosted platform.
Where Customers enable optional external identity providers such as Google, Microsoft or another OAuth provider, those providers may separately receive authentication related information.
Customer selected identity providers are treated as Customer selected integrations unless Codefy itself appoints the provider as a Subprocessor for the relevant Service.
7. Communications Providers
Codefy may use communications providers to deliver operational messages, notifications, one time passwords, alerts, support communications or other Service related communications.
| Provider | Purpose | Possible information | Role |
|---|---|---|---|
| SMS Misr | SMS delivery, one time passwords, operational alerts or Service related text messages where enabled | Recipient phone number, message content or template, delivery status, timestamps and related technical metadata | Communications provider / Subprocessor where it processes Customer Personal Data on Codefy's behalf |
If Codefy uses a separate production email, WhatsApp or other communications provider that materially processes Customer Personal Data on Codefy's behalf, Codefy will add that provider to this list according to the DPA.
8. Mobile Push Notifications
Codefy mobile applications may rely on operating system push infrastructure.
This can include services operated by Apple or Google depending on the device platform.
The mobile application may transmit a push notification token and information necessary to deliver an operational notification.
| Provider | Purpose | Possible information | Role |
|---|---|---|---|
| Apple Push Notification Service | Delivery of iOS push notifications where used | Device push token, notification content or metadata necessary for delivery | Mobile notification infrastructure |
| Firebase Cloud Messaging or applicable Android notification infrastructure | Delivery of Android push notifications where used | Device push token, notification content or metadata necessary for delivery | Mobile notification infrastructure / Subprocessor where it processes Customer Personal Data on Codefy's behalf |
9. Hosting and Deployment Provider
Codefy's current architecture uses hosted infrastructure rather than self-managed physical servers.
The main web application and APIs may be hosted through Vercel, while the fleet tracking gateway may be hosted through Fly.io where live tracking is enabled.
If Codefy changes a material hosting provider, Codefy will update this list or another appropriate Customer facing provider inventory according to the DPA.
10. Customer Selected Integrations
Customers may enable integrations that are not standard Codefy Subprocessors.
These can include:
external identity providers;
Customer accounting systems;
Customer APIs;
map services;
communications providers;
external storage;
third party AI systems;
or other Customer selected applications.
Where the Customer independently selects and instructs Codefy to connect to such a service, that provider may act independently from Codefy.
Such providers are not necessarily included in Codefy's standard Subprocessor List.
The Customer is responsible for evaluating independently selected integrations according to the Codefy DPA.
11. Technology That Is Not a Subprocessor
The presence of software in Codefy's source code does not automatically mean the developer of that software processes Customer Personal Data.
Examples include open source libraries, frontend components, database drivers and locally executed frameworks.
Accordingly, Codefy does not list every software package used in developing Codefy ERP.
A provider is listed here where the provider materially receives or processes information in connection with delivering the Services, or where transparency regarding the provider is otherwise appropriate.
12. Current Provider Classification
Confirmed Core Subprocessors
Supabase
Database, authentication, storage and backend infrastructure.
Vercel
Web application, API and deployment infrastructure where used.
Fly.io
Fleet tracking gateway hosting where used.
Damoov Pte. Ltd.
Telematics and transportation tracking.
Feature Specific Providers
OpenAI
AI functionality where enabled and used.
OpenRouter
AI model routing where enabled and used.
Google Maps Platform
Maps and location functionality where the applicable Google service is used.
Paymob
Payment processing where Codefy billing or payment functionality uses Paymob.
Communications Providers
SMS Misr
SMS delivery, one time passwords and operational text messages where enabled.
Firebase Cloud Messaging
Android push notifications where used.
Apple Push Notification Service
iOS push notifications where used.
Additional Providers Added When Enabled
Email delivery, WhatsApp messaging, customer selected integrations or other feature specific providers may be added to this list where they materially process Customer Personal Data on Codefy's behalf.
13. Changes to Subprocessors
Codefy may add, replace or remove Subprocessors as the Services evolve.
Where required by the Codefy Data Processing Addendum or applicable law, Codefy will provide reasonable notice of material new Subprocessors processing Customer Personal Data.
Where the Customer has an applicable contractual right to object, objections must be based on reasonable data protection grounds and handled according to the DPA.
14. Provider Replacement
Codefy may replace a technology provider because of:
security;
reliability;
availability;
functionality;
cost;
regulatory requirements;
geographic requirements;
provider discontinuation;
or product development.
Replacement of a provider does not permit Codefy to materially disregard the privacy and security obligations established by the DPA.
15. Processing Locations
Processing locations may vary depending on:
the Codefy Service;
Customer configuration;
Codefy infrastructure region;
and the provider used.
Codefy will maintain provider and processing location information through this page or another appropriate Customer facing provider inventory rather than permanently embedding every provider location into the master Terms.
For Damoov, its current Privacy Policy states that data may be processed in Singapore, Germany or the United States.
For AI providers, processing locations may vary across the provider's infrastructure and subprocessors.
For Supabase, the relevant location depends on the actual region selected for Codefy's production project for the relevant Service.
For Vercel, the relevant location depends on the configured deployment regions and Vercel's applicable infrastructure.
For Fly.io fleet tracking gateway hosting, the relevant location depends on the configured gateway deployment region and infrastructure.
16. International Transfers
Where a Subprocessor processes Egyptian Personal Data outside Egypt, Codefy will address applicable international transfer requirements under Egyptian data protection law and the Codefy DPA.
A provider appearing on this page does not itself mean that every Customer's Personal Data is transferred to every processing location associated with that provider.
17. Data Minimization
Codefy seeks to provide each Subprocessor only the information reasonably necessary to provide the applicable function.
In particular:
Damoov: Codefy seeks to use pseudonymous Driver, device, vehicle or trip identifiers rather than unnecessary Rider or student identity.
AI providers: Codefy seeks to send only data needed for the AI request.
Map providers: Codefy seeks to avoid including unrelated identity information in map requests.
Payment providers: Codefy seeks to avoid storing complete payment credentials where payment can be handled directly by the payment processor.
18. Children's Information
Codefy does not intend to provide children's identifying information to third party telematics providers unless necessary for the Service and lawfully authorized.
For student transportation, the intended architecture is to associate students with transportation trips inside Codefy while tracking the relevant Driver device, vehicle or trip through the telematics provider.
Damoov's current privacy policy states that its telematics processing uses pseudonymous identifiers and that identity information is separated from its telematics analytics pipeline.
19. Provider Legal Documents
Rather than copying third party legal terms into Codefy's documents, Codefy may refer Customers to the applicable provider legal materials, including where relevant:
Damoov
Privacy Policy
Service Agreement
Data protection documentation
Supabase
Privacy and legal documentation
Security and compliance documentation
Vercel
Privacy, security and data processing documentation
Fly.io
Privacy, security and data processing documentation
OpenAI
Services Agreement
Data Processing Addendum
Subprocessor List
Google Maps Platform
Maps Platform Terms
Google Privacy Policy
Paymob
Privacy Policy
Applicable payment service agreement
SMS Misr
Applicable SMS service agreement and privacy documentation
Provider terms may change independently of Codefy, so Customers should review the provider's current legal materials where those materials are relevant to their assessment.
20. Contact and Subprocessor Questions
Questions regarding Codefy's Subprocessors and technology providers may be directed to:
Codefy Hub For IT Solutions
Trading as Codefy Hub
16 Omar Ibn Al Khattab, Sheraton, Cairo, Egypt
Registration# 773819371
Legal: legal@codefyhub.com
Privacy: privacy@codefyhub.com
Enterprise Customers may also contact Codefy to request information reasonably necessary for their vendor or privacy assessment.
