Spatial Guide Private Limited ("Spatial Guide", "we", "our", or "us") may engage carefully selected third-party service providers ("Subprocessors") to support the delivery, operation, maintenance, security, and continuous improvement of our products and services. These providers perform specialized functions that enable us to deliver reliable, scalable, and secure cloud-based Services to our Customers.
We recognize that our Customers place significant trust in us when they entrust us with their information. Accordingly, Spatial Guide carefully evaluates Subprocessors before engaging them and requires them to maintain appropriate technical, organizational, contractual, and operational safeguards that are consistent with the nature of the services they provide.
This Subprocessor Policy explains the circumstances under which Spatial Guide may engage Subprocessors, the governance processes we apply when selecting and monitoring those providers, and the commitments we make regarding the protection of Customer Data processed on our behalf.
This Policy should be read together with our Privacy Policy, Data Processing Addendum, Security Policy, Terms of Service, and any applicable commercial agreements.
What is a Subprocessor?
A Subprocessor is a third-party organization engaged by Spatial Guide to process Customer Data on behalf of Spatial Guide for the purpose of delivering or supporting our Services.
Subprocessors generally perform specialized operational functions such as cloud infrastructure hosting, identity and access management, content delivery, customer communications, payment processing, monitoring, logging, analytics, artificial intelligence services, customer support, backup, disaster recovery, software development, security monitoring, or other technology services necessary for the operation of our platform.
Not every third-party vendor engaged by Spatial Guide is a Subprocessor. Vendors that do not process Customer Data on behalf of Spatial Guide, such as office suppliers or general business service providers, are not considered Subprocessors for the purposes of this Policy.
Why We Use Subprocessors
Modern cloud platforms rely upon specialized technology providers that deliver services at a scale and level of operational maturity that would not be practical to develop independently.
Spatial Guide engages Subprocessors only where doing so enables us to provide secure, reliable, resilient, and high-performing Services to our Customers. These providers may support functions including cloud computing infrastructure, secure authentication, content delivery, payment processing, communications, artificial intelligence capabilities, monitoring, logging, backup services, software development, security tooling, or other operational capabilities that improve the quality, availability, and security of our Services.
The use of Subprocessors allows Spatial Guide to focus on developing innovative products while leveraging trusted providers for specialized infrastructure and operational services.
Selection and Due Diligence
Before engaging a Subprocessor that may process Customer Data, Spatial Guide conducts a risk-based evaluation appropriate to the nature of the services being provided.
Our evaluation may include consideration of the provider's information security practices, privacy program, regulatory compliance posture, operational maturity, business continuity capabilities, incident response processes, contractual commitments, financial stability, reputation, certifications, and ability to support the security and availability requirements of our Services.
Where appropriate, Spatial Guide also evaluates publicly available audit reports, security documentation, compliance certifications, penetration testing practices, and privacy commitments before entering into a commercial relationship.
The scope of due diligence varies depending upon the sensitivity of the information processed, the operational role of the provider, and the level of access required to perform the contracted services.
Contractual Safeguards
Spatial Guide requires Subprocessors that process Customer Data on our behalf to enter into written agreements that include appropriate obligations relating to confidentiality, privacy, information security, lawful processing, incident notification, and the protection of Customer Data.
Where applicable, contractual agreements require Subprocessors to implement appropriate technical and organizational measures designed to safeguard the confidentiality, integrity, and availability of Customer Data throughout the duration of the engagement.
Where Customer Data is transferred across national borders, Spatial Guide seeks to ensure that appropriate legal transfer mechanisms are implemented in accordance with applicable privacy and data protection laws.
Monitoring and Ongoing Oversight
Our responsibility for protecting Customer Data continues throughout the lifecycle of each Subprocessor relationship.
Spatial Guide periodically reviews Subprocessors to determine whether they continue to satisfy our operational, security, and privacy expectations.
Depending upon the services being provided, these reviews may include monitoring changes to compliance certifications, reviewing security advisories, evaluating operational performance, assessing privacy practices, considering audit information where available, and reviewing significant security incidents that may affect the provider.
Where a Subprocessor no longer satisfies our operational or security requirements, Spatial Guide may require corrective actions, implement additional contractual safeguards, restrict the provider's access to Customer Data, or transition services to an alternative provider where reasonably appropriate.
Categories of Subprocessors
Spatial Guide may engage Subprocessors across several operational categories depending upon the products and services used by our Customers.
These categories may include cloud infrastructure providers, content delivery networks, authentication and identity management providers, database hosting providers, artificial intelligence service providers, payment processors, customer communication platforms, email delivery providers, analytics platforms, monitoring and observability services, logging providers, backup and disaster recovery services, customer support platforms, software development and collaboration tools, security monitoring providers, telecommunications providers, and other specialized technology partners.
The specific Subprocessors engaged may vary over time as our products evolve, customer requirements change, or improved technologies become available.
Current Subprocessors
Spatial Guide maintains a separate Subprocessor Register identifying the primary third-party providers that may process Customer Data on our behalf. This register may include the provider's name, the services provided, the purpose of processing, the geographic location in which processing primarily occurs, and other information reasonably necessary to support customer transparency.
Because our infrastructure and operational requirements continue to evolve, the contents of the Subprocessor Register may change periodically. Customers should refer to the most recent version of the register available through our Trust Center or upon reasonable request.
Customer Notifications
Where required by applicable law, our Data Processing Addendum, or a separately negotiated commercial agreement, Spatial Guide will provide reasonable notice before engaging a new Subprocessor that is expected to process Customer Data on behalf of our Customers.
Where Customers possess contractual rights to object to the appointment of a new Subprocessor, such objections should be submitted promptly together with a reasonable explanation describing the legitimate privacy, security, or regulatory concerns associated with the proposed appointment.
Spatial Guide will consider such concerns in good faith and may, where commercially reasonable, propose alternative solutions, implement additional safeguards, or discuss other mutually acceptable arrangements.
International Data Processing
Some Subprocessors may process Customer Data in jurisdictions different from those in which the Customer or Spatial Guide is established.
Where international transfers occur, Spatial Guide seeks to implement appropriate legal, contractual, technical, and organizational safeguards consistent with applicable privacy laws, including contractual transfer mechanisms where required.
Customers remain responsible for evaluating their own regulatory obligations relating to international data transfers within their respective jurisdictions.
Changes to this Policy
Spatial Guide may update this Subprocessor Policy periodically to reflect changes in our products, technology stack, legal obligations, operational practices, or Subprocessor relationships.
Material updates will be published through our website or otherwise communicated to Customers where required by applicable agreements or law. Continued use of the Services following publication of an updated Policy constitutes acceptance of the revised version unless otherwise required by applicable law.
Contact Us
Questions regarding this Subprocessor Policy or requests relating to Spatial Guide's current Subprocessors may be directed to:
Spatial Guide Private Limited
Email: privacy@spatial.guide
Website: https://www.spatial.guide