Subprocessors
The third-party processors that handle personal information on behalf of Cr8tivehub Digital Studios (Pty) Ltd.
1. Our Commitment
- We update this list before we onboard a new subprocessor that will process personal information.
- We provide at least 30 days' notice of any material change (a new subprocessor, a change of location, or a new category of data) by:
- Updating the “Last updated” date above;
- Posting an entry under “Recent changes” at the bottom of this page;
- For business customers (agencies under the Agency DPA), sending an email to the Authorised Representative.
- Where a subprocessor change creates an unacceptable risk for an agency customer, the agency may terminate the affected service on written notice within the 30-day window and receive a pro-rata refund of the unused prepaid period.
2. Current Subprocessors
Core platform infrastructure
| Subprocessor | Service | Data categories | Location | Safeguards |
|---|---|---|---|---|
| Google LLC (Google Cloud Platform and Firebase) | The platform itself: accounts and sign-in, the database, file storage for portfolio media and for verification documents (deleted once a decision is made), server-side processing, push delivery, abuse protection, runtime configuration, and crash reporting | Account and profile data, credentials in hashed form, content and its metadata, messages, billing records, settings, user-generated media, verification documents, device and push identifiers, crash diagnostics | Belgium (EU) for the database, file storage, accounts and server processing; globally distributed for push delivery, abuse protection and configuration; United States for crash reporting | EU adequacy for the European services; Google Standard Contractual Clauses throughout; encryption at rest |
| Vercel Inc. | Hosting of cr8tivehub.com, accounts.cr8tivehub.com and agency.cr8tivehub.com | IP address, request metadata, server logs; personal information passing through those websites | United States; globally distributed network | Vercel data processing addendum |
Content moderation and identity verification
| Subprocessor | Service | Data categories | Location | Safeguards |
|---|---|---|---|---|
| Google LLC (Cloud Vision API) | Automated content moderation on uploaded images and video frames | Image content during scan; SafeSearch result returned | United States | Google SCCs |
| Google LLC (ML Kit — Face Detection) | On-device liveness detection during the in-app verification fallback | Camera frames during the verification capture only — does not leave the device | On the user's device | N/A (no cross-border transfer) |
| Didit (Didit Identity Spain, S.L., Calle Nápoles 227, 08013 Barcelona, Spain; and/or Didit Identity, Inc., Delaware, USA) | Identity verification for creatives (primary method): identity document check, live selfie, liveness detection and face match. Where enabled, business verification for agencies (company registry check and a director's identity check). | Identity document images and data read from them, selfie, liveness recording (biometric — special personal information). Collected by Didit directly; Cr8tivehub receives only the result (status, checks passed, document type and issuing country). | European Union (Spain) and/or United States | 2021 EU Standard Contractual Clauses and adequacy decisions (as stated by Didit); verification media retained for six months; sessions deleted at Didit on account erasure. Privacy policy |
Live streaming and real-time
| Subprocessor | Service | Data categories | Location | Safeguards |
|---|---|---|---|---|
| LiveKit Inc. | Real-time audio/video streaming infrastructure | Audio/video stream content, room metadata, participant identifiers | United States | LiveKit SCCs |
Payments
| Subprocessor | Service | Data categories | Location | Safeguards |
|---|---|---|---|---|
| PayFast (Pty) Ltd | Subscription payment processing | Name, email, transaction amount, tier identifier. Payment card data does not touch Cr8tivehub systems — it is handled exclusively by PayFast. | South Africa | PCI DSS Level 1; POPIA §21 operator agreement |
| Google LLC (Google Play in-app purchases) | In-app purchases in the Android app (verification badge, boosts) | Transaction identifier and purchase status returned to Cr8tivehub; Google handles the payment itself | United States | Google SCCs |
Search and discovery
| Subprocessor | Service | Data categories | Location | Safeguards |
|---|---|---|---|---|
| Typesense (Typesense Cloud) | Hosted search index for talent discovery and agency search | Public creative-profile fields only (professional name, professions, location, attributes the creative has made visible). No contact details, identity documents or private data. | Cluster region being confirmed | Typesense data-processing terms for Typesense Cloud |
| Subprocessor | Service | Data categories | Location | Safeguards |
|---|---|---|---|---|
| Twilio Inc. (SendGrid) | Delivery of all platform email — account and security email, notifications, transactional and marketing email | Recipient email address, name, email content | United States | Twilio SCCs |
Security and abuse prevention
| Subprocessor | Service | Data categories | Location | Safeguards |
|---|---|---|---|---|
| Google LLC (reCAPTCHA Enterprise) | Bot and abuse detection on web forms and, through Firebase App Check, on accounts.cr8tivehub.com and agency.cr8tivehub.com | IP address, browser fingerprint, behavioural signals | United States | Google SCCs |
Mobile-only
| Subprocessor | Service | Data categories | Location | Safeguards |
|---|---|---|---|---|
| Google LLC (Google Mobile Ads / AdMob) | In-app advertising on the mobile app, only for users without an ad-free subscription | Advertising ID (if opted in), device data, ad interaction events | United States | Google SCCs; AdMob consent SDK gates personalised ads |
3. Categorisation Under POPIA
For the purposes of POPIA, Cr8tivehub is the responsible party for the personal information of its users. The subprocessors above are operatorsunder section 21 of POPIA, processing on Cr8tivehub's behalf under written agreements.
Special-category data (biometric data — identity document image, selfie, liveness and face match) is processed under section 27(1)(a) of POPIA (explicit consent), with the only subprocessors involved being:
- Didit (primary method) — performs the document, liveness and face-match checks and holds the images and liveness recording under the retention we configure; Cr8tivehub receives only the result;
- For the in-app verification fallback only: Google ML Kit (on-device face detection, no transfer) and Google Cloud Storage (encrypted storage of the selfie and ID document in the EU, deleted once a decision is made).
4. Cross-Border Data Transfers
Where a subprocessor processes data outside the Republic of South Africa, the transfer is justified under section 72 of POPIA on the basis of one or more of:
- EU adequacy— recognised for transfers to Belgium (EU) and, where Didit's EU data plane is used, Spain (EU).
- Standard Contractual Clauses — Google, LiveKit and Twilio; Didit states that it relies on the 2021 EU Standard Contractual Clauses and adequacy decisions for its international transfers.
- Consent — where applicable for specific user-initiated transfers (e.g. payment to PayFast).
Cr8tivehub maintains copies of the relevant transfer mechanisms and will make them available to the Information Regulator on request.
5. Recent Changes
| Date | Change | Reason |
|---|---|---|
| 2026-09-11 | Added Didit (identity verification), Vercel (hosting) and app-store in-app purchases; clarified biometric processing. | Bring the list in line with the processors actually in use |
| 2026-05-21 | Initial publication | First formal subprocessor list |
Future changes will be added to the top of this table with a 30-day prior-notification entry.
6. Contact
Privacy enquiries: legal@cr8tivehub.com
Subprocessor objections (agency customers): agency-support@cr8tivehub.com
Information Officer: Thokozani Dube — admin@cr8tivehub.com (registration 2026-011645)