Provider transparency

Service Providers and Data Transfers

This policy explains provider selection, data a provider might receive, contractual and transfer controls, and how we avoid publishing an assumed list that does not match actual operations.

Published and effective as an operational document, without claiming external legal review

This is a public operational text. It does not replace a project contract, a product-specific privacy notice, or legal review based on the organization and its actual service providers.

Document code
POL-PUB-PROVIDERS-001
Version
1.0.0
Effective date
Content review
Next review
Owner
Governance and privacy
Authoritative version
Arabic. If translations differ, the Arabic text prevails, subject to applicable law and contract.
Contact channel
studio@cupcodestudio.com
Scope

Public website, accounts, and connected digital services

Audience

Visitors, users, and clients

Jurisdiction

Kingdom of Saudi Arabia, subject to other mandatory laws where applicable

Operational publication authority

Cup Code operational publication catalog

Document summary

This policy explains provider selection, data a provider might receive, contractual and transfer controls, and how we avoid publishing an assumed list that does not match actual operations.

Actual, not invented, provider list

We do not publish a provider merely because the platform supports connecting it. This version contains no provider list because a publishable operations register has not yet been approved. You may request disclosure relevant to your service through the privacy channel. This page must be updated before a provider appears in the public storage register.

Due diligence

Before connection, we review ownership, location, service, security, privacy, continuity, incidents, subprocessors, deletion, audit rights, and exit plan.

Contract terms

The contract defines party roles, purpose, instructions, categories, location, confidentiality, controls, assistance with rights and incidents, and disposal. A sensitive service does not rely only on linked public terms.

Minimization and access

Providers receive the smallest technical and data scope. Separate service accounts, key rotation, and access logs are used, and administrative accounts are not shared between vendors.

Transfers outside the Kingdom

A transfer assessment records country, purpose, categories, sensitivity, necessity, safeguard, and any applicable exemption. A suitable legal mechanism such as standard contractual clauses or approved safeguard is used where needed.

Provider changes

A new provider is reviewed before activation. We update the list and notice and request new consent if an optional purpose changes or law requires. Exit and deletion plans run on termination.

Monitoring and incidents

We review connection status, errors, permissions, security reports, and renewal. Providers must report incidents without undue delay and provide information needed for assessment and notification.

Rights and deletion

The data map links providers so access or destruction requests reach every system. We verify a deletion certificate or API outcome rather than relying only on account closure.

Official references

References used to prepare this content

Links point to official legal or guidance sources. Applicability depends on the organization, product, and contract.

Versions

Change log

  1. Version 1.0.0

    Published the first operational version with clear scope, responsibilities, rights, and escalation routes.