This page is the Subprocessor List referred to in Schedule 1 (Data Processing Agreement), DPA 4.2 of the Saije Software Licence, Subscription & Managed Presentation Services Agreement (the “Full Agreement”) and in Section 4 of our Privacy Policy. It identifies the third parties PixelFaerie engages to process personal data on behalf of its clients in the course of providing the Saije Platform and Managed Services.
1.1 Where you submit Client Content containing personal data to the Saije Platform for Managed Services, PixelFaerie acts as your data processor. A “sub-processor” is a third party engaged by PixelFaerie to process that personal data, or the account and service data associated with your use of the Platform, on PixelFaerie’s behalf.
1.2 Every sub-processor listed below is bound by written terms imposing data protection obligations equivalent to those in Schedule 1 of the Full Agreement, and PixelFaerie remains liable for their acts and omissions (DPA 4.3).
1.3 For each material sub-processor this list identifies the service performed, the country or countries in which processing takes place, and the mechanism relied on for any transfer of personal data outside the European Economic Area (“EEA”), as required by DPA 4.2.
Sub-processors engaged to operate the Saije Platform and to deliver Managed Services:
| Sub-processor | Service performed | Location of processing | Transfer mechanism |
|---|---|---|---|
| PixelFaerie (Pty) Ltd | Presentation, slide and document production — design, formatting and production of Deliverables from Client Content under Managed Services | South Africa | EU Standard Contractual Clauses (SCCs); encryption in transit and at rest |
| Microsoft Azure | Cloud hosting and infrastructure for the Saije Platform, including storage and backup of Client Content and account data | European Union; Middle East & Africa; United States | Adequacy decision (EU–US Data Privacy Framework, US); EU Standard Contractual Clauses (SCCs); encryption in transit and at rest |
| Mimecast | Email security, continuity and archiving for service notifications, support correspondence, renewal and change notices | European Union; Middle East & Africa; United States | Adequacy decision (EU–US Data Privacy Framework, US); EU Standard Contractual Clauses (SCCs); encryption in transit and at rest |
| Sendmarc | Email authentication and domain protection (DMARC, SPF, DKIM) for outbound email | European Union; Middle East & Africa; United States | Adequacy decision (EU–US Data Privacy Framework, US); EU Standard Contractual Clauses (SCCs); encryption in transit and at rest |
| Stripe, Inc. | Billing and payment processing. Card payments are handled by the payment processor under its own PCI-DSS compliance; PixelFaerie does not store card numbers | European Union; United States | Adequacy decision (EU–US Data Privacy Framework, US); EU Standard Contractual Clauses (SCCs); encryption in transit and at rest |
| ESET | Cyber security — endpoint protection, security monitoring and threat detection for the Platform and production systems | European Union | Not applicable (processing within the EEA) |
2.1 Website analytics and advertising tools. The following providers process website-visitor data only (not Client Content) and load solely with your cookie consent, as described in Sections 2.6 and 9.5 of the Privacy Policy. They are listed here for completeness:
| Provider | Service performed | Location of processing | Transfer mechanism |
|---|---|---|---|
| Google Ireland Limited | Google Analytics 4 — website usage analytics (Consent Mode v2, consent-gated) | European Union; United States | EU–US Data Privacy Framework and/or EU Standard Contractual Clauses |
| LinkedIn Ireland Unlimited Company | LinkedIn Insight Tag — advertising measurement and retargeting (consent-gated) | European Union; United States | EU–US Data Privacy Framework and/or EU Standard Contractual Clauses |
| Meta Platforms Ireland Limited | Meta Pixel — advertising measurement and retargeting (consent-gated) | European Union; United States | EU–US Data Privacy Framework and/or EU Standard Contractual Clauses |
3.1 Notification. PixelFaerie will notify you of any intended addition or replacement of a sub-processor at least fourteen (14) days before the change takes effect. Notice is given by email to the registered contact on your account and by updating this page and the change log in Section 5. To receive notices at a different address, update the contact details in your account settings or email dataprotectionofficer@pixelfaerie.com.
3.2 Objection. You may object to the appointment of a new sub-processor on reasonable data-protection grounds by giving written notice within the fourteen (14)-day notice period. PixelFaerie will work in good faith with you to resolve the objection. If the parties cannot reach a reasonable solution within thirty (30) days of the objection, you may terminate the affected Managed Services without penalty, and PixelFaerie will refund any prepaid fees attributable to the terminated services on a pro-rata basis, as set out in DPA 4.2A of the Full Agreement.
Where a sub-processor processes personal data outside the EEA, PixelFaerie ensures an adequate level of protection by relying on a European Commission adequacy decision (including the EU–US Data Privacy Framework where the recipient is certified), the European Commission’s Standard Contractual Clauses (Article 46(2)(c) GDPR), or another safeguard permitted under Chapter V GDPR, as described in Section 5 of the Privacy Policy. Copies of the applicable safeguards are available on request.
| Version | Date | Change |
|---|---|---|
| 1.0 | 4 September 2026 | Initial publication. |
Data Protection
General and Legal Enquiries