🔐 Sub-processor & Security Overview

Effective Date: September 23, 2026
Version: 1.0
Company: DASTAVEZ.NET (SMC-PRIVATE) LIMITED
This page provides transparency about the third parties that process personal data on behalf of Dastavez.net and the security measures protecting the Platform. It forms part of the Data Processing Addendum (Annex 3) and supports the Privacy Policy.

1. Purpose

This page provides transparency about the third parties that process personal data on behalf of Dastavez.net and the security measures protecting the Platform. It forms part of the Data Processing Addendum (Annex 3) and supports the Privacy Policy. It is updated whenever our sub-processors change, with at least fifteen (15) days’ advance notice before a new sub-processor processes Publisher Data.

2. Current Sub-processors

The following categories of sub-processors process personal data to help us deliver the Services:

Sub-processorFunctionProcessing location
Amazon Web Services (AWS)Hosting, storage, and compute for the Platform, and infrastructure monitoring/logging via Amazon CloudWatchSingapore
MongoDB AtlasDatabase hosting for the PlatformCloud region configured for our deployment, aligned with our primary hosting region (Singapore)
Brevo (Sendinblue SAS)Transactional and service email deliveryEuropean Union

Analytics: Dastavez uses an in-house, self-built analytics system rather than a third-party analytics provider. No personal data is shared with an external analytics sub-processor for this purpose.

Customer support: Customer support is provided directly by Dastavez via email and phone (see Contact, below) rather than through a third-party support-ticketing platform.

Error and crash monitoring: Application stability and error diagnostics are handled through internal logging together with Amazon CloudWatch (see the AWS entry above); no separate third-party crash-monitoring sub-processor is used.

Each sub-processor is bound by a written contract imposing data protection obligations materially equivalent to our DPA. This table is kept current as our vendors change.

3. Independent Providers (Not Sub-processors)

The following providers process personal data as independent controllers under their own terms and privacy policies, when you choose to use them:

  • Payment processors — process subscription and Minting payments you initiate; Dastavez never receives full card numbers or banking credentials;
  • Redemption Partners — licensed third-party wallet and reward-fulfilment providers that perform Value Coin redemptions, including their own identity verification (KYC);
  • Sign-in providers (Google, Facebook, Apple) — when you choose third-party sign-in.

4. Security Overview

Infrastructure and data

  • Primary hosting in Singapore on Amazon Web Services, with environment segregation between production and staging (production personal data is not used in staging except anonymised);
  • Encryption in transit (TLS 1.2+) and at rest; hashed and salted credential storage;
  • Backups with defined restoration objectives and rolling deletion of expired backups.

Access and operations

  • Role-based access control on the principle of least privilege, with access reviews and logging of administrative access;
  • Token-based authentication for integrations; secrets management for credentials;
  • Vulnerability management, patching, and periodic security reviews.

People and process

  • Personnel confidentiality undertakings and security awareness measures;
  • Vendor due diligence and contractual security obligations for all sub-processors;
  • Documented incident response supporting 72-hour breach notification to affected Publishers and, where required, supervisory authorities.

5. Updates and Notifications

Changes to this page are versioned and dated. Business-plan Publishers may subscribe to sub-processor change notifications by emailing privacy@dastavez.net with the subject “Sub-processor notifications”. Objection rights and procedures are set out in Section 5 of the Data Processing Addendum.

6. Reporting Security Issues

If you believe you have found a security vulnerability, please report it responsibly to privacy@dastavez.net with sufficient detail to reproduce the issue. We ask that you do not access or modify data belonging to others, and we commit to acknowledging good-faith reports promptly and not pursuing action against good-faith security research conducted within these bounds.

DASTAVEZ.NET (SMC-PRIVATE) LIMITED
98-H, Gulberg 3, Lahore, Pakistan
privacy@dastavez.net