MyGatePass Subprocessors
Last Updated: 09/09/2026
Who processes data on our behalf
This page is the authoritative Subprocessor List referred to in the MyGatePass Data Processing Agreement. It identifies every third party that processes personal data on behalf of our customers, the country in which each one processes it, what it does, and what data it receives.
| Subprocessor | Country of processing | Service performed | Data received | Minimisation applied |
|---|---|---|---|---|
| Microsoft (Azure) | United Arab Emirates. Azure UAE North for primary processing and storage; Azure UAE Central for backup and geo-redundant copies | Cloud hosting, compute, managed database, blob and image storage, backup, identity, platform monitoring | All customer personal data | Processing remains within the United Arab Emirates. See clause 8.3 of the DPA on Azure's global platform layer |
| Apple Inc. (Apple Push Notification service) | United States. Delivery infrastructure is globally distributed | Delivery of push notifications to iOS devices | Device push token and a minimised message payload | The payload carries an opaque reference only. No name, no vehicle plate, and no restriction or welfare content. The app resolves the reference from MyGatePass after the user authenticates |
| Google LLC (Firebase Cloud Messaging) | United States. Delivery infrastructure is globally distributed | Delivery of push notifications to Android devices | Device registration token and a minimised message payload | As Apple. Firebase installation identifiers are purged by Google within 180 days of last use |
| Brevo (Sendinblue SAS) | European Union. France, Germany and Belgium | Transactional email to end users: account activation, password reset, account and security notices | Email address and the content of the message sent | No student data, no vehicle plate data, and no restriction or welfare content |
| SMSGlobal Pty Ltd | Australia | One-time passcodes and operational SMS to customer staff and MyGatePass staff | Mobile telephone number and a short message body, typically a numeric passcode | Not sent to parents or guardians. No student data |
| Freshworks Inc. (Freshdesk) | Currently outside the United Arab Emirates. The account was hosted in the Freshworks UAE data centre. Freshworks moved it out of the region as a service-continuity measure following the March 2026 regional cloud disruption in the UAE, and has described the move as temporary. We are obtaining written confirmation of the current region and of the date of return, and will publish it here and notify account administrators under clause 7.2 of the DPA | Support ticketing between customer staff and MyGatePass | Support correspondence only. There is no automated feed from the platform | The tool holds only what a member of customer staff puts into a ticket. No customer personal data is placed in this tool while the hosting region remains unconfirmed |
No other party receives customer personal data.
Notice of changes, and your right to object
We give each customer's account administrator at least 30 days' notice by email before:
- adding or replacing a subprocessor;
- a subprocessor changing the country in which it processes personal data, whether or not the subprocessor itself changes; and
- any change to the description of the processing, the categories of data received, or the minimisation stated in the table above.
The notice states the subprocessor's identity, the country of processing, what it will do, what data it will receive, and the transfer basis relied on. A customer may object within that period on reasonable data-protection grounds. Where an objection is not resolved, the customer may terminate the affected services without penalty and we refund fees paid in advance for the terminated part pro rata. This is clause 7 of the Data Processing Agreement.
Parties that are not subprocessors
Recorded here to avoid ambiguity, because customers reasonably ask about each of them.
| Party | Why it is not a subprocessor |
|---|---|
| Contracted engineering personnel outside the United Arab Emirates | These personnel hold no access to production systems and no access to customer personal data, neither standing nor just-in-time. They contribute source code through reviewed pull requests under MyGatePass change control, working against non-production environments with synthetic data. No production credential is issued to them, and no customer personal data is exported to or reachable from their location. See clause 5.5 of the DPA |
| Systems the customer licenses directly | Where MyGatePass integrates with a customer's own student information system, HR system, directory or similar, that system is the customer's own processor and not our subprocessor. We consume the customer's API under the field mapping shown in the customer's account |
| UAE PASS | The UAE national digital identity service, where an organisation enables identity verification through it. UAE PASS is a source of verified identity attributes provided at the individual's own authentication, not a party we send customer personal data to for processing on our behalf. What we receive is recorded in Annex A of the DPA |
| Microsoft Power BI | Where a customer licenses Power BI and connects it to its own tenant data, that deployment is the customer's own, under the customer's own Microsoft agreement. We provide the interface; we do not send data to a Power BI service of our own |
| Customer-owned cameras and access hardware | Cameras, video management systems, barriers and readers on a customer's site are customer-owned and customer-procured and operate on the customer's own network. MyGatePass enables no manufacturer cloud service, remote-management channel or telemetry |
| Microsoft Azure DevOps | MyGatePass's own engineering environment: source control, work items and build pipelines. The organisation is provisioned outside the United Arab Emirates, in West Europe, which we disclose rather than leave to be found. It is not a production system, receives no feed from the platform, and holds no customer personal data. What it holds is MyGatePass source code and engineering records |
| AI services (Microsoft Azure OpenAI, Anthropic, OpenAI) | Used for internal MyGatePass tooling only. No customer personal data is submitted to any AI service, save for the single disclosed support-ticket flow described in clause 5.3 of the DPA, which operates after an automated redaction step. Listed here for transparency, not as data recipients. If that basis ceases to hold we will add them to the table above under clause 7.2 |
Fourth parties
Where a subprocessor engages its own processor to handle customer personal data, our flow-down terms require equivalent protections, and MyGatePass remains liable to the customer for that processing as if it were its own. This is clauses 7.4 and 7.5 of the Data Processing Agreement.
Where data is held
All customer personal data stores, being databases, blob and image storage, backups, any image store and the audit store, are provisioned in Azure UAE North with backup replication to Azure UAE Central. Both are in the United Arab Emirates.
The services listed above that operate outside that boundary are the push notification services, transactional email, staff SMS and support ticketing. Email at Brevo is the only systematic storage of end-user personal data outside the United Arab Emirates. Support correspondence may contain personal data where a member of customer staff includes it in a ticket.
No customer personal data is accessible to MyGatePass personnel located outside the United Arab Emirates. Each subprocessor's own personnel have access only to what its own system holds, as set out in the table above.
The transfer basis for each flow is set out in clause 8.5 of the Data Processing Agreement. Where a customer is subject to the EU GDPR or the UK GDPR, the transfer clauses in Annex F of that agreement apply and take effect without a separate signature.
Questions
Data protection: dpo@mygatepass.com. Security: security@mygatepass.com.
This page is reviewed at least annually and on any material change to the services.