Vendor Ecosystem & Architecture

BizLiveGo Subprocessors & Third-Party Services

Official public registry of external data processors, infrastructure partners, payment networks, telemetry providers, and technical due-diligence protocols maintaining the BizLiveGo digital profile ecosystem.

Data Fiduciary: BizLiveGo | Operator: MD Joshim Biswas | Malda, WB, India - 732206 | Effective Date: 16 September 2026

1. Statutory Framework

Role of Subprocessors

A Subprocessor is a vetted third-party data processor engaged by BizLiveGo who receives or processes personal data on our behalf to deliver specialized hosting, delivery, routing, or transaction services.

This policy satisfies strict transparency mandates under the Digital Personal Data Protection (DPDP) Act, Article 28 of the GDPR, and the CCPA/CPRA.

2. Contractual Guarantees

Data Processing Agreements (DPAs)

Every vendor listed in our registry is bound by legally enforceable Data Processing Addendums mandating:

  • Processing personal data strictly in accordance with BizLiveGo's documented instructions.
  • Implementing robust technical encryption (TLS 1.3 in transit, AES-256 at rest).
  • Prohibiting secondary monetization, sale, or data broker cross-sharing.
Zero-Transmission Rule

3. Absolute Exclusion of Sensitive Identity Credentials

BizLiveGo maintains an architectural barrier ensuring that third-party vendors and subprocessor data pipelines never receive high-risk identity documents:

Never Disclosed to Subprocessors

No external vendor pipeline ever ingests or processes:

  • National identification numbers, passport numbers, or tax registration records.
  • Unredacted identification card scans, citizen cards, or biometric data files.
  • Raw banking card CVVs, PIN numbers, OTPs, or private authentication passwords.

Encrypted Tokenization

Payment checkouts and edge deliveries follow isolation boundaries:

  • Financial transactions execute within sandboxed PCI-DSS Level 1 iframes (Razorpay, Stripe).
  • Voluntary directory listings (blood donor groups, biodata) are cached on encrypted edge servers solely for public link resolution.
4. Architecture Breakdown

Functional Subprocessor Classifications

How third-party technical vendors integrate into the BizLiveGo software delivery chain:

1. Hosting & Core DB

Infrastructure & storage:

  • Production cloud servers
  • Encrypted database clusters
  • Static asset object buckets
  • Daily automated snapshots

2. Edge CDN & WAF

Delivery & defense:

  • Global edge caching
  • DDoS mitigation
  • Web Application Firewall
  • Dynamic QR routing

3. Payment Gateways

Financial processing:

  • PCI-DSS tokenized checkouts
  • UPI & Indian net banking
  • International card settlement
  • Automated GST invoicing

4. Telemetry & Maps

Platform utilities:

  • Interactive map coordinates
  • Pseudonymized GA4 metrics
  • Promotional pixel attribution
  • System stability logging
5. Public Registry

Official Registry of Authorized Subprocessors

Complete audit inventory of authorized third-party service providers, service scopes, and entity locations:

Subprocessor Entity Service Scope & Purpose Data Categories Transferred Corporate Location
Cloudflare, Inc. Global Edge CDN, DNS routing, DDoS protection, and WAF security firewalls. IP addresses, device telemetry, HTTP headers, cached profile HTML. United States (Global Edge Nodes)
Hostinger Operations, UAB Primary server infrastructure, web hosting runtime, and application services. Account records, profile content, uploaded catalogs, system application logs. Lithuania (EU) / India Datacenter
Amazon Web Services (AWS) Encrypted cloud object storage buckets and automated rolling disaster backups. Uploaded image galleries, PDF resumes, logos, and encrypted snapshot shards. India (Mumbai Region)
Razorpay Software Pvt. Ltd. Domestic checkout gateway, UPI settlement, and automated tax invoicing. Billing name, transaction amount, order ID, masked banking reference. India
Cashfree Payments India Secondary domestic Indian checkout processing and banking reconciliations. Order numbers, payment session tokens, customer phone, transaction status. India
Stripe, Inc. International credit card processing and multi-currency billing checkouts. Tokenized card references, billing country, customer email, payment total. United States / Ireland (EU)
Google LLC (Google Maps API) Geographic pin rendering, latitude/longitude conversion, and turn-by-turn routing. User-pinned geographic coordinates, search queries, IP address. United States
Google LLC (Google Analytics 4) Pseudonymized platform telemetry, QR scan performance, and traffic flow monitoring. Pseudonymous client IDs, page URL paths, screen resolutions, device type. United States
Meta Platforms, Inc. (Meta Pixel) Marketing conversion tracking and platform audience discovery attribution. Hashed event parameters, browser user agent, referral campaign IDs. United States
6. Security Vetting

Vendor Due Diligence & Compliance Standards

How BizLiveGo evaluates and audits third-party service providers prior to onboarding:

1. Security Certification

All hosting, database, and infrastructure subprocessors must maintain certified compliance frameworks (SOC 2 Type II, ISO/IEC 27001, or PCI-DSS Level 1 for financial gateways).

2. Data Minimization

APIs and integrations are configured to pass strictly the minimal parameters required. Telemetry scripts are stripped of personal identifiers, utilizing randomized session keys.

3. Annual Audit Reviews

Our Data Protection Office conducts annual security and compliance reviews of all active vendors, confirming updated Standard Contractual Clauses (SCCs) and adherence to Indian DPDP requirements.

7. Change Notifications

Subprocessor Updates & Right to Object

As BizLiveGo expands, we may engage new subprocessors to enhance platform security, stability, or features.

  • Notice Period: We publish updates to this registry at least 15 calendar days prior to authorizing a new subprocessor.
  • Right to Object: Enterprise publishers may lodge an objection on data protection grounds by contacting our DPO at support@bizlivego.com.
  • Resolution: If an objection cannot be mitigated, the user may terminate their subscription without penalty.
8. Downstream Purges

Deletion Synchronization Across Vendors

When a user exercises their Right to Erasure or terminates an account:

  • Cloudflare edge caches receive instant purge API triggers flusing profile snapshots.
  • Database clusters execute hard purges (`DELETE / DROP`) within our 7 to 15 working days SLA.
  • Payment gateways decouple customer profiles while retaining statutory tax receipts.
Quick Summary

Subprocessor Governance Quick Reference

Consolidated review of vendor obligations, data boundaries, and user rights:

Governance Area Platform Provision Compliance Standard
Statutory Foundation Section 8 of DPDP Act 2023, Article 28 of GDPR, and CCPA/CPRA. Enforceable DPA Mandates
Prohibited Identifiers National ID cards, passports, bank card CVVs, and passwords are never transferred. Zero-Transmission Ban
Primary Server Location Core application and user databases hosted in India (Mumbai / Bengaluru regions). Domestic Data Security
Edge CDN Distribution Cloudflare edge nodes cache profile layouts and dynamic QR SVG assets globally. Encrypted Caching
Subprocessor Vetting Mandatory SOC 2 Type II, ISO 27001, or PCI-DSS certifications before onboarding. Rigorous Due Diligence
Registry Notice Period Registry updates posted at least 15 days in advance of new vendor activation. Advance Notice Period
Downstream Purge SLA Erasure directives synchronized to downstream caches within 7 to 15 working days. Enforced SLA

Questions Regarding Our Subprocessor Network?

If you wish to inspect our Data Processing Addendums (DPAs), object to a proposed subprocessor, or inquire about third-party security certifications, reach out to our privacy compliance office.

Data Protection Officer: Joshim Biswas | Location: Masimpur, Kaliachak, Malda, West Bengal, India - 732206