MyGatePass Subprocessors
Last Updated: 09/09/2026
Who processes data on our behalf
This is the authoritative Subprocessor List referred to in the MyGatePass Data Processing Agreement. It identifies every third party that processes personal data on behalf of our customers, the country in which each one processes it, what it does, and what data it receives.
It is published here so that a customer, a prospective customer or an individual can read it without having to ask. Every change notice under clause 7.2 of the DPA repeats the same information in the notice itself, so no one is dependent on retrieving this page in order to exercise the right to object under clause 7.3. Questions about an entry go to privacy@mygatepass.com.
| Subprocessor | Country of processing | Service performed | Data received | Minimisation applied |
|---|---|---|---|---|
| Microsoft (Azure) | United Arab Emirates. Azure UAE North for primary processing and storage; Azure UAE Central for backup and geo-redundant copies. A disaster recovery server is provisioned in Azure North Europe (Ireland) and currently holds no customer personal data, with no database replicating to it | Cloud hosting, compute, managed database, blob and document storage, backup, identity, platform monitoring | All customer personal data | Processing of customer personal data remains within the United Arab Emirates. The Ireland server is disclosed before use rather than after; clause 8.1 of the DPA describes it, why the region was chosen, and what activating it would mean, including 7 days' notice before replication begins in the ordinary course and notification within two business days where failover is needed during an actual incident. See clause 8.3 on Azure's global platform layer |
| Apple Inc. (Apple Push Notification service) | United States. Delivery infrastructure is globally distributed | Delivery of push notifications to iOS devices | Device push token and a minimised message payload | The payload carries an opaque reference only. No name, no vehicle plate, and no restriction or welfare content. The app resolves the reference from MyGatePass after the user authenticates |
| Google LLC (Firebase Cloud Messaging) | United States. Delivery infrastructure is globally distributed | Delivery of push notifications to Android devices | Device registration token and a minimised message payload | As Apple. Firebase installation identifiers are purged by Google within 180 days of last use |
| Brevo (Sendinblue SAS) | European Union. France, Germany and Belgium | Transactional email to end users: account activation, password reset, account and security notices | Email address and the content of the message sent | No student data, no vehicle plate data, and no restriction or welfare content |
| SMSGlobal Pty Ltd | Australia | One-time passcodes and operational SMS to customer staff and MyGatePass staff | Mobile telephone number and a short message body, typically a numeric passcode | Not sent to parents or guardians. No student data |
| OpenAI, L.L.C. | United States | AI analysis of entry and visit activity, producing written summaries for an organisation's own administrators in the MyGatePass dashboard | Entry and visit records of adult visitors | Used for no other purpose. Safeguarding and welfare content, any student or child data, and all data of any customer with the school module enabled are excluded absolutely under clause 5.3 of the DPA and cannot be included by notice or agreement. Any customer may have all AI submission of its data disabled on written request. This processing is moving to Microsoft Azure OpenAI Service in Azure UAE North, at which point this row is removed and the Microsoft row updated under clause 7.2 |
| Anthropic PBC | United States | Reading an identity document at the gate where the machine-readable zone cannot be scanned, so the details can be entered without manual typing | The document image, for that transaction only | Reached only as a fallback from the machine-readable-zone scan. Excluded categories as above. Subject to the same customer disable right. Also moving in region |
| Freshworks Inc. (Freshdesk) | Currently outside the United Arab Emirates. The account was hosted in the Freshworks UAE data centre. Freshworks moved it out of the region as a service-continuity measure following the March 2026 regional cloud disruption in the UAE, and has described the move as temporary. We are obtaining written confirmation of the current region and of the date of return, and will record it here and notify account administrators under clause 7.2 of the DPA | Support ticketing between customer staff and MyGatePass | Support correspondence only. There is no automated feed from the platform | The tool holds only what a member of customer staff, or of MyGatePass staff, puts into a ticket, which may include personal data. Support staff are instructed not to place student data, safeguarding content or welfare content in a ticket. The transfer basis is clause 8.5 of the DPA, and the country of processing will be stated here as soon as Freshworks confirms it in writing |
| Functional Software, Inc. (Sentry) | United States [CONFIRM: whether the MyGatePass organisation is on Sentry's US or EU region] | Crash and error diagnostics for the MyGatePass mobile applications: Visitor, GateKeeper, Kiosk and Infopanel | Diagnostic data captured at the moment of a crash: application and device state, operating system and application version, and a stack trace | Personal data masking is enabled in each application, so the content of fields on screen is not transmitted. Collection of IP address and device identifier is configured off [CONFIRM]. MyGatePass describes this configuration rather than warranting it, and clause 6.2 of the DPA applies. A crash report from a staff-facing application may still carry a MyGatePass or customer staff identifier where the operating system includes it in the crash context |
No other party receives customer personal data.
Notice of changes, and your right to object
We give each customer's account administrator at least 30 days' notice by email before:
- adding or replacing a subprocessor;
- a subprocessor changing the country in which it processes personal data, whether or not the subprocessor itself changes; and
- any change to the description of the processing, the categories of data received, or the minimisation stated in the table above.
The notice states the subprocessor's identity, the country of processing, what it will do, what data it will receive, and the transfer basis relied on. A customer may object within that period on reasonable data-protection grounds. Where an objection is not resolved, the customer may terminate the affected services without penalty and we refund fees paid in advance for the terminated part pro rata. This is clause 7 of the Data Processing Agreement, published at mygatepass.com/dpa.
Parties that are not subprocessors
Recorded here to avoid ambiguity, because customers reasonably ask about each of them.
| Party | Why it is not a subprocessor |
|---|---|
| Contracted engineering personnel outside the United Arab Emirates | These personnel hold no access to production systems and no access to customer personal data, neither standing nor just-in-time. They contribute source code through reviewed pull requests under MyGatePass change control, working against non-production environments with synthetic data. No production credential is issued to them, and no customer personal data is exported to or reachable from their location. See clause 5.5 of the DPA |
| Systems the customer licenses directly | Where MyGatePass integrates with a customer's own student information system, HR system, directory or similar, that system is the customer's own processor and not our subprocessor. We consume the customer's API under the field mapping shown in the customer's account |
| UAE PASS | The UAE national digital identity service, where an organisation enables identity verification through it. UAE PASS is a source of verified identity attributes provided at the individual's own authentication, not a party we send customer personal data to for processing on our behalf. What we receive is recorded in Annex A of the DPA |
| Microsoft Power BI | Where a customer licenses Power BI and connects it to its own tenant data, that deployment is the customer's own, under the customer's own Microsoft agreement. We provide the interface; we do not send data to a Power BI service of our own |
| Customer-owned cameras and access hardware | Cameras, video management systems, barriers and readers on a customer's site are customer-owned and customer-procured and operate on the customer's own network. MyGatePass enables no manufacturer cloud service, remote-management channel or telemetry |
| Microsoft Azure DevOps | MyGatePass's own engineering environment: source control, work items and build pipelines. The organisation is provisioned outside the United Arab Emirates, in West Europe, which we disclose rather than leave to be found. It is not a production system, receives no feed from the platform, and holds no customer personal data. What it holds is MyGatePass source code and engineering records |
| AI services used for MyGatePass's own internal work (support-ticket triage, engineering productivity) | Internal MyGatePass tooling. No customer personal data is submitted for these internal purposes. Clause 5.3 of the DPA governs every submission to an AI service whatever the purpose, and any service that receives customer personal data appears in the table above |
Fourth parties
Where a subprocessor engages its own processor to handle customer personal data, our flow-down terms require equivalent protections, and MyGatePass remains liable to the customer for that processing as if it were its own. This is clauses 7.4 and 7.5 of the Data Processing Agreement.
Where data is held
All customer personal data stores, being databases, document and file storage, backups and the audit store, are provisioned in Azure UAE North with backup replication to Azure UAE Central. Both are in the United Arab Emirates.
One thing disclosed before it exists. A database server for disaster recovery is provisioned in Azure North Europe (Ireland). It holds no customer personal data and no database is replicating to it. We are telling you now rather than when it is switched on. The reason for choosing Ireland rather than a third Emirati region is that Azure UAE North and Azure UAE Central are around 130 kilometres apart in one jurisdiction and share one regional risk envelope, so a recovery region outside that envelope protects you better. Clause 8.1 of the DPA sets out what activating it would involve, and we are not committing to activate it.
The services listed above that operate outside that boundary are the push notification services, transactional email, staff SMS, support ticketing, crash diagnostics and the AI services. Email at Brevo is the only systematic storage of end-user personal data outside the United Arab Emirates. Support correspondence may contain personal data where a member of staff includes it in a ticket, and a crash report may carry a staff identifier where the operating system includes it in the crash context.
Access to customer personal data is granted only to MyGatePass personnel whose normal place of work is the United Arab Emirates. Occasional access by an authorised person while travelling is from a managed device with multi-factor authentication and is logged. Before granting access to anyone whose normal place of work is outside the United Arab Emirates, MyGatePass gives at least 30 days' notice and the customer may object on reasonable data-protection grounds. This is clause 5.5 of the DPA. Each subprocessor's own personnel have access only to what its own system holds, as set out in the table above.
The transfer basis for each flow is set out in clause 8.5 of the Data Processing Agreement. Where a customer is subject to the EU GDPR or the UK GDPR, the transfer clauses in Annex F of that agreement apply and take effect without a separate signature.
Questions
Data protection: dpo@mygatepass.com. Security: security@mygatepass.com.
This page is reviewed at least annually and on any material change to the services.