Subprocessors
Third-party providers Regi uses to deliver the service, and the personal data they may process.
Last updated: May 7, 2026
When Regi processes traveler personal data on behalf of a lodging customer, it does so as a data processor under Article 28 GDPR. To deliver the service, Regi engages a limited number of third-party providers (subprocessors). Each subprocessor is bound by a written agreement that imposes data-protection obligations consistent with our Data Processing Agreement.
This page lists the current subprocessors. It is part of the Data Processing Agreement and is updated whenever a subprocessor is added or replaced.
How we notify changes
We notify lodging customers of any intended addition or replacement of a subprocessor before the change takes effect. The current published version of this page is the authoritative list. Customers may object to a change as set out in the Data Processing Agreement.
For privacy-related questions about a subprocessor, write to privacy@regi.es.
Current subprocessors
| Provider | Purpose | Data processed | Processing location |
|---|---|---|---|
| Amazon Web Services (AWS) | Authoritative storage and runtime for traveler check-in data, account identity, and asset storage. Includes Cognito (auth), DynamoDB (data), S3 (files), and CloudFront (CDN). | Traveler personal data (names, ID/passport numbers, contact details, etc.), lodging account data, uploaded documents, request logs. | European Union (eu-south-2 Spain primary; eu-west-3 Paris for services not yet offered in eu-south-2, e.g. AWS SES, and for caches co-located with Vercel) |
| Vercel | Hosting of the authenticated Next.js application used by lodging managers. | Account email, IP, user-agent, request logs. | European Union (Paris region) |
| Stripe | Subscription billing, payment processing, invoicing, and tax handling for lodging customers. | Billing contact (name, email, address, tax ID), payment method tokens, invoice history. No traveler data. | Ireland (EU) and United States (with Standard Contractual Clauses) |
| Sentry | Error monitoring and performance traces for the application. | IP addresses; request and error context. PII is scrubbed before transmission, but stack traces and request payloads may incidentally contain personal data despite scrubbing. | European Union (de.sentry.io, Frankfurt) |
| PostHog | Product analytics and server-side sign-up attribution measurement (which marketing channel or campaign a sign-up came from — email today, potentially other channels in future). | Pseudonymous account identifier, sign-up events, and marketing-campaign identifiers (e.g. email rid and UTM parameters). No traveler data. | European Union (PostHog EU Cloud, Frankfurt) |
| Brevo | Transactional and marketing email delivery. | Recipient email address, message content, delivery metadata. | European Union (France) |
| OpenID Connect (Google Sign-In) authentication for lodging managers and Google Analytics 4 audience measurement on the marketing site (loaded only after analytics consent). | OIDC: Google account email and profile data shared at sign-in. GA4: pseudonymous client identifier, IP, user-agent, page interactions. | United States (with Standard Contractual Clauses) |
Notes
- AWS eu-south-2 (Spain) is the primary region where most traveler data is processed and stored. eu-west-3 (Paris) is used only for AWS services not yet offered in eu-south-2 (such as AWS SES for outbound email) and for caching layers co-located with the Vercel Paris region. No production traveler data is stored outside the European Union.
- Cloudflare delivers the public marketing site (regi.es) via Workers and CDN. The marketing site does not require sign-in and does not store identifiable traveler data; Cloudflare may transiently observe IPs and request metadata at the edge for security and routing.
- Sentry should not receive personal data thanks to client- and server-side scrubbing, but logs may occasionally contain personal data. IP addresses are processed by design.