CrewShift Landing Page Subprocessor List
Last updated: 23 July 2026 Version: 2.3 Scope:crewshift-app.com and zmianowo-app.pl as landing pages only
1. Scope
This list covers providers that may process data in connection with the landing page, forms, security, optional analytics and optional chat.
It does not cover the CrewShift/Zmianowo application, accounts, payments, application database, employee data or training modules. Those areas are governed by the application subprocessor list, which is also presented during registration.
2. Providers
| Provider | Role | Data categories | Use condition |
|---|---|---|---|
| Cloudflare Inc. | Workers hosting, server functions, infrastructure logs and metrics, request rate limiting and Turnstile | IP, headers, source domain, request and error logs, rate-limit key and metadata, verification token, device and browser signals | hosting, logs and rate limiting as page infrastructure; Turnstile on form submission |
| Resend / Plus Five Five, Inc. | e-mail delivery for forms and Brillnet-owned contact-list handling | full name, e-mail, company, subject, message content, assessment result, subscription source, consent or unsubscribe status, message metadata | when the user submits a form or subscribes to Brillnet-owned communication |
| Google Ireland Ltd. / Google LLC | Google Analytics 4 | cookie identifiers, page events, device data | only after analytics consent and when GA4 is configured |
| Crisp IM SAS | chat widget | chat session data, conversation content, IP, device metadata | only after functional consent and when Crisp is configured |
3. Transfers outside the EEA
Providers may use infrastructure or subprocessors outside the European Economic Area. Resend / Plus Five Five, Inc. is a US-based provider. Transfers should rely on safeguards declared by the relevant provider, including a data processing agreement, Standard Contractual Clauses, the EU-US Data Privacy Framework or other GDPR-compliant mechanisms.
4. Deliberately excluded items
The landing page should not list services that are not used by the page itself, in particular:
- payment processors,
- application login,
- the production application database,
- error monitoring, unless actually enabled in this project,
- providers of production-application features for training content, learner progress or tests.
If any of those services is actually added to the landing page, this list should be updated before deployment.
