1. Purpose of this page
Kireli is offered by Anchor Labs. For transparency we distinguish between (A) external parties that may process or receive data on behalf of or for Kireli, and (B) technical software components in our own hosting environment. See also the privacy notice.
2. External parties
These are external services or providers with which personal data may be shared so that Kireli can operate. We do not claim that all processing takes place exclusively in the EU, and we do not publish internal risk scores or complete sub-processor lists here.
| Provider / role | Purpose | Data types (high level) | Notes |
|---|---|---|---|
| Hostinger (VPS/cloud hosting) | Running the Kireli production environment | Account, Space and technical runtime data | Primary production server in Germany (Frankfurt). Hostinger publishes a DPA that supplements its terms of service. That does not mean every support action or sub-processing always takes place in Germany. |
| Backblaze B2 (S3-compatible object storage) | Private media storage (database backups per architecture; that region to be confirmed separately) | Media objects, object metadata, backups | Primary production media storage in the EU Central region (Amsterdam according to Backblaze documentation). Backblaze is a US provider with a DPA; support, account data or separate backup copies may imply international access or another region. Kireli may also store a public OSM-derived global basemap archive in a dedicated bucket on the same provider; that archive is not customer trip photos or Space content. |
| Mailjet (Sinch Email) | Transactional email | Email address and service message content (for invitations including Space name, among other things) | DPA via Sinch/Mailjet terms; support may imply international access. |
| Stripe | Subscriptions, payments, Tax, invoices, customer portal | Customer, payment and invoice data | Payment environment on Stripe domains. Stripe may act as processor and (for some purposes) as independent controller. International processing is common. |
| PrintAPI (Galeri.nl B.V.) | Print production and shipping | Order, address and print files | Dutch print partner (Galeri.nl B.V.). Processes only the order, address and print data needed for intentional print orders, not your full private archive. |
There are no live analytics, advertising or cookie-banner providers in the current Kireli frontend.
OpenStreetMap is not a Kireli processor. The global basemap is an OSM-derived copy stored by Kireli and served same-origin to the browser. Protomaps may be the source of that public geographic archive, but neither OpenStreetMap nor Protomaps receive private trip data. OSM data is used under the ODbL with visible attribution.
3. Technical infrastructure
The names below describe software or components with which Kireli is technically built. They are not presented here as if they were automatically separate external processor companies. In the current architecture they run within the service hosting environment.
- Coolify: deployment/management layer for the production application.
- PostgreSQL: primary application database.
- Redis: rate limiting and technical limit storage.
- TileServer GL: previously used for self-hosted raster tiles during Trip Mapping 13.5 (no user data). Production global basemap is PMTiles on dedicated Kireli object storage.
- MapLibre GL JS and the PMTiles protocol: open-source map renderer and archive format in the browser/server; software libraries, not processors of private trip data.
4. What this page is not
This is not a complete internal processor register and not an overview of all providers' sub-processors. Formal governance, transfer matrices and outstanding contractual controls remain internal. We do not publish invented claims such as "all data stays in Europe" or "fully GDPR certified".
5. Contact
Questions about processors: support@kireli.eu.