Legal

Data Processing Agreement V4, up to Oct 8, 2025

Data Processing Agreement

1 Background and Purpose

1.1 This Data Processing Agreement (“DPA”) sets out the terms and conditions for the processing of Personal Data by MeetingPackage.com on behalf of User. This DPA shall be applied to the agreement regarding the provision of electronic platform and/or related reservation and booking services by MeetingPackage.com (“Services”) entered into by and between the Parties (“Agreement”).

1.2 Agreement referred to in this DPA may be either:

(i) Booking Engine Service Agreement based on which MeetingPackage.com processes personal data on behalf of User by storing details of the customers’ reservations including personal data (name, email address, phone number, company name and possible additional information provided by the customers themselves) for the purposes of providing software services for User; or

(ii) Service Provider Agreement based on which MeetingPackage.com processes personal data on behalf of User by transferring details of the customers’ reservations including personal data (name, email address, phone number, company name and possible additional information provided by the customers themselves) to the Service Provider for the purposes of providing services for Customers; or

(iii) User License Agreement based on which MeetingPackage.com processes personal data on behalf of User by providing a customized platform through which customers can book meetings services, hotel rooms, venues and other products. The personal data about customers processed on behalf of the User may include name, email address, phone number, company name and possible additional information provided by the customers themselves or additional information asked from time to time by User.

1.3 Notwithstanding what is stated in the Agreement, in the event of conflict between this DPA and the Agreement the terms and conditions of this DPA shall prevail.

1.4 “Data Protection Regulation” shall in this DPA mean any applicable data protection legislation as amended from time to time (including but not limited to the EU Data Protection Directive (95/46/EC) and the General Data Protection Regulation, “GDPR” (2016/679/EU)) and the instructions and binding orders of the data protection authorities.

1.5 MeetingPackage.com acts as a data processor and User acts as a data controller, the concepts of which are further defined in the Data Protection Regulation. An individual whose Personal Data is being processed by MeetingPackage.com under this DPA and the Agreement will act as a Data Subject, the concept of which is further defined in the Data Protection Regulation.

1.6 The GDPR will not be applied until 25 May 2018. When the GDPR has been implemented into national legislation or if binding instructions are given by any supervisory authority, this DPA might need to be updated, if so mutually agreed between the Parties.

2 Definitions

Any terms not defined in this DPA or the Agreement shall be given the meaning allocated to them in Data Protection Regulation from time to time.

3 The Purpose Of The Processing Of Personal Data

MeetingPackage.com shall process Personal Data on behalf of User and in accordance with the terms and conditions of the DPA for the purpose of providing the Services under the Agreement.

4 Rights And Responsibilities Of User

User shall:

(i) process Personal Data in accordance with good data processing practices and in compliance with Data Protection Regulation and all applicable laws;

(ii) give documented instructions to MeetingPackage.com on the processing of Personal Data, which instructions shall be binding on both User and MeetingPackage.com after the written approval of MeetingPackage.com;

(iii) at all times retain the control and authority to Personal Data, including readiness to respond to requests for exercising the Data Subject’s rights under the Data Protection Regulation; and

(iv) assist MeetingPackage.com by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of MeetingPackage.com’s obligations under this DPA and Data Protection Regulation.

5 Responsibilities Of MeetingPackage.com

5.1 General principles applying to the processing of Personal Data

MeetingPackage.com shall process the Personal Data only in accordance with the Data Protection Regulation, the Agreement and this DPA as well as the approved documented instructions from User, unless otherwise required in applicable laws and regulations to which MeetingPackage.com is subject. In such case, MeetingPackage.com shall inform User of such requirement under applicable laws and regulations before processing of Personal Data, unless the applicable laws and regulations prohibit such notification.

5.2 Assistance of User

5.3 MeetingPackage.com shall, taking into account the nature of the processing of Personal Data under this DPA:

(i) assist User by appropriate technical and organizational measures in User’s obligation to respond to requests for exercising the Data Subject’s rights laid down in Chapter III of the GDPR; and

(ii) assist User in ensuring compliance with its legal obligations pursuant to Articles 32 to 36 of the GDPR.

5.4 The assistance performed by MeetingPackage.com under this section 6.2 shall be charged in accordance with the pricing and payment terms in the Agreement.

5.5 Data security

As from the date when the GDPR is applied, MeetingPackage.com shall implement technical, physical and organizational measures to comply with the obligations regarding security of processing under the GDPR. Detailed measures are listed in ANNEX II to this DPA.

5.6 Confidentiality

MeetingPackage.com shall ensure that the Personal Data processes are kept confidential. MeetingPackage.com shall ensure that any person the MeetingPackage.com has authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

5.7 Reporting and notification obligation

MeetingPackage.com shall make available to User all information necessary to demonstrate compliance with the obligations laid down in this DPA and the GDPR.

As from the date when the GDPR is applied, MeetingPackage.com shall maintain a record of processing activities under this DPA in accordance with the GDPR (“Record”). MeetingPackage.com shall provide User with the Record if requested by User.

5.8 Personal Data Breach notification

In the event of a breach of security leading to accidental or unlawful destruction, loss, alternation, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise processed, MeetingPackage.com shall notify User via email or telephone without undue delay after becoming aware of the personal data breach.

5.9 Returning or destruction of Personal Data

5.10 Upon termination of the applicable purpose of the processing of Personal Data, or upon User’s written request, MeetingPackage.com shall either destroy or return to User all Personal Data unless otherwise required by law.

5.11 MeetingPackage.com shall be entitled to return to User and destroy all Personal Data processed under this DPA if User has not requested MeetingPackage.com to destroy or return the Personal Data within ten (10) days from the date when the applicable purpose of the processing of Personal Data has terminated.

6 Transfers Of Personal Data

MeetingPackage.com shall have the right to transfer Personal Data outside the EU or the EEA if MeetingPackage.com establishes an adequate level of data protection through EU Standard Contractual Clauses based on the EU Commission’s standard contractual clauses.

MeetingPackage.com shall also be entitled to transfer Personal Data outside the EU or the EEA if the country or territory in which the recipient operates has been found to ensure an adequate level of protection for the rights and freedoms of Data Subjects in relation to the processing of Personal Data, including without limitation the EU-U.S. Privacy Shield or any subsequent or separately adopted equivalent provision, as determined by the European Commission and subject to the scope restrictions of any such determination.

7 Subcontractors

7.1 MeetingPackage.com may engage third-party subcontractors when providing the Services and processing Personal Data.

7.2 MeetingPackage.com shall ensure that the subcontractors comply with the same level of confidentiality, data security and other obligations as specified in this DPA. MeetingPackage.com is fully liable for the performance of the subcontractor’s obligations.

7.3 MeetingPackage.com shall inform User of possible forthcoming changes regarding the subcontractors in which case User may object to such change by notifying MeetingPackage.com within five (5) days of such notice. The User may not object to the changes without a grounded reason.

7.4 The list of subcontractors is provided in Annex III of this DPA.

8 Auditing

8.1 At any time during the term of the DPA, User or a recognized, independent third-party auditor appointed by User with proven experience and procedures shall have the right to audit MeetingPackage.com’s technical and organizational security measures as well as compliance with other data protection obligations agreed under this DPA. User shall give a prior written notice to MeetingPackage.com, such notice to be given at least sixty (60) calendar days prior to any audit.

8.2 MeetingPackage.com shall assist User in the execution of an audit and charge such assistance in accordance with the pricing and payment terms defined in the Agreement.

9 Limitation Of Liability

The limitation of liability agreed in the Agreement shall be applied to this Agreement.

10 Term

This DPA shall become effective when duly signed by both Parties and shall automatically terminate upon termination of the applicable purpose of processing of Personal Data under the Agreement.

11 Applicable Law And Dispute Resolution

This DPA shall be governed by the laws of Finland without regard to its principles and rules on conflict of laws and shall be subject to dispute resolution in accordance with the Agreement.

Annex I – List Of Parties

Controller:

Name of Controller: <to be filled>
Address: <to be filled>
Name of DPO: <to be filled>
Email: <to be filled>
Signatory’s Name: <to be filled>
Position: <to be filled>
Email: <to be filled>

Processor:

Name of Processor: MeetingPackage
Address: Sokerilinnantie 7 C, Espoo, Uusimaa 02600, Finland
Name of DPO:
Email:
Signatory’s Name: <to be filled>
Position: <to be filled>
Email: <to be filled>

Annex II – Technical And Organisational Security Measures

Description of the technical and organisational security measures implemented by the processor(s) (including any relevant certifications) to ensure an appropriate level of security, taking into account the nature, scope, context and purpose of the processing, as well as the risks for the rights and freedoms of natural persons.

Cocouz Oy (“MeetingPackage“) are ISO-27001 certified (cert nr. 13606-02) with the scope covering all “Operations (development, marketing, sales and support) for maintaining and developing the MeetingPackage product / service suite”.

1. Organisational Security Measures

1.1. Governance & Policies

1.1.1. Information Security Management System (ISMS) established and maintained in line with ISO 27001.

1.1.2. Documented information security policies approved by management and communicated to employees.

1.1.3. Formal risk assessment and treatment process.

1.1.4. Regular review of ISMS performance and continual improvement.

1.2. Roles & Responsibilities

1.2.1. Appointment of an Information Security Officer or equivalent.

1.2.2. Clearly defined roles, responsibilities, and segregation of duties.

1.3. Training & Awareness

1.3.1. Mandatory information security and privacy training for all employees.

1.3.2. Regular phishing awareness and social engineering prevention exercises.

1.4. Supplier & Sub-Processor Management

1.4.1. Due diligence and contractual security requirements for all suppliers/sub-processors.

1.4.2. Periodic reviews and monitoring of sub-processors’ compliance.

2. Technical Security Measures

2.1. Physical & Environmental Security

2.1.1. Secure office premises with controlled access

2.1.2. Data centers (via cloud providers like AWS) with multi-layered security and 24/7 monitoring.

2.2. 2.2 Access Control

2.2.1. Role-based access control (RBAC) aligned with the principle of least privilege.

2.2.2. Unique user IDs for all accounts; no shared accounts for administrative access.

2.2.3. Strong password policy or multi-factor authentication (MFA) for system access.

2.2.4. Automatic session timeouts and account lockouts after repeated failed attempts.

2.3. Encryption

2.3.1. In transit: TLS 1.2+ (or higher) for all data exchanges.

2.3.2. At rest: AES-256 (or equivalent) for databases, file storage, and backups.

2.3.3. Encryption keys managed securely, with rotation policies.

2.4. Logging & Monitoring

2.4.1. Centralized logging of security-relevant events

2.4.2. Continuous monitoring for anomalies and security incidents.

2.4.3. Retention of logs in a tamper-evident format for a defined period.

2.5. Network Security

2.5.1. Firewalls, intrusion detection/prevention systems (IDS/IPS).

2.5.2. Network segmentation between environments (production, staging, development).

2.5.3. Regular vulnerability scanning.

3. Operational Security Measures

3.1. Backup & Recovery

3.1.1. Encrypted backups with defined retention and secure off-site storage.

3.1.2. Regular restoration testing to verify data integrity and recovery time objectives.

3.2. Change Management

3.2.1. Formal process for approving and documenting changes to systems.

3.2.2. Testing and review before deployment.

3.3. Incident Response

3.3.1. Documented incident response plan covering detection, reporting, containment, eradication, recovery, and lessons learned.

3.3.2. Defined breach notification procedures to customers in accordance with GDPR.

3.4. Business Continuity & Disaster Recovery

3.4.1. Documented business continuity plan (BCP) and disaster recovery plan (DRP), with periodic testing

4. Data Protection Specific Measures

4.1. Data minimisation and purpose limitation in processing.

4.2. Secure deletion or destruction of data after retention periods expire.

4.3. Clear process for handling data subject requests (access, rectification, erasure, etc.).

5. Audit & Certification

5.1. ISO 27001 certification maintained via annual surveillance audits.

5.2. Willingness to provide evidence of compliance (audit reports, certificates).

5.3. Right of the customer to audit or receive third-party audit summaries.

Annex III – List Of Sub-Processors

The following is a list of pre-approved sub-processors.

#

Name of Subcontractor

Country of Processing

Description of Processing

1

Amazon

Germany, EU

Provider of cloud infra for application servers and databases

2

Microsoft

EU/EFTA

Provider of Business Analytics data platform

3

Google

EU, United States of America

Provider of Analytics platform

4

Stripe

Ireland, EU

Payment processor

5

PCI Booking

Ireland, EU

Payment processor

6

MongoDB

Germany, EU

Provider of cloud infra for databases

Data Processing Agreement

1 Background and Purpose

1.1 This Data Processing Agreement (“DPA”) sets out the terms and conditions for the processing of Personal Data by MeetingPackage.com on behalf of User. This DPA shall be applied to the agreement regarding the provision of electronic platform and/or related reservation and booking services by MeetingPackage.com (“Services”) entered into by and between the Parties (“Agreement”).

1.2 Agreement referred to in this DPA may be either:

(i) Booking Engine Service Agreement based on which MeetingPackage.com processes personal data on behalf of User by storing details of the customers’ reservations including personal data (name, email address, phone number, company name and possible additional information provided by the customers themselves) for the purposes of providing software services for User; or

(ii) Service Provider Agreement based on which MeetingPackage.com processes personal data on behalf of User by transferring details of the customers’ reservations including personal data (name, email address, phone number, company name and possible additional information provided by the customers themselves) to the Service Provider for the purposes of providing services for Customers; or

(iii) User License Agreement based on which MeetingPackage.com processes personal data on behalf of User by providing a customized platform through which customers can book meetings services, hotel rooms, venues and other products. The personal data about customers processed on behalf of the User may include name, email address, phone number, company name and possible additional information provided by the customers themselves or additional information asked from time to time by User.

1.3 Notwithstanding what is stated in the Agreement, in the event of conflict between this DPA and the Agreement the terms and conditions of this DPA shall prevail.

1.4 “Data Protection Regulation” shall in this DPA mean any applicable data protection legislation as amended from time to time (including but not limited to the EU Data Protection Directive (95/46/EC) and the General Data Protection Regulation, “GDPR” (2016/679/EU)) and the instructions and binding orders of the data protection authorities.

1.5 MeetingPackage.com acts as a data processor and User acts as a data controller, the concepts of which are further defined in the Data Protection Regulation. An individual whose Personal Data is being processed by MeetingPackage.com under this DPA and the Agreement will act as a Data Subject, the concept of which is further defined in the Data Protection Regulation.

1.6 The GDPR will not be applied until 25 May 2018. When the GDPR has been implemented into national legislation or if binding instructions are given by any supervisory authority, this DPA might need to be updated, if so mutually agreed between the Parties.

2 Definitions

Any terms not defined in this DPA or the Agreement shall be given the meaning allocated to them in Data Protection Regulation from time to time.

3 The Purpose Of The Processing Of Personal Data

MeetingPackage.com shall process Personal Data on behalf of User and in accordance with the terms and conditions of the DPA for the purpose of providing the Services under the Agreement.

4 Rights And Responsibilities Of User

User shall:

(i) process Personal Data in accordance with good data processing practices and in compliance with Data Protection Regulation and all applicable laws;

(ii) give documented instructions to MeetingPackage.com on the processing of Personal Data, which instructions shall be binding on both User and MeetingPackage.com after the written approval of MeetingPackage.com;

(iii) at all times retain the control and authority to Personal Data, including readiness to respond to requests for exercising the Data Subject’s rights under the Data Protection Regulation; and

(iv) assist MeetingPackage.com by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of MeetingPackage.com’s obligations under this DPA and Data Protection Regulation.

5 Responsibilities Of MeetingPackage.com

5.1 General principles applying to the processing of Personal Data

MeetingPackage.com shall process the Personal Data only in accordance with the Data Protection Regulation, the Agreement and this DPA as well as the approved documented instructions from User, unless otherwise required in applicable laws and regulations to which MeetingPackage.com is subject. In such case, MeetingPackage.com shall inform User of such requirement under applicable laws and regulations before processing of Personal Data, unless the applicable laws and regulations prohibit such notification.

5.2 Assistance of User

5.3 MeetingPackage.com shall, taking into account the nature of the processing of Personal Data under this DPA:

(i) assist User by appropriate technical and organizational measures in User’s obligation to respond to requests for exercising the Data Subject’s rights laid down in Chapter III of the GDPR; and

(ii) assist User in ensuring compliance with its legal obligations pursuant to Articles 32 to 36 of the GDPR.

5.4 The assistance performed by MeetingPackage.com under this section 6.2 shall be charged in accordance with the pricing and payment terms in the Agreement.

5.5 Data security

As from the date when the GDPR is applied, MeetingPackage.com shall implement technical, physical and organizational measures to comply with the obligations regarding security of processing under the GDPR. Detailed measures are listed in ANNEX II to this DPA.

5.6 Confidentiality

MeetingPackage.com shall ensure that the Personal Data processes are kept confidential. MeetingPackage.com shall ensure that any person the MeetingPackage.com has authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

5.7 Reporting and notification obligation

MeetingPackage.com shall make available to User all information necessary to demonstrate compliance with the obligations laid down in this DPA and the GDPR.

As from the date when the GDPR is applied, MeetingPackage.com shall maintain a record of processing activities under this DPA in accordance with the GDPR (“Record”). MeetingPackage.com shall provide User with the Record if requested by User.

5.8 Personal Data Breach notification

In the event of a breach of security leading to accidental or unlawful destruction, loss, alternation, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise processed, MeetingPackage.com shall notify User via email or telephone without undue delay after becoming aware of the personal data breach.

5.9 Returning or destruction of Personal Data

5.10 Upon termination of the applicable purpose of the processing of Personal Data, or upon User’s written request, MeetingPackage.com shall either destroy or return to User all Personal Data unless otherwise required by law.

5.11 MeetingPackage.com shall be entitled to return to User and destroy all Personal Data processed under this DPA if User has not requested MeetingPackage.com to destroy or return the Personal Data within ten (10) days from the date when the applicable purpose of the processing of Personal Data has terminated.

6 Transfers Of Personal Data

MeetingPackage.com shall have the right to transfer Personal Data outside the EU or the EEA if MeetingPackage.com establishes an adequate level of data protection through EU Standard Contractual Clauses based on the EU Commission’s standard contractual clauses.

MeetingPackage.com shall also be entitled to transfer Personal Data outside the EU or the EEA if the country or territory in which the recipient operates has been found to ensure an adequate level of protection for the rights and freedoms of Data Subjects in relation to the processing of Personal Data, including without limitation the EU-U.S. Privacy Shield or any subsequent or separately adopted equivalent provision, as determined by the European Commission and subject to the scope restrictions of any such determination.

7 Subcontractors

7.1 MeetingPackage.com may engage third-party subcontractors when providing the Services and processing Personal Data.

7.2 MeetingPackage.com shall ensure that the subcontractors comply with the same level of confidentiality, data security and other obligations as specified in this DPA. MeetingPackage.com is fully liable for the performance of the subcontractor’s obligations.

7.3 MeetingPackage.com shall inform User of possible forthcoming changes regarding the subcontractors in which case User may object to such change by notifying MeetingPackage.com within five (5) days of such notice. The User may not object to the changes without a grounded reason.

7.4 The list of subcontractors is provided in Annex III of this DPA.

8 Auditing

8.1 At any time during the term of the DPA, User or a recognized, independent third-party auditor appointed by User with proven experience and procedures shall have the right to audit MeetingPackage.com’s technical and organizational security measures as well as compliance with other data protection obligations agreed under this DPA. User shall give a prior written notice to MeetingPackage.com, such notice to be given at least sixty (60) calendar days prior to any audit.

8.2 MeetingPackage.com shall assist User in the execution of an audit and charge such assistance in accordance with the pricing and payment terms defined in the Agreement.

9 Limitation Of Liability

The limitation of liability agreed in the Agreement shall be applied to this Agreement.

10 Term

This DPA shall become effective when duly signed by both Parties and shall automatically terminate upon termination of the applicable purpose of processing of Personal Data under the Agreement.

11 Applicable Law And Dispute Resolution

This DPA shall be governed by the laws of Finland without regard to its principles and rules on conflict of laws and shall be subject to dispute resolution in accordance with the Agreement.

Annex I – List Of Parties

Controller:

Name of Controller: <to be filled>
Address: <to be filled>
Name of DPO: <to be filled>
Email: <to be filled>
Signatory’s Name: <to be filled>
Position: <to be filled>
Email: <to be filled>

Processor:

Name of Processor: MeetingPackage
Address: Sokerilinnantie 7 C, Espoo, Uusimaa 02600, Finland
Name of DPO:
Email:
Signatory’s Name: <to be filled>
Position: <to be filled>
Email: <to be filled>

Annex II – Technical And Organisational Security Measures

Description of the technical and organisational security measures implemented by the processor(s) (including any relevant certifications) to ensure an appropriate level of security, taking into account the nature, scope, context and purpose of the processing, as well as the risks for the rights and freedoms of natural persons.

Cocouz Oy (“MeetingPackage“) are ISO-27001 certified (cert nr. 13606-02) with the scope covering all “Operations (development, marketing, sales and support) for maintaining and developing the MeetingPackage product / service suite”.

1. Organisational Security Measures

1.1. Governance & Policies

1.1.1. Information Security Management System (ISMS) established and maintained in line with ISO 27001.

1.1.2. Documented information security policies approved by management and communicated to employees.

1.1.3. Formal risk assessment and treatment process.

1.1.4. Regular review of ISMS performance and continual improvement.

1.2. Roles & Responsibilities

1.2.1. Appointment of an Information Security Officer or equivalent.

1.2.2. Clearly defined roles, responsibilities, and segregation of duties.

1.3. Training & Awareness

1.3.1. Mandatory information security and privacy training for all employees.

1.3.2. Regular phishing awareness and social engineering prevention exercises.

1.4. Supplier & Sub-Processor Management

1.4.1. Due diligence and contractual security requirements for all suppliers/sub-processors.

1.4.2. Periodic reviews and monitoring of sub-processors’ compliance.

2. Technical Security Measures

2.1. Physical & Environmental Security

2.1.1. Secure office premises with controlled access

2.1.2. Data centers (via cloud providers like AWS) with multi-layered security and 24/7 monitoring.

2.2. 2.2 Access Control

2.2.1. Role-based access control (RBAC) aligned with the principle of least privilege.

2.2.2. Unique user IDs for all accounts; no shared accounts for administrative access.

2.2.3. Strong password policy or multi-factor authentication (MFA) for system access.

2.2.4. Automatic session timeouts and account lockouts after repeated failed attempts.

2.3. Encryption

2.3.1. In transit: TLS 1.2+ (or higher) for all data exchanges.

2.3.2. At rest: AES-256 (or equivalent) for databases, file storage, and backups.

2.3.3. Encryption keys managed securely, with rotation policies.

2.4. Logging & Monitoring

2.4.1. Centralized logging of security-relevant events

2.4.2. Continuous monitoring for anomalies and security incidents.

2.4.3. Retention of logs in a tamper-evident format for a defined period.

2.5. Network Security

2.5.1. Firewalls, intrusion detection/prevention systems (IDS/IPS).

2.5.2. Network segmentation between environments (production, staging, development).

2.5.3. Regular vulnerability scanning.

3. Operational Security Measures

3.1. Backup & Recovery

3.1.1. Encrypted backups with defined retention and secure off-site storage.

3.1.2. Regular restoration testing to verify data integrity and recovery time objectives.

3.2. Change Management

3.2.1. Formal process for approving and documenting changes to systems.

3.2.2. Testing and review before deployment.

3.3. Incident Response

3.3.1. Documented incident response plan covering detection, reporting, containment, eradication, recovery, and lessons learned.

3.3.2. Defined breach notification procedures to customers in accordance with GDPR.

3.4. Business Continuity & Disaster Recovery

3.4.1. Documented business continuity plan (BCP) and disaster recovery plan (DRP), with periodic testing

4. Data Protection Specific Measures

4.1. Data minimisation and purpose limitation in processing.

4.2. Secure deletion or destruction of data after retention periods expire.

4.3. Clear process for handling data subject requests (access, rectification, erasure, etc.).

5. Audit & Certification

5.1. ISO 27001 certification maintained via annual surveillance audits.

5.2. Willingness to provide evidence of compliance (audit reports, certificates).

5.3. Right of the customer to audit or receive third-party audit summaries.

Annex III – List Of Sub-Processors

The following is a list of pre-approved sub-processors.

#

Name of Subcontractor

Country of Processing

Description of Processing

1

Amazon

Germany, EU

Provider of cloud infra for application servers and databases

2

Microsoft

EU/EFTA

Provider of Business Analytics data platform

3

Google

EU, United States of America

Provider of Analytics platform

4

Stripe

Ireland, EU

Payment processor

5

PCI Booking

Ireland, EU

Payment processor

6

MongoDB

Germany, EU

Provider of cloud infra for databases