Processors and recipients
Last updated: 8 October 2026 · the French version is authoritative.
Processors and recipients
Last updated: 8 October 2026 (list in line with the Privacy Policy, version 1.16, Articles 6 and 9).
The French version is the legal and original version; the NL/DE/EN versions are courtesy translations; in the event of any discrepancy, the French version prevails.
This page publishes the list of providers used by MOLDEREZ-CONSULT SRL (bloo.Cards) that process personal data. It applies:
- to the processing for which bloo.Cards is the controller, described in the Privacy Policy (Article 6);
- as the list of authorised sub-processors within the meaning of the Data Processing Agreement annexed to the Terms of Use, for the data that card holders collect through the Service.
The descriptions below reproduce the text of the Privacy Policy.
1. Processors
| Provider | Purpose and data sent | Country | Safeguard |
|---|---|---|---|
| Falcon Internet · OVHcloud (Gravelines) | Hosting of the infrastructure and servers (including the MariaDB database, the logs and the media files: images, videos and documents) | European Union | DPA, GDPR, SCC (where applicable) |
| Mollie | Payment processing (Bancontact, cards, iDEAL, PayPal, SEPA), including appointment deposits paid by card visitors; deposits and prepayments for restaurant bookings are collected through the restaurant's own Mollie account; PCI-DSS certified | Netherlands (EU) | DPA, GDPR |
| AuthSMTP | Sending transactional e-mails (verification, invoices, notifications) | United Kingdom | EU adequacy decision + SCC, DPA |
| Google (Google Ireland / Google LLC) | Maps, Places, OAuth (SSO) and Google Analytics 4 (optional, subject to consent) | Ireland (EU) / United States | EU-US Data Privacy Framework + SCC |
| LinkedIn Corporation (Microsoft) | "Sign In with LinkedIn" (optional SSO, OpenID Connect) | United States | EU-US Data Privacy Framework |
| ModernMT | Automatic translation of card content, at the request of the card's administrator, and of Multilingual chat messages (as a fallback); data sent: texts of card content and text of chat messages (without the participants' name, e-mail address or IP address) | European Union | DPA, GDPR |
| Langbly | Automatic translation of Multilingual chat messages, when this provider is activated (otherwise: ModernMT); data sent: text of the messages only | Access point in the European Union (eu.langbly.com) | GDPR |
| Z.ai (JINGSHENG HENGXING TECHNOLOGY PTE. LTD) | Artificial intelligence reading of business cards scanned in the Wallet; the photo is not kept (see Article 17.2) | Singapore | DPA, standard contractual clauses (SCC) |
| Anthropic PBC | Back-office AI assistant: text suggestions for empty fields of the card (tagline, job title, hobby, headline, SEO title, description and keywords), only at the user's request; data sent: card name and type, first name, last name, job title, company, department and tagline from the Contact module, types of active modules, city of the first address and texts already entered in these fields; never an e-mail address, phone number or address book contact | United States | Standard contractual clauses (SCC) |
| Twilio Inc. | Sending the verification code at registration (mobile number, 6-digit code) and SMS notifications to the card holder (video call request from the card, new conversation in the card's chat when the holder has enabled SMS alerts); data sent for notifications: holder's phone number, first name or name given by the visitor and a link to reply | United States | EU-US Data Privacy Framework + SCC |
| Recommand | Sending electronic invoices via the Peppol network; data sent: invoice in UBL format (customer's name or company name, address, VAT and company numbers and e-mail address, lines and amounts) | Belgium (EU) | GDPR |
The MariaDB database and the application sessions are hosted on our infrastructure at OVH (EU); these are not separate third-party services. Some processors (in particular Mollie, Google, AuthSMTP and Z.ai) may use their own sub-processors; the up-to-date list is available on request at privacy@bloo.cards.
2. Recipients that are not processors
The following services are not processors bound by a data processing agreement: they are third-party services to which certain data is sent, as recipients.
| Provider | Purpose and data sent | Country | Safeguard |
|---|---|---|---|
| OpenStreetMap Foundation (Nominatim service) | Geocoding of addresses and cities entered by holders in the back office; data sent: the text of the address entered, sent from our server | United Kingdom | EU-UK adequacy decision |
| YouTube (Google LLC) · Vimeo | Playback of videos embedded by holders in their cards; the video is loaded from YouTube or Vimeo only after the visitor clicks | United States | EU-US Data Privacy Framework |
VAT numbers are sent for verification to the European Commission's VIES service (public authority, European Union).
3. Transfers outside the European Union
Transfers to countries outside the European Union and the applicable safeguards (adequacy decision, EU-US Data Privacy Framework, standard contractual clauses of the European Commission) are detailed in Article 9 of the Privacy Policy. A copy of the safeguards may be requested at privacy@bloo.cards.
4. Change of processor: prior notice and objection
- Prior notice: any addition or replacement of a processor is announced by e-mail to account holders, at their account address, at least 30 days before it is put into service; this page is updated on the same date;
- Objection: during this period, you may object to the change in writing, stating your reasons, at privacy@bloo.cards, in accordance with Article A.8 of the Data Processing Agreement annexed to the Terms of Use;
- Signable version: for CORPORATE accounts, a signable version of the Data Processing Agreement is available on request at privacy@bloo.cards.