Register Section 01
Overview
This page identifies third parties that may process Customer Personal Data on behalf of Kool&Tech LLC in connection with contracted services. A provider is a Subprocessor only when the provider processes Customer Personal Data for Kool&Tech in a processor capacity.
The providers actually involved depend on the service, Customer configuration, hosting model, integrations, region, and Statement of Work. Not every listed provider applies to every Customer or engagement.
Important distinction: A customer-selected platform, payment processor, carrier, independent controller, or direct vendor is not necessarily Kool&Tech's Subprocessor. The contractual role depends on the actual data flow and relationship.
Register Section 02
Core service providers
Odoo S.A. and applicable Odoo affiliates
Service dependentERP, CRM, website, eCommerce, portal, help desk, project, automation, application hosting, and related platform functions when an Odoo-managed service is used.
Microsoft Corporation and applicable affiliates
Service dependentBusiness email, identity, collaboration, file exchange, meetings, support, administration, cloud, and AI-enabled Microsoft services where included.
Register Section 03
Communications providers
Twilio Inc. and applicable affiliates
Feature dependentSMS, MMS, voice, verification, messaging, email delivery, or related communications when a Twilio service is enabled for the applicable workflow.
A carrier or telecommunications provider may operate under its own legal role rather than as a Kool&Tech Subprocessor.
Register Section 04
Payment and commerce providers
Stripe entities applicable to the transaction
Role dependentPayment processing, fraud prevention, checkout, transaction administration, or integration functions when Stripe is selected.
PayPal entities applicable to the transaction
Role dependentPayment, checkout, account, fraud-prevention, and transaction functions when PayPal is selected.
Complete payment-card information should be processed directly by an approved payment provider and not stored by Kool&Tech unless expressly agreed.
Register Section 05
Customer-selected platforms
Kool&Tech frequently integrates Odoo and business processes with platforms selected or directly contracted by the Customer. Examples may include Microsoft 365, Shopify, WooCommerce, Amazon services, banks, payment gateways, accounting systems, WMS platforms, carriers, and other APIs.
When the Customer contracts directly with the provider and instructs Kool&Tech to configure or connect it, the provider may be the Customer's processor, independent controller, or direct service provider rather than Kool&Tech's Subprocessor.
The SOW or integration design should identify the provider, purpose, information exchanged, account owner, and responsibilities.
Register Section 06
AI and intelligent services
AI providers are listed as Kool&Tech Subprocessors only when Kool&Tech enables a specific AI provider to process Customer Personal Data on Kool&Tech's behalf.
Future KoolArchitect or other AI-enabled functionality may use Microsoft-hosted AI, OpenAI, Odoo AI, or another documented provider. Before Customer Personal Data is processed through a material AI feature, the applicable provider, purpose, configuration, retention, and contractual role should be documented through the service description, DPA schedule, product notice, or updated Subprocessor list.
AI vendors made available solely through a Customer-owned account or a platform's embedded feature may instead fall under the Customer's or platform provider's contractual relationship.
Register Section 07
Downstream subprocessors
Odoo, Microsoft, Twilio, payment providers, and other vendors may use their own subprocessors. Those downstream organizations are selected and governed by the primary provider under the provider's contract and published privacy materials.
Kool&Tech does not reproduce every downstream vendor in this page because those lists may change independently. Customers should consult the current official Subprocessor disclosures of the applicable primary provider.
Register Section 08
Processing locations and transfers
Processing locations vary by service, region, Customer selection, routing, support activity, and provider architecture. A listed headquarters location does not necessarily identify every processing location.
Restricted Transfers are handled under the Data Processing Addendum and an applicable lawful mechanism, which may include an adequacy decision, approved contractual clauses, certification, or another mechanism recognized by the applicable law.
Register Section 09
Authorization and objections
The Kool&Tech Data Processing Addendum provides general authorization to engage Subprocessors needed to provide contracted services.
Where applicable law or the DPA requires notice, Kool&Tech may publish an update or notify the Customer's designated contact before a material new Subprocessor begins relevant processing. A Customer may object on reasonable, documented data-protection grounds within the applicable notice period.
The parties will work in good faith on a commercially reasonable alternative. If no reasonable alternative is available, the affected service may be discontinued as provided by the DPA or service agreement.
Register Section 10
Provider review and safeguards
Review may consider the provider's purpose, information processed, access, security, privacy terms, data-protection commitments, service dependency, location, transfer mechanism, and available assurance material.
Kool&Tech seeks written protections appropriate to the provider's role. No provider relationship eliminates all operational, security, legal, or availability risk.
Register Section 11
Changes to this list
This list may change as Kool&Tech services, Customers, platforms, integrations, vendors, and legal requirements evolve.
An added provider is not used for every Customer automatically. The current service configuration and applicable agreement determine which providers process a particular Customer's Personal Data.