Subprocessor Notice
生效日期: 2026-03-01
公司: Asteria Limited (HK)
This Subprocessor Notice explains how Asteria Limited (HK) may engage third-party service providers, contractors, infrastructure providers, technical vendors, operational vendors, and other subprocessors to support the operation, security, delivery, monitoring, maintenance, and improvement of ASTERIA KYC services.
ASTERIA KYC provides identity verification, document verification, liveness detection, biometric processing, AML screening support, fraud prevention workflows, risk scoring, case management, API, SDK, dashboard, reporting, and compliance-support services. In order to deliver these services reliably and securely, ASTERIA KYC may rely on carefully selected third-party service providers.
This notice is written as a public overview. It does not list vendor names, account identifiers, infrastructure identifiers, audit firm names, certification identifiers, or contract identifiers.
1. Purpose of Subprocessors
Subprocessors may support ASTERIA KYC in providing and operating services for Customers. Subprocessors may perform limited functions on behalf of ASTERIA KYC, including:
- cloud hosting
- infrastructure operation
- secure storage
- database management
- content delivery
- security monitoring
- system logging
- backup and recovery
- email delivery
- customer support
- error tracking
- performance monitoring
- analytics
- identity verification infrastructure support
- document processing support
- AML or screening data support where enabled
- fraud prevention tooling
- communications
- operational administration
- billing and commercial administration where applicable
Subprocessors are used to support service functionality, resilience, security, and operational efficiency.
2. Categories of Subprocessors
ASTERIA KYC may use subprocessors in the following categories.
2.1 Cloud Infrastructure and Hosting Providers — Cloud infrastructure providers may host application servers, databases, storage environments, processing infrastructure, network services, backup environments, and related technical systems.
2.2 Storage and Database Providers — Storage and database providers may support secure storage of Customer Data, verification workflow data, logs, case records, system data, and backup materials, subject to applicable retention and access controls.
2.3 Security and Monitoring Providers — Security providers may support threat detection, vulnerability management, intrusion monitoring, event logging, access monitoring, incident response, system hardening, and abuse detection.
2.4 Communications and Email Providers — Communications providers may support transactional emails, customer notifications, service updates, operational alerts, support correspondence, and administrative communications.
2.5 Customer Support and Ticketing Providers — Support providers may help manage customer inquiries, technical support tickets, onboarding requests, support communications, and issue tracking.
2.6 Analytics and Performance Providers — Analytics and performance providers may help ASTERIA KYC understand website performance, application performance, usage patterns, error events, page performance, feature adoption, and operational reliability.
2.7 Screening and Compliance Data Providers — Where enabled by Customer configuration, screening or compliance data providers may support sanctions screening, politically exposed person screening, adverse media indicators, watchlist checks, risk data, or other compliance-related data sources.
2.8 Fraud Prevention and Risk Signal Providers — Fraud prevention providers may support device intelligence, abuse detection, fraud pattern analysis, suspicious activity indicators, duplicate detection, or risk signal enrichment.
2.9 Professional and Operational Service Providers — Professional and operational providers may include legal advisers, accountants, security advisers, technical consultants, auditors, insurers, and administrative service providers that support ASTERIA KYC operations under appropriate confidentiality obligations.
3. Types of Data Processed by Subprocessors
Depending on the service and Customer configuration, subprocessors may process or access limited categories of data, including:
- Customer account information
- Customer administrator information
- End User identity data
- identity document data
- document images
- facial images, selfies, or video frames
- biometric-related signals where enabled
- liveness detection outputs
- verification results
- AML screening outputs where enabled
- risk scores
- case management records
- audit logs
- API logs
- security logs
- system metadata
- support communications
- billing or commercial records where applicable
- website usage data
- cookie preference data
The specific categories of data processed depend on the services used, the Customer’s configuration, and the subprocessor’s function.
4. No Public Vendor List Included
This public Subprocessor Notice does not list vendor names, service account identifiers, contract numbers, infrastructure names, audit firm names, certification numbers, or internal supplier identifiers.
ASTERIA KYC may provide additional vendor-related information to Customers through appropriate contractual, security review, procurement, or due diligence channels where commercially reasonable and legally permissible.
5. Subprocessor Selection
ASTERIA KYC seeks to use subprocessors that are appropriate for the service function they perform.
Subprocessor selection may consider factors such as:
- service reliability
- security posture
- confidentiality commitments
- data protection controls
- technical capability
- operational resilience
- support quality
- compliance alignment
- geographic considerations
- contractual safeguards
- ability to support ASTERIA KYC service requirements
6. Contractual Safeguards
Where applicable, ASTERIA KYC expects subprocessors to process data subject to contractual safeguards that may include:
- confidentiality obligations
- data protection commitments
- security obligations
- limited purpose processing
- access restrictions
- incident notification commitments
- cooperation obligations
- deletion or return obligations
- restrictions on unauthorized disclosure
- appropriate transfer mechanisms where required
The exact safeguards may vary depending on the subprocessor category, service function, jurisdiction, and contract type.
7. Access Controls
Subprocessor access to data is intended to be limited to what is reasonably necessary for the subprocessor to provide the relevant service.
Access controls may include:
- role-based access
- environment restrictions
- logging
- authentication controls
- least-privilege principles
- administrative access restrictions
- confidentiality obligations
- monitoring and review where appropriate
8. International Processing
Subprocessors may operate in or access data from jurisdictions outside the Customer’s or End User’s location.
Where required by applicable law, ASTERIA KYC and its Customers should implement appropriate safeguards for international transfers, which may include contractual mechanisms, transfer assessments, supplementary measures, or other legally recognized mechanisms.
Customers are responsible for determining whether their use of ASTERIA KYC involves specific cross-border transfer obligations.
9. Customer Responsibility
Customers are responsible for:
- determining whether the use of ASTERIA KYC and its subprocessors is appropriate for their legal and regulatory obligations
- reviewing applicable data processing terms
- providing required notices to End Users
- obtaining required consents or other lawful bases
- evaluating cross-border transfer requirements
- configuring retention and workflow settings appropriately
- maintaining their own vendor governance where required
- ensuring that their use of verification and screening tools is lawful
10. Changes to Subprocessors
ASTERIA KYC may add, replace, remove, or change subprocessors from time to time in order to improve service delivery, security, reliability, performance, functionality, or compliance operations.
Where required by a written agreement, ASTERIA KYC may provide notice of material subprocessor changes through the agreed notice mechanism.
11. Objections to Subprocessors
If a Customer has a contractual right to object to a new subprocessor, the Customer must submit objections through the process and timeframe specified in the applicable agreement.
An objection should include a reasonable, good-faith basis related to data protection, security, legal, or regulatory concerns.
12. Incident Handling
If ASTERIA KYC becomes aware of a confirmed security incident involving a subprocessor and affecting Customer-controlled personal data, ASTERIA KYC will take appropriate steps to investigate, mitigate, and notify affected Customers as required by applicable law or agreement.
13. Subprocessor Restrictions
Subprocessors are not authorized to use Customer Data for their own independent commercial purposes unless permitted by law, Customer instruction, or applicable agreement.
Subprocessors should process data only as necessary to provide the relevant service function.
14. Relationship with Data Processing Terms
This Subprocessor Notice should be read together with ASTERIA KYC’s Privacy Policy, Data Processing Addendum, Security Statement, Data Retention Policy, and applicable Customer agreements.
If a signed agreement between ASTERIA KYC and a Customer contains specific subprocessor terms, the signed agreement governs to the extent of conflict.
15. Updates to This Notice
ASTERIA KYC may update this Subprocessor Notice from time to time. Updated versions will be posted on the website with a revised effective date.
對本政策有任何疑問嗎?
若您對本政策、ASTERIA KYC 服務、資料處理、合規工作流程或相關文件有任何問題,請透過網站上提供的官方聯絡管道與 Asteria 聯繫。