Gunbix › List of processors

Version 1.6 - In force since 30 August 2026

List of Gunbix processors

This page lists the processors (within the meaning of Article 28 GDPR) engaged by Takion for the provision of the Gunbix Service. This list supplements the Privacy Policy.

Each processor is bound to Takion by a contract compliant with Article 28 GDPR containing, among other things, undertakings as to confidentiality, security, assistance in giving effect to data subject rights, and notification of personal data breaches. Any transfers outside the European Union are governed by the standard contractual clauses adopted by the European Commission (Decision 2021/914), supplemented by additional safeguards in accordance with the Court of Justice judgment in Schrems II.

1. Hosting and application infrastructure

Cloudflare, Inc.

Item Detail
Identity Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, United States
Services used Cloudflare Workers and Workers Static Assets, Cloudflare D1, Cloudflare R2, Cloudflare Turnstile, Cloudflare DNS and content delivery network, Email Routing, Workers logging
Purpose Hosting the Service infrastructure, running the server code, storing user data, protection against automated requests for sign-in codes, delivery of the website and the web application, routing of correspondence to the published contact points
Categories of data All user data processed by the Service
Principal location See the section "Where the data actually is" below. Requests are handled by the global Cloudflare network
Transfers outside the EU Possible (edge processing, support). Governed by the standard contractual clauses and the EU-US Data Privacy Framework
Certifications ISO 27001, ISO 27018, SOC 2 Type II
Documentation cloudflare.com/trust-hub

Turnstile, the anti-robot check

The request for a sign-in code may be protected by Turnstile, a check that distinguishes a human visitor from a program. It works by loading a script served by challenges.cloudflare.com and presenting the browser with a test that is usually invisible; the result is verified by the server with the same provider. This is not an additional processor: it is Cloudflare, which is already responsible for the whole of the infrastructure.

Two points that matter. First, the script is loaded only if the check is active: the browser queries the server before displaying the sign-in screen, and for as long as the check is switched off, no request goes to challenges.cloudflare.com. Second, it is switched off as at 30 August 2026. It is described here because the wiring is in place and switching it on will require only a configuration change: the list must say so beforehand, not afterwards.

This check is strictly necessary to protect the Service against the automated sending of sign-in codes. It serves no other purpose, and in particular no audience measurement.

Where the data actually is

Three resources hold the data of the Service, and they do not offer the same guarantee. The distinction is not a drafting subtlety: with this hosting provider, a location indication expresses a latency preference, whereas a jurisdiction is a technical constraint that prevents execution and storage outside the region.

Resource Content Observed region Jurisdiction
R2 object storage gunbix-media Target photographs, supporting documents European Union European Union, constrained at creation
Database gunbix-db Accounts, shooting sessions, firearms inventory, sign-in history Western Europe, observed on 31 July 2026 None
Database gunbix-catalog Public catalogue of firearms and ammunition, containing no personal data Western Europe, observed on 31 July 2026 None

In other words: for object storage, European residency is constrained. For the database that holds the personal data, it is observed as at the date of the reading, and nothing enforces it technically. Takion therefore does not, as of today, promise guaranteed European residency at the level of that database.

That jurisdiction can only be set when a database is created: adding it to gunbix-db means creating a new database, transferring the data to it and switching the Service over. The reading, the command that allows it to be repeated, and the status of that migration are kept in docs/runbooks/residence-donnees.md.

2. Payment

Stripe Payments Europe Limited

Item Detail
Identity Stripe Payments Europe Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland
Services used Stripe Billing, Stripe Checkout, Stripe Customer Portal
Purpose Collection of subscription payments, management of payment methods, issuing of invoices, handling of refunds
Categories of data Subscription identifier, payment status, transaction references. No banking data is processed by Takion
Principal location European Union (Ireland)
Transfers outside the EU Possible, to Stripe Inc. (United States), in the course of operating the global service. Governed by the standard contractual clauses and the Data Privacy Framework
Certifications PCI DSS Level 1, ISO 27001, SOC 1, SOC 2
Documentation stripe.com/legal/privacy-center

As at 30 August 2026 no paid offering is open: billing is disabled in the Service and no data is transmitted to Stripe. The entry is retained because the provider has been selected and because its entry into service will be the subject of prior notice.

3. Transactional communications

Two providers are involved, each within a distinct scope.

Cloudflare, Inc., already listed under point 1, routes correspondence addressed to the published contact points (Email Routing).

Resend, Inc.

Item Detail
Identity Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, United States
Services used Transactional email sending API (api.resend.com)
Purpose Delivery of all email sent by the Service: single-use sign-in code, message stating that no account is associated with an address, bulk message sent by a Club to its members, automatic reminder for a document approaching expiry, alert to a shooter for a quarter without a session, summary sent to Club staff
Categories of data Recipient's email address, Club's reply address, subject and body of the message, name of the Club, nature and due date of the document concerned, technical identifier of the message returned by the provider, and the delivery events for the message (accepted, permanently rejected, temporarily rejected, reported as spam)
Data sensitive by its nature The body of the sign-in email contains the single-use code, valid for a few minutes and on one occasion only. The provider is thereby on the authentication path, which justifies restricting communication with it to a single module of the code
Principal location United States
Transfers outside the EU Yes. Governed by the standard contractual clauses
Documentation resend.com/legal/privacy-policy

Recipients are resolved on the server side from the Club's membership file, never supplied by the browser, and each message is sent individually: no member's address is disclosed to another recipient.

No commercial prospecting email is sent from the Service.

Open and click tracking: not enabled. The provider offers to place an invisible pixel in messages and to rewrite the links they contain, in order to measure opens and clicks. Neither option is used: the Service's emails contain no images, neither remote nor embedded, and no link is rewritten. Such a pixel would fall under Article 5(3) of the ePrivacy Directive and would require the recipient's prior consent (see Article 2.8 of the Privacy Policy).

4. Mapping

Google Ireland Limited (Google Maps Platform)

Item Detail
Identity Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Services used Google Maps JavaScript API, Places API, Geocoding API
Purpose Display of maps (clubs, gun shops), address autocompletion at registration, conversion of an address into coordinates
Categories of data IP address of the terminal, originating page, location coordinates or address entered, partial autocompletion text, technical identifiers
Principal location European Union
Transfers outside the EU Governed by the standard contractual clauses
Documentation cloud.google.com/maps-platform/terms

When exactly the library is fetched. It used to be fetched when the application opened, on every screen, including those that display no map: Google received the IP address of every visitor before that visitor had asked for anything. That has not been the case since 22 August 2026. Loading is now triggered by the screen that needs a map, and by address autocompletion on the first keystroke in the field. A User who opens neither a map nor an address form does not contact Google.

Geocoding (conversion of an address into coordinates) is called from the terminal: Google receives its IP address.

5. Technical components of the web application

As at 30 August 2026, no technical component of the application is served by a third party any longer. The rendering engine, the three brand typefaces, the fallback typefaces and all images are produced at build time and served from Takion's servers. There is therefore no processor entry on that account, and this section exists to state what was removed and what prevents it from returning.

What was removed, and when. Three loads went to Google on each opening of the application, none of them visible from any screen.

What was sent To Removed on How
The modules of the legacy database service www.gstatic.com 22 August 2026 Together with the code that called them, which had become purposeless
The CanvasKit rendering engine, the largest item at start-up www.gstatic.com 22 August 2026 Produced at build time, served from our own servers
The engine's fallback typefaces, including Roboto fonts.gstatic.com 23 August 2026 Copied to our servers, the engine's source address reconfigured

A fourth recipient left rather than being added. The Google sign-in plug-in, which had remained in the application manifest without any screen using it, caused the browser to load accounts.google.com/gsi/client on every opening, before any screen and before any consent, for a feature that does not exist: identification goes through the Service's own authentication. The dependency was removed on 23 August 2026. Declaring that transfer would have been possible; removing it was right.

What guarantees that this remains so. The fact alone would be no more than a dated observation. The rendering engine reports nothing when a typeface is missing: it displays empty boxes in place of the affected characters, and nobody notices before a User complains about the way their name is written. The addresses of these typefaces, however, carry a version number: an upgrade of the engine calls for others that the copy held by Takion would not contain. An automated check (scripts/sync_font_fallbacks.py --check) is therefore run on every deployment and causes the deployment to fail if a single file is missing. The breakage occurs at Takion, at the point of publication, and not at the User's end.

What has not yet been measured, and therefore remains written down. The origin fonts.gstatic.com remains permitted by the application's content security policy. It had two users: the rendering engine, which no longer calls it, and the stylesheet that the mapping library injects from fonts.googleapis.com, whose rules refer to it. That second use could not be measured, and the permission is maintained rather than withdrawn blindly, because a policy that forbids what is still being called degrades the Service silently. That call, if it exists, can only occur on a map screen, and therefore following an action by the User, and it is covered by point 4.

In other words: Google has not disappeared from this page, it has disappeared from the opening of the application. That is the point that matters for the purposes of Article 5(3) of the ePrivacy Directive, since that is the only moment at which a request goes out before the User has asked for anything.

6. Push notifications

Google Ireland Limited (Firebase Cloud Messaging)

Item Detail
Identity Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Services used Firebase Cloud Messaging (fcm.googleapis.com), and the OAuth 2.0 token service that conditions access to it (oauth2.googleapis.com)
Purpose Delivering to the User's device the notifications they have subscribed to
Categories of data Device token issued by the service, and content of the notification. No practice data, no session content
Who makes the call The server, never the browser: the call originates from the Worker, so the provider does not see the User's IP address at the time of sending. Obtaining the device token, by contrast, takes place on the device
Principal location Google's global network
Transfers outside the EU Possible. Governed by the standard contractual clauses
Documentation firebase.google.com/support/privacy

The trigger is the User, and nothing else. No device token is requested until the User has themselves enabled notifications in their preferences. For as long as they do not, nothing described here occurs.

As at 30 August 2026 the service is dormant. The project identifier and the service account credentials are not configured: the sending code exists and is tested, but no call goes out. The entry appears here because the provider has been selected, and because a list of processors must be up to date before entry into service, not after.

7. Weather

Google Ireland Limited (Google Weather API)

Item Detail
Identity Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Services used Google Weather API, currentConditions:lookup endpoint (weather.googleapis.com)
Purpose Supplying the ballistic calculator with the temperature, pressure and wind at the shooting location
Categories of data Latitude and longitude of the shooting location, rounded to two decimal places (about one kilometre), and nothing else. No user identifier, no user IP address, no altitude
Origin of the call The Gunbix server, never the terminal. See the paragraph below
Principal location Google's global network
Transfers outside the EU Possible. Governed by the standard contractual clauses and the EU-US Data Privacy Framework
Certifications ISO 27001, ISO 27017, ISO 27018, SOC 2/3
Documentation developers.google.com/maps/documentation/weather/policies

This is not an additional processor. Google already appears on this list for mapping (point 4), push notifications (point 6) and Android distribution (point 8). Weather is one further purpose entrusted to the same party, under the same contract, and that is the reason this provider was preferred to the previous one.

Where the call comes from, and what Google sees of it. The call is sent by the Cloudflare Worker, at the request of the application, and not by the User's terminal. Google therefore receives a request coming from a Cloudflare IP address, carrying two coordinates rounded to the kilometre. It receives no identity, no User IP address, no device fingerprint and no session token. Nor does it receive the altitude that the User may enter in the calculator: that value is used for a pressure conversion carried out on our servers and does not leave our infrastructure.

That is the difference from the mapping described at point 4, where the library is loaded by the browser and Google receives the terminal's IP address. The two processing operations are deliberately designed differently, and the list must say so rather than conflating them under a single provider name.

Nothing is written down. The reading is not attached to any session and is stored nowhere: not in the database, not in a file, not in a log. A position, even rounded, says where someone was at a given time; the only way not to build a history of that is not to write it down.

As at 30 August 2026 the feature is switched off (WEATHER_ENABLED="false") and no call goes out. It is described here because the wiring is in place and switching it on will require only a configuration change: the list must say so beforehand, not afterwards.

Open-Meteo, which occupied this point in the French version until version 1.4, has been removed. That provider (Open-Meteo, Zurich, servers in Germany) never received any request from the Service: the feature was never enabled. The code that called it was removed on 23 August 2026. It has never appeared in the English list and is not being added to it.

8. Application distribution

Apple Distribution International Limited

Item Detail
Identity Apple Distribution International Limited, Hollyhill Industrial Estate, Hollyhill, Cork, Ireland
Services used App Store Connect, TestFlight
Purpose Distribution of the iOS application, beta testing
Categories of data Apple ID, anonymised download and crash data
Principal location European Union (Ireland) for European users
Documentation apple.com/legal/privacy

Google Ireland Limited (Google Play)

Item Detail
Identity Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Services used Google Play Console, distribution of the Android application
Purpose Distribution of the Android application, beta testing, crash reports
Categories of data Google Play identifier, anonymised download and crash data
Principal location European Union (Ireland) for European users
Documentation play.google.com/about/privacy

9. Artificial intelligence models (target analysis)

Service self-hosted by Takion

Automatic analysis of target photographs is performed by a proprietary model (YOLOv8) running on infrastructure owned and operated by Takion, reachable through a Cloudflare tunnel. No third-party compute provider is involved and no photograph is transmitted to an external artificial intelligence provider. The analysis is carried out in memory and the result is returned to the User; the photographs are retained only in the Cloudflare R2 object storage bucket, created in the European Union jurisdiction, in accordance with the Privacy Policy.

10. Updating the list

Takion undertakes to update this list before the addition, withdrawal or substantial modification of a processor.

The User may object to a new processor on grounds relating to their particular situation by sending a reasoned email to privacy@takion.be within a reasonable time following publication of the update. If the objection is well founded and objectively prevents use of the Service, Takion will propose an alternative solution or, failing that, will terminate the contract without penalty.

11. Contact

For any question concerning processors: privacy@takion.be.

TAKION SRL Rue Mansart 39/A 7534 Tournai Belgium