Back to Home
Legal · Sub-processors

Sub-processors

Last updated 3 June 2026·Effective 17 June 2026·Version 1.0
Service provider
SMS Bite Limited
trading as SMSBite
5.17/F. Bonham Trade Centre, 50 Bonham Strand
Sheung Wan, Hong Kong
Company Registration N° 78685084

01Purpose and scope

Where SMS Bite Limited processes personal data on behalf of a business customer, the customer is the controller and SMSBite is the processor. A sub-processor is a third party engaged by SMSBite to carry out part of that processing.

This page describes the categories of sub-processor engaged, what each category does, and how a customer obtains the current named list. It supplements the Privacy Policy and the Data Processing Addendum, which is issued with and forms part of every Order Form.

Nothing on this page limits the customer’s own obligations as controller toward the individuals it messages, including the consent and record-keeping obligations in the Anti-Spam & Messaging Compliance Policy.

02How the list is disclosed

The current named sub-processor list is issued on request under a mutual non-disclosure agreement. It gives each sub-processor’s legal name, the processing it performs and the country or countries in which it processes data, and it is maintained as a dated, versioned document so that a customer can point to the version in force on any given date.

Supplier and operator connectivity arrangements are commercially sensitive, and a published map of them is equally useful to anyone probing the platform for abuse routes. Issuing the list under NDA gives customers and their auditors the full detail while keeping it out of general circulation.

Requests go to privacy@smsbite.com and are answered within two business days. A customer whose own compliance programme requires broader disclosure should raise it before signature so that the position can be recorded in the Order Form.

03Categories of sub-processor engaged

The categories below describe the functions for which SMSBite engages sub-processors. Not every category applies to every customer, and the categories in use may change as described in section 05.

Messaging aggregation and operator connectivity
Purpose
Routing submitted messages to the destination mobile network operator and returning delivery receipts.
Data processed
Recipient MSISDN, sender identity, message content and delivery metadata, for the period required to route the message and reconcile the charge.
Cloud infrastructure and hosting
Purpose
Running the platform, the submission API, the customer control plane and the databases that support them.
Data processed
All categories of data processed by the platform, at rest and in transit within the hosting environment.
Network delivery, DNS and edge protection
Purpose
Serving the website and API endpoints, resolving domain names and mitigating denial-of-service and other network attacks.
Data processed
Connection metadata such as IP address, user agent and request headers. Message content is not processed for this purpose.
Backup and disaster recovery storage
Purpose
Holding encrypted backups so the service can be restored after failure or data loss.
Data processed
Encrypted copies of platform data, retained under the schedule in the Privacy Policy.
Business email and customer correspondence
Purpose
Receiving and sending correspondence with customer contacts, including enquiries, notices and support threads.
Data processed
Business contact details and the content of correspondence.
Billing, invoicing and payment processing
Purpose
Issuing invoices and receiving payment from business customers.
Data processed
Business identity and billing contact details, invoice and transaction records. SMSBite does not store full card numbers.
Professional advisers
Purpose
Legal, accounting, tax and audit support where a matter requires it.
Data processed
Only the data relevant to the specific matter, under professional confidentiality obligations.

Message content reaches only the categories that need it to deliver or account for a message. It is not shared for advertising, profiling, model training or any purpose unrelated to providing the service.

04Obtaining the current list

Write to privacy@smsbite.com from a contact associated with your account, or from the address used in your enquiry if you are evaluating the service. Tell us whether you also need the Data Processing Addendum and the international transfer documentation.

  • We aim to respond within two (2) business days. This is a target response window, not a resolution time.
  • Where an NDA is not already in place, we will send one to sign before releasing the list.
  • The list is issued as a dated document so it can be filed against your own processing records.

05Changes and the right to object

Customers receive general written authorisation for sub-processing under the Data Processing Addendum, subject to the notice and objection rights below.

  • We notify account contacts in writing at least thirty (30) days before a new sub-processor begins processing personal data, or before an existing engagement changes materially.
  • A customer may object on reasonable data-protection grounds within that notice period, setting out the grounds in writing to privacy@smsbite.com.
  • Where an objection is raised we will work in good faith to offer an alternative arrangement or configuration. If none is reasonably available, the customer may terminate the affected part of the service without penalty, and any unused pre-paid balance is refunded in accordance with the Refund & Cancellation Policy.
  • Where a change must be made without the full notice period to preserve the security or continuity of the service, we notify as soon as practicable and the objection right still applies.

06Transfers and safeguards

Delivering a message inherently requires transferring the recipient number and message content toward the destination country, so international transfer is a function of the service rather than an optional feature. The transfer mechanisms relied on, and the safeguards applied to them, are set out in the international transfers section of the Privacy Policy.

The processing country for each sub-processor is stated in the list issued under section 04, so a customer can complete its own transfer impact assessment.

07Diligence and flow-down

  • Each sub-processor is engaged under a written contract imposing data-protection obligations no less protective than those SMSBite owes its customers.
  • Engagement is limited to the processing necessary for the function described, on documented instructions, with confidentiality obligations on personnel.
  • SMSBite remains fully liable to the customer for the performance of its sub-processors’ obligations.
  • Diligence is proportionate to the data involved and is performed by SMSBite before engagement and on review. SMSBite’s own technical and organisational measures are set out on the Security page and stand independently of any credential held by a sub-processor.

08Contact

Sub-processor list, Data Processing Addendum, transfer documentation and any other data-protection request: privacy@smsbite.com.

Order Forms, contracts and legal notices: legal@smsbite.com. Full entity details are on the contact & legal entity page.