MASProLegal

Technology & providers

Security and service providers

Last updated: 21 August 2026

This English version is provided for convenience. In case of discrepancies, the German version prevails.

Depends on configuration: Not every service listed here automatically receives data. Many providers are used only if an club selects, connects and uses the function concerned.

Security principles

Service providers and categories of recipients

CategoryProvider / technologyPurpose and use
Infrastructure & storageHetzner; self-hosted Supabase/PostgreSQL and Redis-compatible componentsHosting, database, object storage, cache and platform operations.
Google servicesGoogle Cloud, Drive, Sheets, Gmail, Firebase, Data Manager, GeminiOnly depending on the activated sign-in, file/spreadsheet function, email, push, conversion or AI function.
MicrosoftMicrosoft 365Optional email and account integration.
PaymentsStripe / Stripe ConnectOptional payment processing, merchant onboarding and status reporting.
MessagingMeta/WhatsApp, Bird/MessageBird, Vonage, httpSMS, MessaggioOptional messaging, SMS and delivery functions.
EmailResend, Emailit and connected mailboxesTransactional communication and communication initiated by the customer.
AIOpenAI, Anthropic, Mistral, Google GeminiOnly for activated assistance, generation or analysis functions; inputs should be kept to a minimum.
Documents & postpdfRest, Pingen, OnlineBrief24Optional PDF processing, printing or letter dispatch.
BankingBanksAPI, NevloOptional account transaction and reconciliation functions.
Maps & error analysisMapbox, SentryOptional map/location display and technical error diagnostics.

Depending on the product, the contracting party and the region, a provider may itself act as a controller or as a processor. Details follow from its documentation, the customer configuration and the specific instructions. Material changes to this overview are published here.

Responsible use

Clubs should activate only the integrations they need, review permissions regularly, avoid special categories of personal data or protect them with particular care, and disconnect connections that are no longer required.

Security contact

Confidential reports: office@pock.biz. Please also see our vulnerability disclosure policy.