Syncard

Subprocessors

Version: v2.0
Effective date: 2026-08-13
Last updated: 2026-08-13
Service provider: ObAIoT Information Co., Ltd. (俄巴資訊有限公司, "we", "us")
Contact: support@obaiot.com

This page lists the third-party processors we engage in order to provide Syncard ("the Service"). It is an annex to section 4 of our Privacy Policy and should be read together with it; for the countries data is transferred to, see Privacy Policy section 4.1.

1. Current processors

The processors below may process data only on our instructions and only to the extent necessary to provide their service, and they are bound by confidentiality and security obligations.

CategoryProcessorPurpose and data handled
Cloud infrastructure and storageAmazon Web Services (AWS)Application compute, storage of card images, and system logs
Managed databaseMongoDB AtlasStorage of accounts, cards, contacts and exchange records
Managed cache and job queueUpstashJob queues, temporary storage and one-time verification state
Image text recognition (OCR)Microsoft Azure AI VisionText recognition on card images
Large language model (LLM) routingOpenRouterClassification and structuring of card fields; requests are forwarded to the upstream model provider we specify (currently Anthropic)
Language model for conversational featuresOpenAIGenerating assistant replies and retrieval-based answers; what is sent is the message you type, and may include card fields matched by your query (name, job title, company)
Third-party sign-in (authentication)LINE (LINE Login), GoogleRegistering and signing in with a third-party account
Messaging channelLINE (Messaging API)Sending and receiving messages when you choose to add and interact with our LINE official account
Mobile paymentsLINE PayProcessing payment for paid items
Transactional emailResendSending system notifications such as account-deletion confirmations

2. Third-party AI processing — specific notes

Two entries in the table above — image text recognition and large language model routing — involve sending your card images and the text recognised from them to third-party AI services.

Before you use the scanning feature for the first time and before any image is sent, we explain this on a dedicated screen and obtain your consent; nothing is sent until consent is given. You can withdraw consent at any time. See Privacy Policy section 3.

For the field-classification LLM step, we require upstream model providers not to retain the content and not to train models on it; if no provider meeting those conditions is available, the request fails outright — it is not re-routed to a provider that would retain the content.

3. Standard of protection required

We require the processors above to provide protection for the user data they receive that is the same as or equivalent to what our Privacy Policy sets out; where such protection cannot be provided, we do not share user data with them.

4. Changes

When a processor is added, replaced or removed, we update this page and record the date of the update. For material changes to the scope of data sharing, we also notify you in the manner set out in Privacy Policy section 10.

5. Contact us

If you have any questions about this page or about how we handle data, please contact:


The Traditional Chinese version of this page is the authoritative text. Translations into other languages are provided for convenience only; in the event of any discrepancy between language versions, the Traditional Chinese version prevails.