Legal Document

Service Providers

The complete current list of third-party service providers used by Aika Lab to deliver our Services, including what data is shared with each, where it is processed, and what safeguards apply.

Last updated: April 18, 2026 Reviewed: Quarterly, or upon any change Authority: Aika Lab (AI Player in Gothenburg, org. nr. 571121-3230)

This page is the authoritative source for our list of third-party service providers, as referenced in Section 6 of our Privacy Policy. We maintain this page so that you always have access to the current state of our data processing relationships, even if our Privacy Policy is between updates.

Each provider listed below has signed a Data Processing Agreement (DPA) with Aika Lab consistent with the requirements of GDPR Article 28, where applicable. Providers process your personal data only on our documented instructions and are bound by appropriate confidentiality and security obligations.

Current Providers

Google Cloud Platform

Infrastructure
Purpose
Server hosting, database (Firestore), serverless backend (Cloud Run), secret management (Secret Manager), object storage
Data shared
All server-side data including account information, subscription records, anonymized EEG data, session metadata, technical logs
Primary region
Frankfurt (europe-west3); other GCP regions used for backup and disaster recovery
Provider entity
Google Ireland Limited (for EU customers); Google LLC (for backend infrastructure in the United States)
Transfer safeguard
EU Standard Contractual Clauses (SCCs); EU-U.S. Data Privacy Framework certification

Google Sign-In SDK

Authentication
Purpose
Optional third-party login (when you choose to register or sign in with your Google account)
Data shared
Your Google account ID, email address, profile photo (only when you actively initiate Google Sign-In)
Provider entity
Google LLC, USA
Transfer safeguard
EU-U.S. Data Privacy Framework
Provider policy
Optional?
Yes — Google Sign-In is one of two registration methods. You may choose phone-number registration instead, in which case Google receives no data from us.

Stripe

Payments — Web Store
Purpose
Processing payments for physical accessories (such as compatible BCI hardware) purchased through our website at aikalab.se/market
Data shared
Transaction details, billing address, shipping address, email address. We do not see or store your card numbers — Stripe handles all card data directly.
Provider entity
Stripe Payments Europe Limited (Ireland) for EU customers; Stripe, Inc. (USA) for backend processing
Transfer safeguard
EU-U.S. Data Privacy Framework; Stripe's Data Processing Agreement
Provider policy

Flexolink AI

BCI Hardware SDK
Purpose
Software Development Kit (SDK) for Bluetooth communication with compatible Flexolink EEG devices (e.g., FLEX-BM05BF)
Data shared
Bluetooth device pairing data is exchanged locally on your device. EEG signal data is processed on-device and uploaded only to Aika Lab's own servers (Google Cloud Platform), not to Flexolink's servers. Flexolink does not receive your EEG data.
Provider entity
Flexolink AI (China)
Transfer safeguard
N/A — no personal data is transmitted to Flexolink. The SDK runs locally on your device.
Important note
Because the SDK is software running on your device, it has access to your EEG signal stream. We have audited the SDK's network behavior to confirm that EEG data is not transmitted to Flexolink. We will continue to monitor this in future SDK versions.

Our Operating Principles

Questions

If you have questions about any provider listed here, or wish to exercise your rights regarding data processed by them, please contact us at hello@aikalab.se. We will respond within 30 days as required by GDPR Article 12.