Schedule 3 — Approved Sub-processors
Effective as of the date of this DPA.
A Sub-processor is a third party we engage to process Customer Personal Data on our behalf in connection with the Platform Service. The list below covers entities that act on our instruction. Identity providers used for Controller user authentication (Google, Microsoft, Apple, etc.), source-code hosts the Controller connects (GitHub, GitLab, Bitbucket), and infrastructure providers the Controller chooses for its own environments (AWS, Google Cloud, Hetzner, DigitalOcean, Linode, OVH, etc.) are NOT our Sub-processors: they act on the Controller's own instruction or on the Data Subject's instruction, and the Controller maintains its own data processing relationship with them.
| Sub-processor | Purpose | Location of processing | Transfer mechanism |
|---|---|---|---|
| Hetzner Online GmbH | Compute and storage for the platform control plane | Germany (Falkenstein / Nuremberg / Helsinki) | GDPR-internal — EU controller-processor |
| DigitalOcean, LLC | Compute and storage for platform supporting infrastructure, including a network relay for platform SSH connections to certain customer servers (where applicable; not for Controller-designated customer environments) | US, with EU regions where used | SCCs |
| Cloudflare, Inc. | DNS, WAF, CDN, DDoS mitigation, TLS termination for the platform admin console and for customer domains connected via the platform's CNAME target (see Schedule 2.2) | US, with global edge | SCCs |
| Stripe, Inc. | Billing and payment processing for the Platform Service subscription | US, with EU entities for European customers | SCCs |
| Mailgun Technologies, Inc. | Transactional email delivery (account, billing, system notifications) | US | SCCs |
| Functional Software, Inc. (Sentry) | Application error monitoring of the Platform Service control plane. Error reports identify the signed-in platform user by an internal account ID only (no email address or name); credentials and other secrets are scrubbed before transmission (the scrubbing scheme is described in the Internal Controls Description, §6.6) | US | SCCs |
| PostHog Inc. | Product analytics on the Platform Service admin console (Controller user actions; no Customer Personal Data inside Controller environments) | US | SCCs |
| Let's Encrypt (Internet Security Research Group) | Automated SSL certificate issuance for platform domains and customer subdomains using public-key infrastructure | US | N/A — no Personal Data transferred |
Not in scope (these are not our Sub-processors under this DPA):
- Controller-designated cloud providers for Controller environments (e.g., AWS for an environment the Controller chose to provision on AWS). The Controller engages these providers directly and maintains the data processing relationship with them. We orchestrate, but do not process on the Controller's behalf at the storage layer for the Controller's own infrastructure.
- Identity providers used by Controller users to sign in to the admin console (Google, Microsoft, Apple, passkey providers). These authenticate the user on the user's own behalf, not on our instruction.
- Source-code hosts the Controller chooses to connect for environment deployments (GitHub, GitLab, Bitbucket). The Controller's git connection is a direct relationship between the Controller and the host.
Updates to this list are governed by clause 6 of this DPA.