[01]Last updated 21 August 2026
Sub-processors
Every third party that touches customer data, and what each one does.
This list is complete. Changes are announced 30 days before they take effect, and workspace owners are emailed. If you object to a new sub-processor within that window, you may terminate without penalty.
| Sub-processor | Service | Data touched | Location |
|---|---|---|---|
| Amazon Web Services | Outbound email delivery (SES), key management (KMS) | Message content in transit, recipient addresses in transit | eu-central-1, Germany |
| Cloudflare | DNS, WAF, CDN, R2 object storage, tracking worker | Encrypted message bodies and attachments, tracking events | EU jurisdiction |
| Hetzner Online | Compute, PostgreSQL, ClickHouse, mail node | All platform data | Falkenstein and Helsinki |
| Stripe | Subscription billing and metered usage | Customer billing data only — never recipient data | EU and US, SCCs |
| MaxMind | GeoIP2 database licence | None. The database is a local file; no lookup leaves our infrastructure | Licence only |
| Sentry (self-hosted) | Error tracking | Request ids and stack traces, with PII scrubbing and an email deny-list | EU |
What is deliberately not on this list
No third-party analytics on the dashboard, no session-replay tool, no per-request geolocation API, no marketing pixel on any page that handles customer data. Each of those would have been convenient and each would have meant a transfer we do not need to make.