Sub-processors
Last updated: July 22, 2026
This is the authoritative register of the sub-processors Developer Friendly OÜ engages to process personal data on behalf of customers in delivering DMARCguard. Our Privacy Policy, our Data Processing Agreement ("DPA"), and our Security Overview all refer to this page. We give 30 days' prior notice of any intended addition or replacement of a sub-processor under the DPA, by email to your account owner; you may object on reasonable data-protection grounds within 15 business days (Estonian working days) of the notice.
| Sub-processor | Entity / location | Purpose | Transfer basis |
|---|---|---|---|
| Hetzner Online GmbH | Germany (EU) | Hosting and compute | Within EU |
| Cloudflare, Inc. | USA — global edge network; customer data stored at our EU origin | CDN, DNS, edge proxy | SCCs (EU–US DPF as supplementary measure) |
| Amazon Web Services | Frankfurt (EU) — US parent | Encrypted secrets storage | Within EU (SCCs for any US access; DPF supplementary) |
| Wasabi Technologies | Frankfurt + Amsterdam (EU) — US entity | Encrypted offsite backups | Within EU (SCCs) |
| PostHog, Inc. | USA — EU-hosted instance | Product analytics | EU hosting; SCCs (DPF supplementary) |
| AhaSend B.V. | Amsterdam, Netherlands (EU) | Transactional email delivery | Within EU |
| Crisp IM SAS | France (EU) | Customer support chat (in-app) | Within EU |
| AbuseIPDB (Marathon Studios, Inc.) | USA | IP abuse-reputation lookups | Strict data minimization — only the bare IP address being checked is transmitted, never names, emails, or customer identifiers; formal SCC coverage is being pursued with the vendor |
Independent controllers (not sub-processors)
Polar Software, Inc. (Delaware, USA) is our merchant of record: when you purchase a paid plan, you buy from Polar under its own buyer terms, and Polar processes payment-related personal data as an independent controller under its own privacy policy (EU–US DPF and/or SCCs for its transfers). We receive billing and subscription metadata only.
Services that process no personal data
- IP geolocation databases — the databases run on our own infrastructure; no personal data is transmitted to the database providers.
- Instatus — hosts our public status page, which publishes only our own service-status information; we have no status-page subscriber notifications enabled, so no customer personal data is processed.
- Inbound report mail — self-hosted on our own EU infrastructure.
- Monitoring — self-operated EU infrastructure; endpoints are private and access-controlled.
- GitHub-hosted CI — builds and tests the software; no customer personal data flows through the build pipeline.
Questions
Data-protection enquiries: [email protected]. A signed DPA is available on request at [email protected].