Legal
Sub-processors
Draft — not yet in force. The table below is the intended set of providers taken from our infrastructure planning. Before this page goes live it has to list exactly the providers that are actually in use — no more, no fewer. A published sub-processor list that does not match reality breaks the DPA it is annexed to.
These are the companies that process data on our behalf so that the Service can run. We vet each one before it starts, bind it to data protection obligations no less protective than our own, and stay liable to you for what it does.
Platform and storage
| Provider | Purpose | Data | Location |
|---|---|---|---|
| [TO CONFIRM] Amazon Web Services EMEA SARL | Hosting, compute, object storage, databases | All service data, including Customer Content | EU (Frankfurt); United States only for workspaces on the US region |
| [TO CONFIRM] Cloudflare, Inc. | DNS, CDN, web application firewall, signed file URLs, bot protection | Request metadata, cached public files | Global edge network |
Payments
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Stripe [TO CONFIRM: entity] | Merchant of record: checkout, invoicing, tax, chargebacks. Stripe is your seller, not only our processor — see Terms, section 4 | Billing contact, purchase and tax data. We never receive card numbers | EU / United States |
Operations, support and monitoring
| Provider | Purpose | Data | Location |
|---|---|---|---|
| [TO CONFIRM] Transactional email provider | Account, billing and system email | Email address, message content | [EU?] |
| [TO CONFIRM] Error monitoring | Crash reports and stack traces, with personal data scrubbed | Technical diagnostics | [EU region?] |
| [TO CONFIRM] Product analytics | Which features are used, where things break | Pseudonymous usage events | [EU region?] |
| [TO CONFIRM] Support desk | Answering support requests | Support conversations and attachments | [EU?] |
How we announce changes
Before a new sub-processor starts processing Customer Personal Data, we publish it here and notify subscribers at least [TO CONFIRM: 30] days in advance. To be notified, write to privacy@dynamicdocumentapi.com with “subscribe sub-processors” in the subject [TO CONFIRM: build a proper subscription — a mailbox rule is not a process]. You may object on reasonable data protection grounds; section 7 of the DPA says what happens then.
Not sub-processors
Providers that never touch Customer Personal Data are not listed here: for example the domain registrar, our own accounting software, or tools used purely internally. Changes to those do not trigger a notice.
Change history
| Version | Date | Change |
|---|---|---|
| 0.1 | 23 September 2026 | First draft from infrastructure planning, pending confirmation of the actual stack |