Sub-processors

Who I share data with — and under what mechanism.

This page lists every third-party processor that touches personal data on philipsloth.com. Each is engaged under a Data Processing Agreement (DPA) and operates as a processor on my behalf — not an independent controller. If a vendor is added, removed, or substantively changed, the change-log at the bottom of this page records it on the date it took effect.

Current sub-processors

VendorRoleRegionTransfer mechanismDPA
Stripe
Stripe Payments Europe Ltd, Ireland; Stripe Inc., USA
Payment processing — card auth, charge, refund, dispute evidence, hosted receipt pages.EEA + USAEU-US Data Privacy Framework + Standard Contractual Clauses (SCCs)DPA →
Resend
Resend Inc., USA
Transactional email — contact-form replies, payment receipts, GDPR rights-request responses.USAEU-US Data Privacy Framework + Standard Contractual Clauses (SCCs)DPA →
Hetzner
Hetzner Online GmbH, Germany
Cloud server (Nuremberg) hosting the self-managed backend: PostgreSQL database + GoTrue authentication + API + backend services (contact, checkout, analytics) with Row-Level-Security. Stores: contact form submissions, payment_links rows, business_settings, admin_allowlist, analytics events.EU (Nuremberg, Germany)None — data resides in Germany (EU); no third-country transfer.DPA →
Cloudflare
Cloudflare Inc., USA
Hosting (Pages), DDoS protection, DNS, R2 object storage (encrypted backups). Logs: country, request path, user-agent (no IP retention beyond 7 days at edge).Global edge network — request handled by nearest PoPEU-US Data Privacy Framework + Standard Contractual Clauses (SCCs)DPA →

International transfers

Some sub-processors are established in the United States. Transfers from the EU to those vendors are made under the EU-US Data Privacy Framework (in force since 10 July 2023), supplemented by Standard Contractual Clauses (Article 46 GDPR) where required. A copy of the SCCs in force for any specific transfer is available on request.

The Data Privacy Framework is currently the subject of legal challenge (Schrems III, pending before the Court of Justice of the European Union). If the framework is invalidated, the SCC fallback applies and I will assess whether additional safeguards are required for each transfer.

Change-log

Material changes to this list are recorded here. Active engagements affected by an addition or change are also notified by email under GDPR Art. 28(2).

  • 2026-07-15 · added
    Hetzner Online GmbH
    Backend migrated to a self-managed server (PostgreSQL + GoTrue + backend services) hosted by Hetzner in Nuremberg, Germany (EU). Replaces Supabase as the database/auth processor.
  • 2026-07-15 · removed
    Supabase Inc.
    Database, authentication, and analytics storage migrated off Supabase to the self-managed Hetzner server; Supabase no longer processes any personal data for philipsloth.com.
  • 2026-05-01 · added
    (initial publication)
    Page published. Pre-existing sub-processors (Stripe, Resend, Supabase, Cloudflare) were already disclosed in the inline privacy-notice table; this dedicated page is now the canonical list.

Contact

Questions about a specific sub-processor or the transfer mechanisms — email philipsloth1@gmail.com. Requests for a copy of a specific DPA or SCC are also handled at this address.

← Back to home·Privacy·Terms·Payment terms·Cookies·Last updated: 2026-05-03