Subprocessors and international transfers
The following list applies to the relevant functions; not every provider processes the same data for every Customer. Maildroppa verifies the legal entity, region and transfer mechanism against the actual contract before first use and after a material change.
| Subprocessor | Service and possible data | Primary location | Third-country mechanism where required |
|---|---|---|---|
| Hetzner Online GmbH, Germany | Core hosting, compute, database and network; Customer Personal Data needed for the service | Germany | no third-country transfer for regular EEA operations |
| Cloudflare, Inc., United States, and contracted entities | DNS, proxy, CDN, WAF, DDoS and security; IP, request, domain, traffic and, for proxied processing, transmitted content data | EU and global edge locations; possible US access | EU-US Data Privacy Framework for certified US recipients and/or SCCs with supplementary safeguards |
| Amazon Web Services EMEA SARL, Luxembourg, and contracted AWS entities | Object storage and technical cloud services; files, templates and related metadata | primarily Frankfurt, Germany (eu-central-1); possible global support access | adequacy decision where applicable, otherwise SCCs with supplementary safeguards |
| Bird B.V., Netherlands, including the SparkPost email platform and service affiliates | Email transmission, delivery events, bounces and complaints; recipient address, sender, message body and sending metadata | SparkPost EU endpoint configured technically; possible support or group access outside the EEA | for third-country access, EU-US Data Privacy Framework where applicable and/or SCCs with supplementary safeguards |
| Okta, Inc., United States, and contracted Auth0/Okta entities | Authentication and account access; account user, login identifier, email, security and session metadata | EU region where enabled; possible US access | EU-US Data Privacy Framework for certified recipients and/or SCCs with supplementary safeguards |
| SmartBear Software, Inc., United States, and affiliates (Bugsnag) | Error diagnostics and operational monitoring; pseudonymous account/user identifier, error, device, request and release metadata | selected Bugsnag region; possible US access | EU-US Data Privacy Framework for certified recipients and/or SCCs with supplementary safeguards |
Auth0/Okta is included in this Schedule only to the extent that it processes Customer Personal Data as a subprocessor in a particular data flow. Maildroppa’s controller processing of account-user data for its own contract, account and authentication purposes is governed by the Privacy Notice and is outside this DPA.
Change notices
Maildroppa informs Customers at the business email address stored in the account and publishes a dated version of this list. The notice identifies the provider, purpose, location, mechanism and intended start date. The objection process is governed by clause 9.
Customer-directed integrations
Zapier, Make and other services connected by Customer are not automatically Maildroppa subprocessors. Where Maildroppa transmits data to such an integration under Customer instruction, Customer is responsible for recipient selection, authority, privacy notices, contracts and international-transfer mechanisms.