Subprocessors and international transfers

The following list applies to the relevant functions; not every provider processes the same data for every Customer. Maildroppa verifies the legal entity, region and transfer mechanism against the actual contract before first use and after a material change.

SubprocessorService and possible dataPrimary locationThird-country mechanism where required
Hetzner Online GmbH, GermanyCore hosting, compute, database and network; Customer Personal Data needed for the serviceGermanyno third-country transfer for regular EEA operations
Cloudflare, Inc., United States, and contracted entitiesDNS, proxy, CDN, WAF, DDoS and security; IP, request, domain, traffic and, for proxied processing, transmitted content dataEU and global edge locations; possible US accessEU-US Data Privacy Framework for certified US recipients and/or SCCs with supplementary safeguards
Amazon Web Services EMEA SARL, Luxembourg, and contracted AWS entitiesObject storage and technical cloud services; files, templates and related metadataprimarily Frankfurt, Germany (eu-central-1); possible global support accessadequacy decision where applicable, otherwise SCCs with supplementary safeguards
Bird B.V., Netherlands, including the SparkPost email platform and service affiliatesEmail transmission, delivery events, bounces and complaints; recipient address, sender, message body and sending metadataSparkPost EU endpoint configured technically; possible support or group access outside the EEAfor third-country access, EU-US Data Privacy Framework where applicable and/or SCCs with supplementary safeguards
Okta, Inc., United States, and contracted Auth0/Okta entitiesAuthentication and account access; account user, login identifier, email, security and session metadataEU region where enabled; possible US accessEU-US Data Privacy Framework for certified recipients and/or SCCs with supplementary safeguards
SmartBear Software, Inc., United States, and affiliates (Bugsnag)Error diagnostics and operational monitoring; pseudonymous account/user identifier, error, device, request and release metadataselected Bugsnag region; possible US accessEU-US Data Privacy Framework for certified recipients and/or SCCs with supplementary safeguards

Auth0/Okta is included in this Schedule only to the extent that it processes Customer Personal Data as a subprocessor in a particular data flow. Maildroppa’s controller processing of account-user data for its own contract, account and authentication purposes is governed by the Privacy Notice and is outside this DPA.

Change notices

Maildroppa informs Customers at the business email address stored in the account and publishes a dated version of this list. The notice identifies the provider, purpose, location, mechanism and intended start date. The objection process is governed by clause 9.

Customer-directed integrations

Zapier, Make and other services connected by Customer are not automatically Maildroppa subprocessors. Where Maildroppa transmits data to such an integration under Customer instruction, Customer is responsible for recipient selection, authority, privacy notices, contracts and international-transfer mechanisms.