Skip to content

Draft — pending legal review. This document is a working draft and is not yet in force. Wording, placeholders in square brackets and commitments may change before publication.

Sub-processors

Last updated

Effective date: [effective date]

1. What this page is

To run the Service we use a small number of third-party providers. Where such a provider processes personal data on our behalf, it is a sub-processor under Article 28 GDPR and under our Data Processing Agreement with each Customer. This page lists those providers so that customers can assess them before they start using the Service and stay informed about changes.

The list covers providers that may handle Customer Content as well as providers that support our own operations, such as billing or internal e-mail, which the Privacy Policy describes. Not every provider receives Customer Content: the "Data" column shows what each one actually processes.

2. Current sub-processors

Sub-processorPurposeDataLocation
Amazon Web Services EMEA SARLHosting (control plane, data planes, storage)All service dataEU (Frankfurt); US (N. Virginia), Singapore or Australia only for workspaces using those regions
Cloudflare, Inc.CDN, WAF, DNS, Workers (signed URLs), TurnstileRequest metadata, cached public filesGlobal edge (EU-only caching option via the Cloudflare Data Localization Suite for Enterprise)
Stripe Payments Europe, Ltd.Payment processing and subscription management under Stripe Managed PaymentsBilling contacts, payment dataEU/US
Link (by Stripe) — contracting entity to be confirmed [Sold through Link, LLC]Merchant of record for payments under Stripe Managed Payments: checkout, receipts and invoices, VAT and sales tax, refunds, disputes and payment supportBilling name, address and e-mail, tax ID, payment method, purchase and subscription recordsUS/EU [to be confirmed]
Sendinblue SAS (Brevo)Transactional e-mailE-mail addresses, e-mail contentEU (France)
PostHog (EU Cloud)Product analyticsPseudonymous usage eventsEU
Functional Software (Sentry, EU region)Error monitoringStack traces (personal data scrubbed)EU
Plain or Crisp — to be confirmedCustomer supportSupport conversationsEU
Google WorkspaceInternal e-mail and documentsCustomer communicationsEU/US
Vanta or Drata — to be confirmedCompliance automationEmployee and system metadataUS/EU
AI model provider, for example Anthropic via AWS Bedrock EU — to be confirmedTemplate generationPrompts, uploaded sample documentsEU region where available

Last changed: [effective date] — first publication of this list.

3. How to read the list

  • To be confirmed marks a decision we have not finalised. Where two providers are named, we will publish the chosen one before launch, and any later change follows the notice process in section 6.
  • Regions. Hosting providers process data only in the regions a workspace actually uses. A workspace that stays in the EU region has its render payloads and generated files processed in the EU; the EU control plane always holds account data, templates and configuration.
  • Opt-in features. The AI model provider is used only for AI-assisted features, which are switched off by default and enabled per Workspace. If a workspace never enables them, no data reaches that provider. We do not allow Customer Content to be used to train models.
  • Payments. Under Stripe Managed Payments, Link (by Stripe) is the merchant of record for payments: customers enter their billing details, tax ID and payment method at Stripe Checkout, and Link issues receipts and invoices and collects and remits VAT or sales tax. We receive only limited billing data from Stripe, as described in the Privacy Policy. [Counsel: confirm whether Link belongs on this list as a sub-processor or is named as an independent recipient.]
  • Support and internal tools. Providers for support, internal e-mail and compliance automation see Customer Content only if a customer sends it to us, for example as an attachment in a support conversation.

4. Third parties you choose yourself

Services that a customer connects to the Service are not our sub-processors, because we do not control them and only send data on the customer's instruction. This includes storage destinations such as the customer's own object storage buckets, webhook endpoints, automation platforms and other integrations, and image sources the customer queries. The customer is responsible for its own agreements with those providers. The same applies to any website rendered from a URL.

5. How we select and monitor sub-processors

Before a provider is added, we assess what data it would receive, where it processes that data, its security posture and its certifications, and we conclude a data processing agreement with Article 28 terms. Transfers outside the EEA are covered by an adequacy decision or the Standard Contractual Clauses, with the UK addendum or Swiss amendments where those laws apply, as described in section 12 of the DPA. We review the list at least once a year and whenever a provider materially changes its service, and we prefer providers that can process data inside the EU.

6. Changes and your right to object

We give at least 30 days' notice before a new sub-processor starts processing Customer Personal Data. The notice is published here and sent to subscribers.

During the notice period, a customer may object on reasonable data protection grounds by writing to privacy@dynamicdocumentapi.com. We will then look for a workable solution, for example a different configuration or region. If no solution is found, the customer may terminate the affected part of the Service before the change takes effect. The full process is in section 7 of the DPA.

Replacing a sub-processor with another provider for the same purpose, or adding a provider for a new optional feature, follows the same notice period.

7. Subscribe to change notices

To receive notices by e-mail, write to privacy@dynamicdocumentapi.com with the subject "sub-processor updates" and the workspace the subscription is for. [A self-service subscription form and a feed are planned; the address above is the interim channel.] We also publish the current version of this page with its change log, so the history stays visible.

8. Change log

DateChange
[effective date]First publication of the sub-processor list.

9. Questions

Write to privacy@dynamicdocumentapi.com for questions about a provider, a copy of the transfer safeguards we rely on, or a security review package. Sales questions about regional processing options go to sales@dynamicdocumentapi.com.