Subprocessor list

Third parties that process personal data on our behalf (GDPR Art. 28). A change to this list flows through to the privacy policy.

ProviderCountry / regionPurpose of processingTransfer mechanismDPA
RenderUnited States (Frankfurt deployment region)Backend API hosting + Postgres databaseSCC (EU Standard Contractual Clauses)DPA
Cloudflare R2European Union regionUploaded production file storage (e.g. DXF, STL) + invoice PDFsEU region — no cross-border transferDPA
Cloudflare TurnstileUnited States (global edge network)Signup form bot protection — visitor IP address and technical dataSCCDPA
StripeIreland (data centre) / United States (parent)Payment processing + receipt issuanceSCC + EU-US Data Privacy FrameworkDPA
ResendUnited StatesTransactional email delivery (magic-link, receipts)SCCDPA
GoogleIreland (Google Ireland) / United States (parent)Sign in with Google when the user chooses it (identity provider — acts as an independent controller)SCC + EU-US Data Privacy FrameworkDPA
SentryUnited StatesError monitoring (gated by analytics consent — see /privacy)SCCDPA
Better StackUnited StatesUptime monitoring, public status page + incident records (operational data and status-page visitor technical data)SCC + EU-US Data Privacy FrameworkDPA
VercelUnited StatesFrontend (storefront, admin) hosting + edge cacheSCC + EU-US Data Privacy FrameworkDPA
ARES (CZ public registry)Czech RepublicCompany-data lookup by IČO (public registry — not a processor)Public registry; no PII transferDPA

Last updated 2026-09-06