Draft — to be reviewed by counsel before publication
Subprocessors
Draft list for MB Tobuli. Contact [Contact email]. Company code [Company code]. Address [Registered address]. VAT [VAT number]. Counsel confirms every row before publication. "To confirm" means this repository does not show the integration as live.
The email service keeps message content, recipient addresses, and event payloads in eu-central-1. That Region lock is separate from the EEA transfer rule.
A party in another EU country does not by itself need a transfer tool. It still must not receive those fields. A party outside the EEA needs a transfer tool before it processes personal data. The tool is to confirm by counsel. See the Data processing agreement.
| Party | What it processes | Where | When it applies |
|---|---|---|---|
| Amazon Web Services | Compute for the API and workers. Database for the tables in this service. Email sending through Amazon SES. Queue and event notification. A private bucket is defined for raw MIME and is not written by the current binary. Send-admission counters in ElastiCache Serverless Valkey. A counter key holds a tenant id. It holds no message content, recipient address, or event payload. | eu-central-1 for the resources this repository defines, including the Valkey cache. | Email service. Compute, the database, the cache, the queue, SES configuration, and the bucket are defined in Terraform. Applying that configuration to a live account is to confirm at launch. |
| Cloudflare | Public site and optional cookieless site analytics. When the dashboard sign-in bot check is configured, the challenge token and the signals named in the Turnstile Privacy Addendum (accessed 2026-10-07): client IP address, TLS fingerprint, User-Agent, site key, and the site key's origin. Cloudflare is the processor for providing the check and the controller for improving detection, as that addendum states. No message content. | To confirm. | The marketing site is a Cloudflare Worker configured in this repository. The Worker serves sendtier.com through a Workers custom domain. Cookieless analytics loads only when a beacon token is set. It does not use the Google consent grant. Customer DNS setup through Cloudflare is a different feature and is not this row. The dashboard check applies only when its site key and secret are both set. The addendum does not name a cookie. It points to Cloudflare's cookie policy and the Turnstile docs. |
| Grafana Labs | Operational metrics, dashboards, alerts, and synthetic checks. It does not receive message content, recipient addresses, or event payloads. | The Grafana module targets a Grafana Cloud stack in AWS eu-central-1. See ADR-0025 (docs/adr/0025-grafana-as-code.md). Applying the module is to confirm at launch. | The module is in this repository. It is separate from the CloudWatch alarms. |
| Analytics and advertising measurement on public marketing and documentation pages. | To confirm. The transfer tool is to confirm by counsel. | Public marketing and documentation pages only. Analytics loads only after the analytics grant and only when a measurement id is set. Advertising measurement loads only after the advertising grant and only when an ads id is set. The tags are in this repository. See the Cookie policy. | |
| Stripe | Billing and payment data. Stripe is a separate controller or processor for that data. It is not a subprocessor for message content. | To confirm. The transfer mechanism is to confirm by counsel. | Only when billing is enabled. Billing is not integrated. |
Stripe transfer
The Stripe data-transfer addendum, page dated 2025-11-18, describes the Data Privacy Framework and standard contractual clauses toward Stripe, LLC. Counsel confirms the tool. This draft does not say we have signed it. Do not send message bodies, recipient lists, or event payloads to Stripe.
Changes
Counsel posts a dated change to this list before a new party processes personal data. The notice period is to confirm by counsel.