Sub-processors
Every third party that may process personal data on behalf of CheckFox, what it is used for, and where the data sits.
This page is Annex 3 of the Data Processing Agreement. It is published so that you can complete your own Article 30 record without having to ask me, and so that you can check each provider's commitments for yourself: every name below links to that provider's own data protection terms.
1. Current sub-processors
These providers take part in running the service for every customer. Each one is bound by a data processing agreement and may act only on my instructions.
| Provider | Legal entity | Purpose | Data location | Transfer safeguard |
|---|---|---|---|---|
| Supabase | Supabase, Inc. (United States) | Database, authentication, file storage and application backend | Stockholm, Sweden (AWS eu-north-1) | Standard contractual clauses |
| Amazon Web Services | Amazon Web Services EMEA SARL (Luxembourg) | Underlying infrastructure for the database provider | Stockholm, Sweden (eu-north-1) | Processing within the EEA |
| OVHcloud | OVH SAS (France) | Hosting of the website and of the origin server | France | Processing within the EEA |
| Cloudflare | Cloudflare, Inc. (United States) | Content delivery, DNS and protection against attacks | Global edge network, EU points of presence | Standard contractual clauses and Data Privacy Framework |
| Stripe | Stripe Payments Europe, Ltd. (Ireland) | Payment processing and subscription management | European Union and United States | Standard contractual clauses and Data Privacy Framework |
| Resend | Resend, Inc. (United States) | Delivery of transactional email (sign-up, invitations, notifications) | United States | Standard contractual clauses |
| Anthropic | Anthropic PBC (United States) | AI assistance features, when you use them; content is not used for training | United States | Standard contractual clauses |
| Browserless | Browserless Inc. (United States) | Headless browser used to run automated accessibility scans | European Union | Standard contractual clauses |
| Umami Cloud | Umami Software, Inc. (United States) | Cookieless audience measurement on public pages; no IP address is stored | European Union | Standard contractual clauses |
2. Integrations you choose to connect
These receive data only if you connect the integration and send something to it, for example when you push an audit issue to a tracker. Doing so is an instruction from you as controller. If you never connect them, they never receive anything.
| Provider | Legal entity | Purpose | Data location | Transfer safeguard |
|---|---|---|---|---|
| GitHub | GitHub, Inc. (United States) | Creating issues in your repository when you push audit findings | United States | Standard contractual clauses and Data Privacy Framework |
| Atlassian (Jira) | Atlassian Pty Ltd (Australia) | Creating issues in your Jira project when you push audit findings | Customer's Atlassian region | Standard contractual clauses |
| Linear | Linear Orbit, Inc. (United States) | Creating issues in your Linear workspace when you push audit findings | United States | Standard contractual clauses |
3. How changes are announced
Before a new sub-processor begins processing customer data, it is added to this page and announced to customers at least 30 days in advance, in accordance with section 6 of the Data Processing Agreement.
During that period you may object on reasonable, data-protection grounds. If no arrangement can be found that removes the objection, you may terminate the affected subscription and be refunded for the unused period.
Removing a provider, or narrowing what one is used for, does not require notice.
4. Getting notified
Account holders are notified by email. If you are a data protection officer who needs the notice without holding an account, write to the address below and I will add you to the list.
Printed from checkfox.eu. Check the site for the current version.