Subprocessors
DRAFT — NOT YET IN FORCE. This list is assembled from the codebase and DNS records. It must be checked against actual contracts and running configuration before publication. An incomplete subprocessor list is a contractual breach with any customer who has signed a DPA.
A subprocessor is a third party that processes personal data on our behalf. We require each of them to be bound by written terms no less protective than our own commitments.
Current subprocessors
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Stripe | payment processing, subscription billing | name, email, billing address, card data (never held by us) | US, EU |
| Bunny CDN | content delivery | IP address, request metadata | global edge |
| Forward Email | inbound mail routing for our domains | email content, sender and recipient addresses | [VERIFY] |
| Amazon Web Services | object storage, supporting services | varies by service | US |
| OpenRouter | AI model routing for specific features | prompt content submitted to the feature | [VERIFY: which products, and is any personal data included?] |
[VERIFY: the following appear in code or configuration and need a decision on whether they are current, retired, or never used in production — Neon (serverless Postgres, appears migrated away from), Oracle Cloud Infrastructure (four domains still resolve to OCI addresses despite the migration), HashiCorp Vault, Cloudflare.]
Infrastructure we run ourselves
These are not subprocessors because no third party processes data:
- Private bare-metal servers — all primary application hosting
- Authentik — identity and single sign-on, self-hosted
- PostgreSQL — self-hosted, one database per service
- Traefik and nginx — reverse proxy and TLS termination
msgs.globalmail relays — self-hosted outbound mail
Self-hosting these is deliberate. It means your authentication data and your application data do not leave our infrastructure.
Changes
We will post new subprocessors here before they start processing. Customers with a signed Data Processing Agreement can subscribe to change notices by emailing privacy@afterdarksys.com, and may object to a new subprocessor on reasonable data protection grounds.
[VERIFY: this commits us to advance notice. Confirm the notice period — 30 days is common — and that a mechanism exists to actually send it.]