Subprocessor Register
Who receives personal data because of something you do with us, which of them act on our instruction, and what changed and when.
Summary
This page exists so a change to the list has an address. It carries 15 recipients and a dated log of every change we hold a record of. 12 of them process personal data on our documented instruction and are subprocessors. 3 receive personal data without acting on our instruction, so calling them subprocessors would tell you we control what they do with it, and we do not. Section 03 of the Privacy Policy remains the authoritative list; this register renders the same declaration and adds the history.
What this register is
A subprocessor is a party that processes personal data on our documented instruction so that we can deliver something you asked for. GDPR Article 28(2) lets a controller give a general written authorisation for us to engage them, on condition that we inform the controller of an intended addition or replacement and give it a chance to object. This page is where that information is published.
The two tables below are rendered from a single declaration in our codebase, the same one that produces the Trust Center and the connector permission inventory. None of it is retyped here. An automated check fails our build when that declaration and section 03 of the Privacy Policy name different parties.
This is a transparency notice, not a contract. It does not vary the Terms of Service, the Privacy Policy, or any Data Processing Agreement we have signed with you. Where a signed agreement and this page differ, the signed agreement governs.
Who publishes it
Michal Jatczak T/A ITSailor, a sole trader registered in Malta, VAT MT32760411, of Level 1, Unit 60, Door No 63, Connecticlub Business Center, Triq Il-Ballut (Zona Industrijali, Mosta), MST 4001, Mosta, Malta. We are the controller for the personal data described in the Privacy Policy, and the processor for personal data you instruct us to process in your own systems.
Subprocessors we instruct
These parties process personal data on our instruction. Where data leaves the EEA we rely on the European Commission Standard Contractual Clauses (Implementing Decision (EU) 2021/914), and additionally on the EU-US Data Privacy Framework (Implementing Decision (EU) 2023/1795) where the recipient self-certifies under it. Section 04 of the Privacy Policy sets out the transfer position in full.
| Recipient | What it does with the data | Established in | Processing location | Transfer basis |
|---|---|---|---|---|
| Stripe Payments Europe Ltd. | Our processor for executing payments, subscription charges and refunds on our instruction. Independent controller for fraud prevention, financial and security risk, AML and KYC obligations, and developing its own products | Ireland (EEA) | Ireland, inside the EEA, with routing to Stripe group entities outside the EEA | Standard Contractual Clauses (EU) 2021/914 for any routing outside the EEA; Stripe also self-certifies under the EU-US Data Privacy Framework. |
| Resend, Inc. | Transactional email delivery | United States | United States, outside the EEA | EU-US Data Privacy Framework, with the Standard Contractual Clauses (EU) 2021/914 in place regardless. |
| Upstash, Inc. | Managed storage for newsletter and rate-limit state | United States | United States, outside the EEA | Data processing addendum and the Standard Contractual Clauses (EU) 2021/914. No framework listing is claimed. |
| Hetzner Online GmbH | Production server hosting and backups | Germany (EEA) | Falkenstein, Germany, inside the EEA | None needed. The processing does not leave the EEA. |
| Cloudflare, Inc. | DNS, CDN, and Zero Trust Tunnel | United States | A global edge network outside the EEA; EU traffic is served from EU edge nodes | EU-US Data Privacy Framework, with the Standard Contractual Clauses (EU) 2021/914 in place regardless. |
| Vercel, Inc. | Frontend hosting and edge logs | United States | Outside the EEA, with EU edge regions preferred | EU-US Data Privacy Framework, with the Standard Contractual Clauses (EU) 2021/914 in place regardless. |
| Plausible Insights OÜ | Cookie-free website and conversion analytics | Estonia (EEA) | Inside the EEA | None needed. The processing does not leave the EEA. |
| GitHub, Inc. | Private repository hosting and tool authentication | United States | United States, outside the EEA | EU-US Data Privacy Framework, self-certified under the Microsoft umbrella, with the Standard Contractual Clauses (EU) 2021/914 in place regardless. |
| Anthropic (Claude API) | SaaS Auditor briefs from aggregate figures, contract-document extraction, internal Ops Log drafting | Not verified. This row names the service rather than a contracting entity; ask us and we will tell you which entity we contract with | Outside the EEA | Standard Contractual Clauses (EU) 2021/914 alone. No framework listing is claimed, because none has been verified. |
| OpenAI (API) | Free-tool diagnostic report and the weekly Platform Health Briefing | Not verified. This row names the service rather than a contracting entity; ask us and we will tell you which entity we contract with | Outside the EEA | Standard Contractual Clauses (EU) 2021/914 alone. No framework listing is claimed, because none has been verified. |
| Cal.com | Scheduling for discovery calls, demos and paid workshop sessions | Not verified. This row names the service rather than a contracting entity; ask us and we will tell you which entity we contract with | Outside the EEA | Standard Contractual Clauses (EU) 2021/914 alone. No framework listing is claimed, because none has been verified. |
| DocRaptor | Rendering purchased eBook PDFs, which carry the buyer email in the licence line | Not verified. This row names the service rather than a contracting entity; ask us and we will tell you which entity we contract with | Outside the EEA | Standard Contractual Clauses (EU) 2021/914 alone. No framework listing is claimed, because none has been verified. |
Recipients we do not instruct
The parties below also receive personal data because of something you do with us, and they are not our subprocessors. They do not process on our instruction, and we do not determine what they do with what they receive. Listing them above would tell you we control that, and we do not. The CSP Marketplace Terms section 07 states the same roles for a licence order, and section 03 of the Privacy Policy separates them the same way.
| Recipient | What it does with the data | Established in | Processing location | Transfer basis |
|---|---|---|---|---|
| Google LLC (reCAPTCHA) | Not our sub-processor. The reCAPTCHA script loads into your browser on our contact and scan-request forms, so your browser sends device, network and interaction data to Google directly. We are a controller for that collection and transmission (CJEU C-40/17 Fashion ID); Google determines what it does with the data afterwards | United States | Outside the EEA. The data goes from your browser to Google and does not pass through our systems | No transfer instrument of ours covers this path, and we claim none. Whether one is required is with counsel. |
| Microsoft Ireland Operations Limited | Not our sub-processor. Licensor and platform operator for Microsoft 365 bought through us via Pax8. Microsoft processes your tenant content as YOUR processor under its Data Protection Addendum, on your instructions and not ours | Ireland (EEA) | Your own tenant, under the agreement you hold with Microsoft. The contracting entity is inside the EEA | Not ours to state. Microsoft processes tenant content on your instruction under its Data Protection Addendum with you, so your agreement governs that transfer and not ours. |
| Pax8 Inc. | Not our sub-processor. Wholesale supplier and provisioning rail for Microsoft licensing. Pax8 receives your order data as an independent controller in its own right to fulfil the wholesale order; your tenant data does not reach it | Netherlands (EEA), for the EU wholesale operation | Netherlands, inside the EEA | Not ours to state. Pax8 receives the order data as an independent controller, so its own position governs that processing. |
Two of those roles are worth stating in words as well as in a table. Microsoft processes the content of your Microsoft 365 tenant as your processor, under its own Data Protection Addendum and on your instructions. Buying a licence from us gives us no access to that content. Google receives reCAPTCHA data straight from your browser, before you submit anything, because we embedded the script that causes it. Following the Court of Justice in Fashion ID (C-40/17) we are a controller for that collection and for its transmission, not a controller instructing a processor. The cookie itself is itemised under third-party cookies.
Notice and objection
What we commit to
We give active customers at least 30 days notice by email before a new subprocessor begins processing personal data. That commitment is published in section 03 of the Privacy Policy and it is not reduced by anything on this page. The change log in section 05 is the second channel, for a reviewer who would rather watch a URL than wait for an email.
How to object
Write to privacy@itsailor.io during the notice period, stating the grounds relating to the protection of personal data. We will tell you what we can change and what we cannot.
What this page does not offer
There is no subscription, feed or webhook on this register. The mechanisms are the email notice above and this URL, which is stable and will not be renamed. If you monitor pages for change, watch the change log anchor rather than the Privacy Policy, whose other thirteen sections change for unrelated reasons.
Change log
Newest first. The list above is current as at , and an automated check fails our build if the recipient declaration changes without an entry being added here.
| Date | Kind | What changed |
|---|---|---|
| publication | This register published at its own URL. No recipient was added, removed or changed by the publication itself. The role of each recipient was recorded explicitly for the first time: Google (reCAPTCHA), Microsoft Ireland and Pax8 moved out of the subprocessor list into the recipients we do not instruct, and Stripe was recorded as holding both roles at once. Those three parties were never our subprocessors; the correction is to how they were described. | |
| correction | The list rendered on the Trust Center was reconciled with section 03 of the Privacy Policy, which had carried five more recipients since 2026-08-02. The attribution of Azure infrastructure for AI features to Microsoft Ireland was deleted as false rather than narrowed: no Azure-hosted model client exists in the platform. | |
| addition | Anthropic (Claude API), OpenAI (API), Cal.com, DocRaptor and Google (reCAPTCHA) added to section 03 of the Privacy Policy. Four of the five were already receiving data at that date, so the entry records a disclosure being corrected, not a new recipient being engaged. |
Contact
Questions about a recipient on this page, a transfer basis, or a copy of the Standard Contractual Clauses with commercially confidential terms redacted: privacy@itsailor.io.
To exercise a data subject right, use dsr@itsailor.io, which is scoped to the request workflow in section 06 of the Privacy Policy. For anything contractual, including a Data Processing Agreement, write to legal@itsailor.io.
Michal Jatczak T/A ITSailor, Level 1, Unit 60, Door No 63, Connecticlub Business Center, Triq Il-Ballut (Zona Industrijali, Mosta), MST 4001, Mosta, Malta.