Sub-Processors

Last Updated: July 2026 · GDPR Art. 28(2)

Pursuant to Article 28(2) of the GDPR, Deznot maintains a current list of sub-processors engaged in processing Customer personal data. Customers will be notified at least 30 days before adding or replacing a sub-processor, giving the Customer the right to object.

Sub-ProcessorPurposeLocationAdequacy
Stripe, Inc.Payment processing (PCI-DSS Level 1)USA / EUSCCs + Privacy Shield successor
Redis Labs (Redis Cloud)Session caching, rate limitingEU (Frankfurt)EU-based, no transfer
Let's Encrypt (ISRG)SSL/TLS certificate issuanceUSASCCs (no personal data processed)
Docker HubContainer image distributionUSA / Global CDNSCCs (no personal data processed)

Objecting to a Sub-Processor

Customers may object to a new or replacement sub-processor by notifying us at legal@deznot.com within 30 days of receiving the notification. In such cases, we will either (a) propose an alternative, or (b) allow the Customer to suspend or terminate the affected service.

Updates

This list is updated whenever sub-processors are added, changed, or removed. The "Last Updated" date reflects the most recent change.