Sub-Processors
Last Updated: July 2026 · GDPR Art. 28(2)
Pursuant to Article 28(2) of the GDPR, Deznot maintains a current list of sub-processors engaged in processing Customer personal data. Customers will be notified at least 30 days before adding or replacing a sub-processor, giving the Customer the right to object.
| Sub-Processor | Purpose | Location | Adequacy |
|---|---|---|---|
| Stripe, Inc. | Payment processing (PCI-DSS Level 1) | USA / EU | SCCs + Privacy Shield successor |
| Redis Labs (Redis Cloud) | Session caching, rate limiting | EU (Frankfurt) | EU-based, no transfer |
| Let's Encrypt (ISRG) | SSL/TLS certificate issuance | USA | SCCs (no personal data processed) |
| Docker Hub | Container image distribution | USA / Global CDN | SCCs (no personal data processed) |
Objecting to a Sub-Processor
Customers may object to a new or replacement sub-processor by notifying us at legal@deznot.com within 30 days of receiving the notification. In such cases, we will either (a) propose an alternative, or (b) allow the Customer to suspend or terminate the affected service.
Updates
This list is updated whenever sub-processors are added, changed, or removed. The "Last Updated" date reflects the most recent change.
