Sub-processor List
Version 1.0 · Effective 2026-08-29
This page lists the third-party Sub-processors Closetforge engages to deliver the Service. We notify Customers at least thirty (30) days before adding or replacing a Sub-processor (see DPA Section 8). Customers can subscribe to update notifications by emailing privacy@closetforge.com.
<!-- DRAFT FOR LEGAL REVIEW (2026-08-29). This list was rewritten against the running system. The previous version named AWS RDS Frankfurt, Cloudflare (CDN/DNS/WAF) and Cloudflare R2 — none of which are in the serving path — and offered three unmade choices (Postmark/Resend/SendGrid, Intercom/Plain/HelpScout, Plausible/PostHog). It also omitted every vendor that actually receives data: Hetzner, Coolify, Sentry, and the geocoding and routing services that receive end-consumer delivery addresses. Verified 2026-08-29 against the production environment and the code. TWO THINGS THE LAWYER MUST RULE ON (OPEN-ITEMS.md, BOTH section, S2 / C7): 1. Coolify Cloud holds administrative access to the server. Sub-processor, or infrastructure vendor? Its legal entity still needs confirming. 2. Nominatim and OSRM below receive a consumer's delivery street, postcode and city. They are free public instances of open-source services, not contracted vendors, so there is no DPA to point at. This was previously undisclosed entirely and it is the most substantive gap in this list. It is now also the ONLY address-lookup path: the Google Distance Matrix and Geocoding integration and the provider-selection switch that could reach it are being removed from the product (founder, 2026-08-29), so there is no second route a deployment could be pointed at by configuration. Google appears on this list only for Gmail and Google Workspace. AMENDED 2026-08-29 (off-site backup) — AWS IS BACK, FOR A DIFFERENT REASON THAN THE ONE THAT REMOVED IT. The rewrite above dropped AWS because the old list named "AWS RDS Frankfurt" as the production database, which was never true. AWS is now on the list legitimately as BACKUP STORAGE and nothing else, and part of it was already running when that rewrite was made: the Coolify scheduler has uploaded a daily `pg_dump` of the production database to S3 in eu-central-1 since at least 13 August 2026. What 2026-08-29 adds is a nightly copy of the OBJECT STORE — quote PDFs, 3D renders, material textures, brand assets — which until that date had no backup of any kind, anywhere: it sat only in MinIO on the same machine as the database. The two statements are not in tension, and the distinction matters to anyone reading the diff: AWS runs no part of the Service and receives no user traffic. It holds copies. - It is the LUXEMBOURG entity (AWS EMEA SARL), because the account's country is Slovenia. The AWS Data Processing Addendum and the 2021/914 SCCs are incorporated into the AWS Service Terms by default (§1.14), so there is no separate DPA to sign and none to chase. - Storage is eu-central-1 (Frankfurt, Germany) and the data does not leave the EEA, so the SCCs sit dormant — the transfer column reads "Within EEA" for the same reason Hetzner's does. - Encryption: SSE-S3 at rest, TLS in transit. The platform deliberately does NOT add client-side encryption on top, and the reason belongs in the record rather than a table cell: the database dump in that same bucket is written by the control plane in plaintext and holds the same personal data, so encrypting only the application's own uploads would add an unrecoverable key without reducing what the provider holds. Revisit if and when the database dump is encrypted too. - RETENTION IS NOT SET YET. All four of the control plane's retention settings are 0, which it reads as keep-everything, and the S3 lifecycle rules that would impose a real period are step 4 of docs/ops/offsite-backup-setup.md. Until they are applied the honest retention statement is "indefinitely", which is why DPA §12.3 and the privacy retention tables are written against the recommended rules and marked pending rather than published as fact. See OPEN-ITEMS S1. -->
Infrastructure
| Sub-processor | Service | Region | Transfer mechanism |
|---|---|---|---|
| Hetzner Online GmbH | The dedicated server that runs the application, the PostgreSQL database and the MinIO object storage (textures, PDFs, thumbnails, brand assets). All three are self-hosted on that one machine. | Germany (Falkenstein) | Within EEA |
| Coolify Cloud (operating entity to be confirmed) | Deployment control plane; holds administrative access to the server above | EU | Within EEA |
| Amazon Web Services EMEA SARL (Luxembourg) | Off-site backup storage only (Amazon S3): a daily copy of the database, and a copy of stored files (quote PDFs, 3D renders, material textures, brand assets), held so that the loss of the single server above does not lose the data. AWS runs no part of the Service itself and receives no user traffic. | Germany (Frankfurt, eu-central-1) | Within EEA — the data does not leave the EEA. The AWS DPA and EU SCCs (2021/914) are incorporated into the AWS Service Terms by default and would apply if it ever did. |
Monitoring
| Sub-processor | Service | Region | Transfer mechanism |
|---|---|---|---|
| Functional Software, Inc. (Sentry) | Application error monitoring — stack traces, request metadata and IP addresses | US company, EU ingest (ingest.de.sentry.io) | EU SCCs (2021/914); DPF as applicable |
Communication
| Sub-processor | Service | Region | Transfer mechanism |
|---|---|---|---|
| Twilio Ireland Limited | SMS one-time-password delivery | EU primary, global delivery | EU SCCs (2021/914) for any non-EEA delivery |
| Resend, Inc. | Transactional email (quotes, notifications) | US | EU SCCs (2021/914) |
| Google Ireland Limited | Gmail API for certain outbound email sent from the platform's own mailbox; Google Workspace for internal email and documents | EU contracting entity, global processing | EU SCCs / DPF |
Address lookup and distance
Used to price delivery and to decide which measurement-visit band an address falls in. A consumer's delivery street, postcode and city are sent to these services.
| Sub-processor | Service | Region | Transfer mechanism |
|---|---|---|---|
| Nominatim (OpenStreetMap Foundation) | Converts a delivery address into coordinates | EU / UK | Public open-data service; no contract in place — see the note above |
OSRM (router.project-osrm.org) | Driving distance between the workshop and the delivery address | EU-hosted public instance | Public open-source service; no contract in place — see the note above |
These two are the only services that receive a delivery address. No other mapping, geocoding or routing vendor is used, and none is configured as an alternative. If that ever changes, this list is updated and Customers are notified first.
AI
| Sub-processor | Service | Region | Transfer mechanism |
|---|---|---|---|
| OpenAI Ireland Limited | LLM inference for AI chat (GPT-5 family) | EU contracting entity, US processing | EU SCCs (2021/914) Module Three; data not used for training under enterprise terms |
Payments
| Sub-processor | Service | Region | Transfer mechanism |
|---|---|---|---|
| Stripe Payments Europe, Limited | Card processing | EU primary, US fraud screening | EU SCCs / DPF; Stripe acts as independent controller for some processing |
Internal operations (process Personal Data only incidentally)
| Sub-processor | Service | Region |
|---|---|---|
| Google Workspace | Email, calendar, documents | EU primary |
| GitHub | Source-code hosting (no production data) | US |
We do not use a helpdesk product; support is a monitored mailbox.
Analytics
<!-- Written so that adding a vendor is a row, not a rewrite. Plausible is wired into the marketing site behind NEXT_PUBLIC_PLAUSIBLE_DOMAIN and the env var is not set, so no analytics script is served and no analytics vendor receives anything today. The founder expects to switch it on eventually (2026-08-29); when he does, it becomes a row in the table below and the sentence under it still reads true. -->| Sub-processor | Service | Region | Transfer mechanism |
|---|---|---|---|
| No analytics vendor is engaged at the date of this version. |
Any web or product analytics vendor we engage is listed in this table, and Customers are notified at least thirty (30) days beforehand under DPA Section 8.
Notes
- Any Sub-processor that processes Personal Data on Closetforge's behalf is bound by a written agreement imposing data-protection obligations no less protective than those in the DPA.
- Sub-processors marked "DPF-certified" appear on the EU–US Data Privacy Framework list; transfers rely on the EU Commission's adequacy decision for the DPF.
- Where transfers fall outside an adequacy decision and DPF coverage, EU SCCs (2021/914) are used, supplemented by encryption in transit and at rest, contractual purpose limitations, and the Sub-processor's own technical and organisational measures.
<!-- THE SIX MONTHS RUNS FROM THE REVIEW, NOT FROM LAUNCH — and this is the one place in the pack where the founder's 2026-08-01 was not simply stamped through (2026-09-01). "Last review" is a claim that a person checked this list on that day. That happened on 2026-08-29 (the round-two pass against the production environment and the code, recorded in the comment at the top of this file and in OPEN-ITEMS.md's CLOSED section). It did not happen on 2026-08-01. Writing 2026-08-01 would be a false statement of fact, and a review cadence is only worth anything if the date it counts from is real. So both stamps run from the real review: 2026-08-29 + 6 months. February 2027 has no 29th, so the next review clamps to 2027-02-28. FOR THE REVIEWER: if the cadence is meant to run from actual PUBLICATION of this version rather than from the review, both dates move together and neither of them is 2026-08-01 either — publication has not happened yet. Say which basis you want; do not re-pair a true date with a launch-derived one. -->
Last review: 2026-08-29 Next scheduled review: 2027-02-28
To request an updated list or detailed information about any entry, email privacy@closetforge.com.