Sub-processor List
Satisfies GDPR Art. 28(2) (informing the controller/counterparty of sub-processor changes) and is the client-facing form of register/suppliers.yaml — the document a partner or institutional investor would actually be shown during onboarding or due diligence. Formalizes the same 12 real, verified entries; nothing here is invented beyond suppliers.yaml. Two of the twelve are the known staleness corrections: Hetzner is the real hosting layer, not named at all in `dsgvo-data-flow.md`'s processor table; AWS SES replaced Resend as the transactional-email processor, both confirmed against code (register/facts.md).
Current sub-processors
| Processor | Purpose | Location | DPA status |
|---|---|---|---|
| Supabase (self-hosted, on the Hetzner host) | DB, auth, realtime, storage — all app data | EU (Hetzner nbg1) | In place (Supabase software/managed-service DPA; hosting-location change to self-hosted noted, re-confirmation with Supabase recommended) |
| Hetzner Online GmbH | Physical/infrastructure host for the entire production stack | Germany (nbg1) | Unknown — open item |
| AWS SES (`eu-central-1`) | Transactional + broadcast email — addresses and message content | EU | Unknown — open item |
| Stripe Payments Europe Ltd | Subscription payments (Stratify has no card/IBAN access) | Ireland | In place |
| PostHog | Analytics, no autocapture, explicit identify() only | EU | In place |
| Sentry | Error telemetry, server-side only, PII sanitization enabled | EU | In place |
Vercel AI Gateway → Anthropic (claude-sonnet-4) | Draft signal content may reach model prompts, for AI-assisted German signal drafting | Not confirmed (Vercel AI Gateway routing; model provider Anthropic) | Unknown — open item |
| Apple Push Notification Service (APNs) | iOS push routing — device push tokens | US | Unknown — open item |
| Google Firebase Cloud Messaging (FCM) | Android push routing — device push tokens | US/EU | Unknown — open item |
| Expo Push API | Mobile push tokens | US | Unknown — open item |
| Resend *(historical, decommissioned)* | Former transactional-email vendor, replaced by AWS SES; listed for audit-trail continuity only, no longer integrated | n/a | Was in place (2026-05-19); not a live processor |
| wait, what. Advisory | Controller of record, not a sub-processor — listed for completeness pending Stratify AG/GmbH incorporation | Switzerland (Zürich) | Not applicable |
Open items — stated plainly, not hidden
A document shown to a partner is exactly where an open DPA status must not be glossed over:
- Hetzner and AWS SES are the two open items with the most operational weight — Hetzner because
it is the physical host of everything and currently isn't even named in dsgvo-data-flow.md's processor table; AWS SES because it now carries every transactional and broadcast email address and message body that used to run through Resend. Both are being actively closed: Hetzner's standard hosting DPA and AWS's DPA under the AWS Customer Agreement are the expected instruments, pending confirmation and filing.
- Push-routing vendors (APNs, FCM, Expo Push API) and the AI Gateway/Anthropic path also
show unknown DPA status in register/suppliers.yaml. These carry lower-sensitivity data (device push tokens; draft signal text, not subscriber PII) but are listed here rather than omitted — this table's job is completeness, not a curated subset that looks cleaner than reality.
- Owner of closing all of the above: DPO / Privacy Owner (Antonios), per the RACI in
GOV-03
("Supplier / DPA review" row).
Change-notification commitment
Stratify commits to notifying counterparties of any new sub-processor, or any change to a listed sub-processor's role, with 30 days' notice before that sub-processor begins processing data under a counterparty agreement — proposed, pending confirmation by the DPO / Privacy Owner (Antonios). This satisfies the Art. 28(2) obligation to give the controller an opportunity to object. Once procedures/PRO-10 (Sub-processor onboarding & review, pending) is written, that procedure becomes the authoritative mechanism keeping this list current — this document is the output it maintains, not a standalone record kept separately.
Review
This list is regenerated from register/suppliers.yaml whenever that file changes, and reviewed on the quarterly cadence dsgvo-data-flow.md §10 already states for the underlying DPA links, until PRO-10 formalizes its own cadence.