Sub-processors
Version 2026-10-06, effective 2026-10-06
About this list
This document lists Dvelopin's sub-processors and other recipients for the white-label portal service.
Dvelopin is not certified under the EU-US Data Privacy Framework and does not represent that it is. The "DPF" entries below describe each vendor's own status on the DPF list, not Dvelopin's.
Sub-processors in use today
- AWS (Lightsail, S3, SES): hosting, file storage, backups, email. All personal data the portal holds: account profiles (email, name, phone, company, US tax state), organization memberships and roles, invitations, sign-in security settings, display preferences, sign-in and session logs, API token metadata, security events, request capture (off by default), rate-limit keys, staff action log, email logs, the email suppression list, and SES delivery, bounce and complaint notices. United States (us-east-2) for hosting, file storage, email, and backups. EU option: Lightsail in Frankfurt, Ireland, London, Paris, Stockholm (Spain opt-in); SES in several EU regions. [to be confirmed]. Processor. SCC Modules 2 and 3, UK Addendum, DPF (active, under Amazon.com, Inc.)
- Stripe: payment processing on the billing page. Billing contact email, Stripe customer IDs, saved payment method details (card brand, last four digits, expiry, wallet type), invoices, payments, subscriptions. This is Dvelopin's controller data; Stripe is listed here for consistency with the tenant privacy notice. [to be confirmed]. No EU region offered; data "may be stored and processed in any country where we do business". Processor; independent controller for fraud, AML, KYC, and analytics. DPF first, then SCC Modules 1 to 3, UK Addendum (active, Stripe, LLC)
AWS data processing addendum (opens in a new tab)
Stripe data processing addendum (opens in a new tab)
Used only when SMS is switched on for an organization
These sub-processors are engaged only when SMS is switched on for a customer organization and the named provider is chosen. Dvelopin staff switch SMS on for an organization (it is off by default); the organization's owner or an admin, or Dvelopin staff, then chooses the provider and saves its credentials. No organization has SMS on today. [to be confirmed]
- Telnyx: SMS, only when Telnyx is the organization's chosen provider. Recipient phone number and message text; the vendor's own message logs. Today the only message the portal sends is the test message from the SMS settings page. [to be confirmed]. EU option: partial, an at-rest locality option in Germany. Processor for content; independent controller for account and usage data, including message logs. SCC Modules 1 to 3, UK Addendum, DPF (active)
- Twilio: SMS, only when Twilio is the organization's chosen provider. Recipient phone number and message text; the vendor's own message logs. Today the only message the portal sends is the test message from the SMS settings page. [to be confirmed]. EU option: SMS in Ireland (IE1). Processor; independent controller for account, usage, and message content for limited purposes. DPF, BCRs, SCC Modules 1 to 3, UK Addendum (active)
Telnyx data processing addendum (opens in a new tab)
Twilio data protection addendum (opens in a new tab)
Planned, not used today
The following vendors are planned for future engagement. They are not sub-processors today and are not authorized by the current DPA. Any of them would be added only through the notice and objection process below.
- Anthropic: planned for AI features [planned: AI1]. Held off for any organization with the EU privacy setting on [planned: G10]. No AI features exist today; a dormant adapter is in the code, and no page or job calls it.
- Square: planned as an alternative payment processor [planned: I1]. Not engaged.
- PayPal: planned as an alternative payment processor [planned: I1]. Not engaged.
Other recipients (not sub-processors)
These recipients are not Dvelopin's sub-processors. Where one acts as an independent controller, the customer's privacy notice should name it as a recipient.
- Google Pay (inside Stripe's Express Checkout): wallet payment option on the billing page, only if the user chooses it. Independent controller under its own API terms (dated 2021, still citing Privacy Shield). No DPA with Dvelopin.
- Apple Pay (inside Stripe's Express Checkout): wallet payment option on the billing page, only if the user chooses it. [to be confirmed]. No DPA with Dvelopin.
- Let's Encrypt: issues TLS certificates for the portal's web addresses. Acts for its own purposes. It receives Dvelopin's certificate account details and server information, not users' personal data, unless a tenant's domain name itself identifies a person. No DPA with Dvelopin.
Change notice and objection
When Dvelopin intends to add or replace a sub-processor:
- Written notice: Dvelopin gives the customer written notice at least 30 days before the change takes effect. The notice identifies the new or replacement sub-processor, its role, its location, and the transfer tool that will apply.
- Automatic notices and public page: a public sub-processor page (this page) and automatic notices to organization owners, each with an effective date 30 days out, are available [planned: G6].
- Right to object: the customer may object to a proposed change on reasonable grounds relating to data protection within the 30-day notice period. If the parties cannot resolve the objection: [to be confirmed].