Subprocessors
Every third party that touches your data.
Last updated 2026-04-24
A “subprocessor” is any company we use that processes personal data on our behalf. Under ourData Processing Addendumwe commit to (1) keep this list current, (2) give you at least 30 days’ notice before we add or replace any subprocessor, (3) ensure each one is bound by GDPR-equivalent contractual terms before any personal data reaches them.
| Processor | Purpose | Data | Region | Transfer mechanism |
|---|---|---|---|---|
| Google Cloud / Firebase | Hosting, authentication, Firestore database, Cloud Storage. | Account email, workspace metadata, telemetry configured by customer, server logs. | europe-west3 (Frankfurt, DE) for EU workspaces; us-central1 (Iowa, US) for US workspaces. | For EU data, Google is committed to the EU-US Data Privacy Framework plus SCCs (2021 Modules 2 + 3) for any onward transfer. |
| Cloudflare | DNS, WAF, DDoS mitigation, TLS termination for public marketing site. | IP address, user agent, request metadata in access logs. | Global anycast edge; logs retained in EU. | Cloudflare DPA + SCCs 2021. Cloudflare is self-certified under the EU-US DPF. |
| Google reCAPTCHA Enterprise (App Check) | Bot / abuse attestation on every Firestore and Auth call from the browser. | Browser fingerprint signals, IP, user agent. | US; delivered via Google Cloud infrastructure. | EU-US DPF + SCCs per Google Cloud DPA. |
| Resend | Transactional email (sign-in links, security notices). | Recipient email, message body generated by Sutrace. | US east. | Resend DPA + SCCs. |
Notification of change
We maintain a change log at the bottom of this page and email the primary billing contact on every customer workspace at least 30 days before a new subprocessor goes live. Customers may object in writing to privacy@sutrace.io; if the objection cannot be resolved, either party may terminate the affected service.
Change log
- 2026-04-24Initial publication of subprocessor list.
Requesting an audit
Enterprise customers can request a third-party audit of our subprocessor management under the DPA. Contact legal@sutrace.io.