Legal

Sub-processors

Last updated: May 2026 · The third parties Provlyn uses to deliver its service

We believe you have the right to know exactly who handles your data. This page lists every sub-processor that Provlyn engages, what they do, where they are, and on what legal basis we transfer data to them.

1. What is a sub-processor?

A sub-processor is a third party that Provlyn engages to process personal data on our behalf. They only ever act on our written instructions and on the limited scope necessary to deliver the service.

Each sub-processor on this list has been assessed for security, contractual terms, and lawful transfer mechanisms. Where the sub-processor handles personal data, a Data Processing Agreement (DPA) is in place. Where the sub-processor receives only cryptographic hashes or other non-personal data, a DPA is not required.

2. Current sub-processors

ServicePurposeData processedLocationTransfer basisDPA
Render
Render Services Inc. (United States)
Backend application hosting and PostgreSQL databaseAccount data, vault metadata, deposit metadata, access logs, security event logFrankfurt, Germany (EU)EU hosting; US parent — SCCs in placeSigned
Amazon Web Services (S3)
Amazon Web Services EMEA SARL
Storage of deposited filesUploaded files, file metadataStockholm, Sweden (EU)EEA storage; no transfer outside EEASigned
Vercel
Vercel Inc. (United States)
Frontend hosting and edge deliveryRequest logs (IP, user agent) — short-term operational onlyGlobal edge; primary USUS transfer — SCCs and UK IDTASigned (scope-limited; full scope on Pro plan upgrade pre-launch)
Paddle
Paddle.com Market Limited (United Kingdom)
Payment processing as Merchant of RecordName, email, billing address, transaction history, tokenised payment methodUnited Kingdom and globalUK and EU — adequacy decision appliesIn progress (response awaited)
Resend
Resend Inc. (United States)
Transactional email deliveryRecipient email address, message content, delivery statusUnited StatesUS transfer — SCCs and UK IDTASigned
Sentry
Functional Software, Inc. dba Sentry (United States)
Application error monitoringError events, request context, may incidentally include user IDsFrankfurt, Germany (EU region)EU region selected; US parent — SCCs in placeSigned
GoDaddy
GoDaddy.com, LLC (United States)
Domain registration and email aliasesInbound and outbound email metadata for provlyn.com aliasesUnited StatesUS transfer — SCCs and UK IDTASigned
GitHub
GitHub, Inc. (United States)
Source code repositoryNo production personal data; source code onlyUnited StatesNo personal data in scopeNot applicable
UptimeRobot
UptimeRobot Service Provider Limited (United Kingdom)
Uptime monitoring of public health endpointsNo personal data — only public endpoint reachabilityUnited KingdomNo personal data in scopeNot applicable
Have I Been Pwned
Superlative Enterprises Pty Ltd (Australia)
Compromised password breach check during registration and password changeFirst 5 characters of SHA-1 password hash (k-anonymity); no password or identity transmittedAustralia (Cloudflare global edge)No personal data in scopeNot applicable
FreeTSA
freetsa.org
RFC 3161 trusted timestamps for deposit certificatesSHA-256 file hash only — no personal data, no file contentsSwitzerlandNo personal data in scopeNot applicable
AlfaTrust
AlfaSign (Romania, EU)
Qualified eIDAS timestamps (per-deposit and daily access-log anchoring); Qualified Trust Service Provider on the EU Trusted ListCryptographic hash only — no personal data, no file contentsRomania (EU)No personal data in scopeRequested
OpenTimestamps and Bitcoin network
Public protocol and decentralised network
Blockchain anchoring of cryptographic hashesSHA-256 file hash only — no personal data, no file contentsDecentralised (public)No personal data in scopeNot applicable

3. International data transfers

Where personal data is transferred outside the United Kingdom or European Economic Area, Provlyn relies on the following safeguards as required by Article 46 of the UK and EU GDPR:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • UK International Data Transfer Agreement (IDTA) or UK Addendum where the UK is involved
  • Adequacy decisions where the destination country has been recognised by the UK or EU as providing adequate protection

Where a sub-processor receives only cryptographic hashes (FreeTSA, AlfaTrust, OpenTimestamps, Have I Been Pwned), no personal data leaves Provlyn and these safeguards are not engaged.

4. Changes to this list

Provlyn may add, replace, or remove sub-processors as the service evolves. We update this page promptly when changes occur.

We do not currently send proactive email notifications of sub-processor changes to account holders. Customers with a contractual right to advance notice may subscribe by emailing privacy@provlyn.com and we will notify them by email at least 14 days before any new sub-processor begins processing their personal data.

Where a sub-processor change presents a material risk, we will publish a notice on this page and, where required by law, notify affected users directly.

5. Questions or objections

If you have questions about any sub-processor, or wish to object to a specific sub-processor handling your data, contact privacy@provlyn.com.

Where an objection cannot be reasonably accommodated without affecting Provlyn's ability to deliver the service, we will work with you to find an alternative, which may include termination of your subscription with a pro-rata refund.

Privacy PolicyCookie PolicyTerms & ConditionsFAQContact Us