Contact sécurité
Demande d'assistance
Retour d'expérience

Sub-processors

Version: 1.2Effective: July 31, 2026
Last updated: July 31, 2026

This page is the complete list — the single source of truth. The privacy policy, the GDPR page, the DPA and the security page all point here; if you spot a discrepancy anywhere, this page prevails.

30 days’ advance notice of every change

At least 30 days before engaging a new sub-processor we email the billing contacts of accounts and update this page. A customer acting as controller may object within 30 days of the notice, stating its reasons — section 7 of the DPA governs what happens then.

Subscribe to the notices: (subject: “Sub-processor notices”)

1. Active sub-processors

List last modified: 31 July 2026. The “Contracting entity” column shows which company we contract with — for assessing transfers this is what matters, not where the server physically sits.

ProviderWhat we use it forContracting entityWhere data is storedTransfer basis
Hetzner Online GmbH
DPA
Application hosting (Kubernetes cluster), Redis cacheGermanyGermany (Falkenstein / Nuremberg)No transfer — EU entity, EU data centre
OVH Hosting Limited
DPA
Managed MongoDB database — storage of all operational dataIreland (Dublin) — the contracting entityFrance (Gravelines) — the data centreNo transfer — EU entity, EU data centre
Mollie B.V.
DPA
Payment processing (card, SEPA, iDEAL)Netherlands (Amsterdam)EUNo transfer — EU entity, EU storage
Billingo Technologies Zrt.
DPA
Electronic invoicing and reporting to the Hungarian tax authority (NAV)HungaryHungaryNo transfer — EU entity, EU storage
Tarhely.eu / EZIT Kft.
DPA
Email delivery (SMTP relay at mail.cadensa.io), domain servicesHungaryHungaryNo transfer — EU entity, EU storage
Plausible Insights OÜ
DPA
Cookie-free, identifier-free website analytics on the public siteEstonia (Tallinn)EU (Germany)No transfer — EU entity, EU storage
Vercel Inc.
DPA
Serving the static files of the website and the application (hosting + CDN). Stores no customer data: API calls go directly to the EU backend.⚠️ United States (Delaware) — the contracting entity is US-basedEU edge region (fra1, Frankfurt)Serving happens in the EU edge region, yet we rely on SCCs. That is not a contradiction: where data is stored and who can reach it are two different questions. Vercel’s US-based engineers can access the system remotely for support and operations, and under the GDPR that access counts as a transfer even though the data physically stays in Frankfurt. Basis: Vercel DPA + SCCs. Data involved: IP address, user agent, request metadata.
Formbricks GmbH
DPA
The engine behind our feedback, support and security report forms, and the NPS surveys (app.formbricks.com). Whatever you type into a form goes to them.Germany (Kiel) — Kuhnkestr. 6, 24118 KielGermany (EU)No transfer — EU entity, EU storage. The widget marks in your browser which surveys you have seen; that requires consent to the analytics category, without which it does not even load.
Functional Software, Inc. (Sentry)
DPA
Error logging and performance monitoring in the web application. Errors and performance samples only: session replay is switched off and no screen content is captured. The production backend sends nothing to Sentry.⚠️ United States (San Francisco) — the contracting entity is US-basedEU region (de.sentry.io, Germany)We use Sentry’s EU data region, so events stay in Germany. The entity is nonetheless US-based, and remote support access counts as a transfer. Basis: Sentry DPA + SCCs. Authorization and Cookie headers, and the query string, are stripped before an event is sent.
Wasabi Technologies LLC
DPA
Object storage with three separate buckets: (1) encrypted database backups on a rotating schedule, (2) invoice PDF archive under WORM Object Lock, (3) profile pictures. The profile picture bucket is publicly readable so the image can render in the interface — so do not upload anything there you would not put in public. Uploading a profile picture is optional and it can be deleted at any time.⚠️ United States (Massachusetts) — the contracting entity is US-basedGermany (eu-central-2, Frankfurt)Data stays in the EU, but the entity is US-based. Basis: Wasabi DPA + SCCs. Backups are encrypted with AES-256-GCM before upload — the key stays with us, so Wasabi cannot read them.

2. What is deliberately not on the list

Google LLC — Google Calendar integration

Google is not our sub-processor, because it does not act on our instructions. When you connect your own Google account via OAuth, Google is an independent controller for its own service. The integration is optional, off by default, runs with read-only scope, and can be revoked at any time. The transfer relies on the Article 45 adequacy decision (EU–US Data Privacy Framework).

Google LLC — Sign in with Google

The same as with the calendar: Google does not act on our instructions here either, but is an independent controller for its own authentication service. If you choose it, Google learns that you signed in to Cadensa, and we receive your name, email address and profile picture from Google. Sign-in also works without a Google account, with an email address and password — this is not a required path. The transfer relies on the Article 45 adequacy decision.

Sign-in via Microsoft Entra ID or SAML is not implemented, so Microsoft appears on this list in no capacity at all. When it ships, it goes on this page first and goes live only afterwards.

Stripe

Billing used to run on Stripe; today it runs on Mollie (Netherlands). Stripe receives no data: the production environment holds no Stripe keys, and all payment traffic goes through Mollie. Legacy Stripe code, including the webhook endpoint, is still in the codebase because of the migration, but without keys it does nothing and it will be removed in the next cleanup.

CDN, WAF and analytics vendors

There is no Cloudflare, no Google Analytics, and no advertising or social media pixel in the service. Static delivery of the website runs on the Vercel edge (see above); the application’s API traffic goes straight to the Hetzner cluster.

3. On the US entities, plainly

Three of our sub-processors are US-incorporated companies: Vercel, Wasabi and Sentry. All three store in an EU region, but their parent companies sit under US jurisdiction, so CLOUD Act exposure exists in principle. We would rather say so than claim a “100% EU chain” that a thorough buyer disproves in five minutes.

It is worth saying plainly why SCCs apply even to a provider that stores in the EU. Because under the GDPR a transfer is not only the physical movement of data, but also the possibility of access from a third country. An engineer at a US provider may look at the system for support or operations — that is a transfer even if the disk spins in Frankfurt. So “EU storage” on its own is not a complete answer, and anyone claiming otherwise has either not thought it through or is not telling you.

  • Time entries, projects and reports — the substance of customer data — reach neither US entity: they live in the Hetzner cluster and the OVHcloud database.
  • The backups stored at Wasabi are encrypted before upload, and the key never leaves our side.
  • We have carried out a transfer impact assessment (TIA) for all three providers; we share it on request for procurement. We verified the contracting entity and the storage region from provider invoices, not from marketing material.

Related Documents:

Language of this document

This document is authored in English and Hungarian. On other language interfaces the English text is shown. In case of any discrepancy between the two versions, the English text prevails — except where the contracting party is a consumer resident in Hungary, in which case the Hungarian version applies. If you spot a discrepancy between the versions, please tell us at legal@cadensa.io and we will fix it.