Data protection · Annex 1 to the DPA

Register of sub-processors

Version 1.0 · as of 29 August 2026

This page is the public version of Annex 1 to our data processing agreement under Art. 28 GDPR. It names every provider that processes personal data on our behalf, what for, where, and on what legal basis. Which machine runs what, and how to verify it yourself, is on where patchletter runs.

Where processing takes place

Of 7 sub-processors, 6 process exclusively within the EU. The remaining one is named below with the safeguards applied: Cloudflare, Inc. — authoritative DNS, and the reason we write “no US hosting” rather than “no US provider”.

Controller

Company
patchletter UG (haftungsbeschränkt) i. G.
Address
Meisterweg 16, 45896 Gelsenkirchen, Deutschland
Represented by
Kolja Sagorski
Data protection
legal@patchletter.com
Security reports
security@patchletter.com

Sub-processors

Scaleway SAS

EU only
Address
8, rue de la Ville-l’Évêque, 75008 Paris, Frankreich
Purpose
Hosting: the application on an instance we run ourselves, plus database and object storage as managed services. Since 29 August 2026 the same instance also runs error monitoring (Bugsink), analytics (Umami) and the electronic signing of the DPA (DocuSeal). In addition, the delivery of sign-in links, invitations and confirmation emails (Transactional Email).
Categories of data
All application data: email addresses, tracked products, account and billing data, plus log and error data and the recipient addresses of transactional email.
Places of processing
Paris region (fr-par) for application, database and object storage, and likewise for the backups the provider takes of the managed database every six hours (seven days' retention). Our own hourly backup copies are held in the same provider's object storage in the Amsterdam region (nl-ams).
Safeguards
A French company with no US parent. The provider operates regions exclusively within the EU (Paris, Amsterdam, Warsaw, Milan). Data processing agreement under Art. 28 GDPR.
Verify with
scw rdb instance list -o json · scw instance server list --help
Privacy policy
at the provider

Heinlein Hosting GmbH (mailbox.org)

EU only
Address
Schwedter Str. 8/9b, 10119 Berlin, Deutschland
Purpose
Mailbox and receipt of incoming email to @patchletter.com addresses, and storage of our off-site backups of the database.
Categories of data
Content, senders and attachments of email addressed to us; in the backups the complete data set — but that as ciphertext only.
Places of processing
Berlin, Germany.
Safeguards
A German company processing in Germany. Backups are encrypted client-side (Kopia, AES-256-GCM) before they leave our machine; the provider holds ciphertext only. Data processing agreement under Art. 28 GDPR.
Privacy policy
at the provider

LOGIN SystemHaus GmbH (mailbridge)

EU only
Address
Hagenauer Str. 55, 65203 Wiesbaden, Deutschland
Register
Amtsgericht Wiesbaden, HRB 12713
Purpose
Delivery of update, newsletter and security emails via the mailbridge relay.
Categories of data
Recipient address and content of the message sent. No click or open tracking — plain SMTP has no such thing.
Places of processing
Germany only.
Safeguards
A German company processing exclusively in Germany. Data processing agreement under Art. 28 GDPR.
Privacy policy
at the provider

IONOS SE

EU only
Address
Elgendorfer Str. 57, 56410 Montabaur, Deutschland
Purpose
A separate machine at a different provider: uptime monitoring of our services (status page) and, until the old machine is switched off, the backups of its database.
Categories of data
None for the monitoring itself — it checks availability and operational values. The remaining backups of the old machine contain its data set.
Places of processing
Berlin, Germany.
Safeguards
A German company processing in Germany. Data processing agreement under Art. 28 GDPR.
Privacy policy
at the provider

manitu GmbH

EU only
Address
Welvertstraße 2, 66606 St. Wendel, Deutschland
Purpose
Server hosting for the decommissioned old machine. Since the subdomain move on 29 August 2026 it processes nothing — error monitoring, analytics, DocuSeal and the receipt of machine-generated email ran there until then and have run at Scaleway since. Until it is switched off, a dormant copy of the application data from the move remains there; it is the way back should the move have to be reversed.
Categories of data
The dormant copy holds the complete data set as of the move, i.e. every subscriber address.
Places of processing
St. Wendel, Germany.
Safeguards
A German company processing exclusively in Germany. The provider is still listed because it holds copies of production data — a sub-processor that does so belongs in the list with exactly that purpose, even when nothing is running. Data processing agreement under Art. 28 GDPR.
Verify with
ssh manitu 'docker ps' — seit dem 29.08.2026 ohne laufenden Container
Privacy policy
at the provider

Mailjet SAS (Sinch-Gruppe)

EU only
Address
13-13 bis rue de l’Aubrac, 75012 Paris, Frankreich
Purpose
Standby path for sending. Used only if the regular path fails, and capped at 200 messages a day.
Categories of data
In a fallback: recipient address and content of the message sent.
Places of processing
EU data centres (Frankfurt and Saint-Ghislain).
Safeguards
Processing in EU data centres. It is listed although it is not the regular path: the access is set up and takes over the moment the regular path fails, and naming a processor only once it is actually in use would be naming it too late. Data processing agreement under Art. 28 GDPR.
Privacy policy
at the provider

Cloudflare, Inc.

third country
Address
101 Townsend St, San Francisco, CA 94107, USA
Purpose
Authoritative DNS for patchletter.com only. This resolves domain names; no account data and no email content is transmitted.
Categories of data
No stored personal data. The IP addresses of querying resolvers, as arise with any name resolution.
Places of processing
Global anycast network; the provider is based in the USA.
Safeguards
Standard Contractual Clauses (Art. 46 GDPR) and, where the provider is certified, the EU-US Data Privacy Framework. This is the only point with a third-country element — and the reason we write “no US hosting” rather than “no US provider”: a single dig NS patchletter.com would disprove the latter; the command is below, to check for yourself. The domain is still subject to a transfer lock; a move to a German registrar is planned as soon as it has lapsed.
Verify with
dig NS patchletter.com
Privacy policy
at the provider

Deliberately not listed

A gap without a reason reads as an oversight. So here is what is missing, and why.

Our payment provider
It processes billing data, for which we are a controller in our own right — it is not a sub-processor for the data we handle on your behalf.
Analytics, error monitoring and bot protection
We run Umami and Bugsink ourselves on our own instance; the bot-protection challenge (ALTCHA) is issued and verified by the application itself. No third-party service is involved — the host of that instance is listed above as Scaleway in any case.

Changes to this list

Any intended change — a new sub-processor or a switch — is announced in text form to your billing address at least 30 days in advance. Within those 30 days you may object on substantive data protection grounds; if we cannot resolve the objection, you may terminate. The procedure is set out in section 9 of the DPA.