This page identifies external providers that may process personal data to provide, protect, maintain or support the Praisera Service.
A subprocessor is a provider that processes personal data following Praisera’s instructions in connection with the Service. Praisera maintains data processing agreements or other appropriate contractual instruments with its subprocessors where applicable.
This list does not include providers that do not intentionally receive production personal data as part of the normal operation of the Service, professional advisers, or software, libraries or technical components operated directly by Praisera within its own infrastructure.
1. Current subprocessors
| Provider | Service | Main location | Data processed | Safeguards |
|---|---|---|---|---|
| Hetzner Online GmbH | Hosting and infrastructure: application servers, database, storage and backups | Germany, EEA | Data stored by the Service, including accounts, configuration, reviews, logs, events and backups | Hetzner DPA. Main processing within the EEA |
| Cloudflare, Inc. | DNS, CDN, proxy, perimeter security, abuse mitigation, WAF/bot protection where configured | Global network, including the U.S. and Europe | HTTP request metadata, IP address, user agent, technical headers, paths, security events and data in transit necessary to deliver and protect the Service | Cloudflare DPA, SCCs and DPF where applicable |
| Stripe Payments Europe Ltd. | Payments, subscriptions, billing, fraud prevention and financial compliance | Ireland, with possible transfers to the U.S. | Payment, billing and subscription data, customer identifiers, payment history and tax records. Praisera does not store full card numbers or CVV | Stripe DPA, SCCs and DPF where applicable. Stripe may also act as an independent controller |
| Resend, Inc. | Sending transactional and operational emails | U.S. | Email addresses, name if included, email subject, email body, one-time tokens/links, delivery metadata, bounces and errors. Emails may include review content or report information where this forms part of a notification | Resend DPA, SCCs and DPF where applicable |
| Functional Software, Inc. / Sentry | Error monitoring, diagnostics and reliability | Events hosted mainly in Frankfurt, Germany, with possible access or support from the U.S. | Error events, stack traces, routes, technical identifiers and diagnostic metadata. Praisera configures Sentry to minimize personal data and avoid the intentional sending of review content, emails, tokens or request bodies | Sentry DPA, EU data residency for events and SCCs where applicable |
2. Identity providers
When a Review Author signs in through an external provider, that provider acts as an independent controller for its own authentication service.
| Provider | Use |
|---|---|
| Review Author sign-in where the user chooses this option |
Praisera receives only the data necessary to authenticate the user in the Service, such as a stable identifier of the Google account, first name, last name and email address, according to the data provided by Google and authorized by the user.
3. International transfers
Praisera’s main infrastructure is hosted in the European Economic Area.
Some providers may process personal data or provide support from countries outside the EEA. In those cases, Praisera relies on the transfer mechanisms indicated by each provider in its DPA, data processing terms or applicable legal documentation, such as adequacy decisions, Standard Contractual Clauses, the EU-U.S. Data Privacy Framework where applicable, or other appropriate safeguards.
Where Praisera relies on the EU-U.S. Data Privacy Framework, it will do so only while the provider maintains an active certification covering the relevant data.
If a transfer mechanism becomes unavailable or invalid, Praisera may implement an alternative mechanism, suspend the affected transfer, replace the provider or discontinue the affected functionality where necessary.
4. Changes to this list
Praisera may add, replace or remove subprocessors to provide the Service.
Where a change is material to the processing of personal data on behalf of a Client, Praisera will update this list and, where reasonably possible, notify registered Clients before the change takes effect.
Clients may object to a new subprocessor on reasonable and documented data protection grounds in accordance with the DPA. Objections must be sent to [email protected].
If the subprocessor is necessary to provide the Service or a specific functionality and Praisera cannot reasonably accommodate the objection, the Client may stop using the affected functionality or terminate the affected Service before the change takes effect, unless the law or a signed agreement requires otherwise.
Editorial corrections, link updates or clarifications that do not materially change the processing may be made without prior notice.
5. Onward subprocessors
The providers listed may use their own subprocessors in accordance with their respective processing agreements and legal documentation.
Praisera reviews the data protection and transfer documentation of its main providers. This page does not exhaustively list all onward subprocessors of each provider.
Upon written request, Praisera may provide reasonably available information about relevant onward subprocessors, subject to confidentiality, provider restrictions, security and protection of trade secrets.
6. Contact
Questions about this list or objections to subprocessor changes must be sent to:
In case of inconsistency between this page and the applicable DPA, the DPA will prevail.