Sub-processors of the sygnadesk service
In the event of any discrepancy between language versions, the Polski version prevails.
DRAFT FOR LEGAL REVIEW AND COMPLETION. Public page referenced by the Data Processing Agreement.
The operator of the sygnadesk service (Jeton Cloud sp. z o.o. sp.k., Warsaw) uses the providers listed below as further processors (sub-processors) within the meaning of Article 28(2) GDPR. We notify clients by email of every change to this list at least 14 days before it takes effect, in accordance with the Data Processing Agreement.
Last updated: [date to be completed]
| Sub-processor | Registered seat | Role in the service | Processing location | Transfer outside the EEA |
|---|---|---|---|---|
| OVH | France | Server infrastructure (application and database hosting) | European Economic Area | No |
| Hetzner Online GmbH | Germany | Storage of encrypted backups (Nuremberg) | European Economic Area | No |
| Cloudflare | USA (EU entity: Cloudflare Portugal) | Content delivery network, attack protection, client domain and certificate handling | Global nodes; configuration targeted at the EEA | Possible; standard contractual clauses (SCC) and the DPF framework |
| Amazon Web Services (SES) | USA (EU entity: AWS EMEA SARL, Luxembourg) | Sending system emails (region eu-central-1, Frankfurt) | European Economic Area (EU region) | Possible on an ancillary basis; SCC and the DPF framework |
| Stripe | USA (EU entity: Stripe Technology Europe, Ireland) | Payment and invoice handling | EU and USA within Stripe's infrastructure | Possible; SCC and the DPF framework |
Notes:
In end-to-end encryption mode, report content, attachments and correspondence with the reporter leave users' devices only in a form encrypted with the client's keys. None of the sub-processors, nor the operator itself, has the technical ability to read this content.
Backups stored with Hetzner are encrypted before dispatch and stored in a form that prevents premature deletion (protection against ransomware and sabotage).
Stripe, to the extent it independently determines the purposes of processing payment data (for example fraud prevention), acts as a separate controller in accordance with its own documentation.
External sign-in providers (Google, Microsoft) are not sub-processors: authentication takes place directly between the user and the identity provider, and the service receives only confirmation of identity and an email address.
[To be completed after verification: exact names of contracting entities (for example OVH SAS or OVH Sp. z o.o., depending on the contract), numbers of data processing agreements with providers, any further providers (for example a monitoring tool, if added).]