Legal
Sub-processors
Current sub-processors
| Sub-processor | Role / service | Data processed | Location / region | Transfer basis | Provider DPA / list |
|---|---|---|---|---|---|
| Hetzner Online GmbH Industriestraße 25, 91710 Gunzenhausen, Germany |
Infrastructure / IaaS hosting (compute, storage, backups) — the Cerynix production stack | All Customer Content and account data hosted in the managed Service | EU — Germany (data residency in EEA by default) | Intra-EEA (no Art. 46 transfer needed for EU region) | DPA (Art. 28) concluded in the Hetzner account; provider DPA at hetzner.com/AV/DPA_en.pdf; sub-processor list at hetzner.com/AV/subunternehmer.pdf |
| Cloudflare, Inc. US; EU entity Cloudflare Germany GmbH |
CDN / edge, WAF, TLS termination, DNS for cerynix.com / app.cerynix.com | Traffic metadata and any personal data in requests passing through the edge (IP addresses, request data); no persistent storage of Customer Content by design | Global edge network (incl. non-EEA) | EU Standard Contractual Clauses and/or EU–US Data Privacy Framework, per Cloudflare's DPA | Cloudflare Customer DPA at cloudflare.com/cloudflare-customer-dpa; sub-processor list at cloudflare.com/gdpr/subprocessors |
| Proton AG Switzerland |
Mailbox for inbound mail to every @cerynix.com address (Cloudflare Email Routing forwards to it). This is the mailbox that receives anything you send to privacy@cerynix.com, hello@cerynix.com, support@cerynix.com or security@cerynix.com |
Whatever the sender puts in the message: name, email address, employer, and the content of the enquiry or rights request | Switzerland | Adequacy decision — the European Commission recognises Switzerland as providing an adequate level of protection, so no SCCs are required for this transfer | Proton DPA at proton.me/legal/dpa |
| Lead intake — no additional processor verified 2026-08-24 |
The demo-request form is delivered as an email to our own company mailbox, by a Cloudflare Worker using Cloudflare Email Routing. No messaging service, CRM or third-party webhook is involved: the two parties that handle it are Cloudflare and Proton, both already listed above. Cloudflare Email Routing can only send to an address verified as a destination in our account, so this path is technically incapable of forwarding your enquiry anywhere else. | Name, email address, employer, organisation size and the message you write | Cloudflare edge (global) then Switzerland (mailbox) | As per the Cloudflare and Proton rows above — no separate transfer | As per the Cloudflare and Proton rows above |
| Payment provider — planned, not engaged | Merchant of record for the managed subscription (checkout, payment processing, EU VAT handling). The integration is implemented in our control plane but no Paddle account exists and the webhook secret is unset in every environment, so no personal data has been or is being sent; the endpoint refuses unverifiable events. This row will be completed, and notice given under the DPA, before any payment can be taken. | Purchaser billing contact and payment data collected by Paddle at checkout; subscription and invoice records | Not applicable until engaged — this row is completed here before the feature is switched on | Not applicable until engaged — this row is completed here before the feature is switched on | Not applicable until engaged — this row is completed here before the feature is switched on |
| Transactional email provider — planned, not engaged | Sending account / system emails (verification, notifications) — to be confirmed once transactional email is wired in production; nothing is sent today | Recipient email address, email content | Not applicable until engaged — this row is completed here before the feature is switched on | Not applicable until engaged — this row is completed here before the feature is switched on | Not applicable until engaged — this row is completed here before the feature is switched on |
Notes
- Data residency: primary storage is in the EU (Hetzner / Germany). Cloudflare operates a global edge; personal data may transit non-EEA edge nodes, covered by SCC / DPF.
- Change process: additions / replacements are notified per the DPA (§4) with 30 days' notice and a right to object on data-protection grounds.
- Self-hosted: Customer-operated deployments do not use these sub-processors for Customer Content unless the Customer chooses equivalent providers itself.
- Website: the marketing site (cerynix.com) is static, carries no
analytics and no tracking cookies, and every call to action on it is a
mailto:link — so it sets no cookie and engages no analytics or email sub-processor of its own. - Support portal: the portal (support.cerynix.com) is also static and analytics-free, but it is not script-free: three pages load a same-origin JavaScript file (status probing, the contact form, and client-side documentation search) and nothing is loaded from any third party. Its contact page hosts a real form, not a mail link: submissions go to our own Cloudflare Pages function and are forwarded to the lead-intake notification recipient listed in the table above. Only the free-text and identity fields the sender fills in are collected, plus an edge country code — see that row for the exact categories.