Legal

Sub-processor List

Version 2.1Effective: 4/6/2026Updated: 7/30/2026
DRAFT — pending legal review. Not a final legal document. This document is missing legally required trader identification.

We use the processors below to run the Service. Each is bound by a written data-processing agreement under Article 28 GDPR. This page is the current list; we update it when a processor is added or removed.

Current processors

Processor | What it does | Data involved | Processing location

Transfers outside the EEA

Where a processor above processes data outside the European Economic Area, the transfer relies on the European Commission's adequacy decision for the EU-US Data Privacy Framework (Article 45 GDPR) where the recipient is certified under it, with Standard Contractual Clauses (Article 46(2)(c) GDPR) incorporated in each agreement as a fallback. We maintain the fallback because the adequacy decision is under appeal before the Court of Justice (Case C-703/25 P). A transfer impact assessment is on file and a copy of the safeguards is available on request.

Changes

We will update this page before a new processor starts handling personal data, or as soon as reasonably possible where a change is urgent. If you want to be told when this list changes, write to dpo@safeguardmdm.it.

Contact