1. About This List
A sub-processor is a third party we engage that processes personal data on your behalf in the course of providing the Service. Article 28(2) of the GDPR requires us to tell you who they are and to give you the chance to object before we add a new one.
This list covers sub-processors engaged for all customers. Integrations you switch on yourself are listed separately in Section 3, because we are not the party engaging them — you are.
2. Current Sub-processors
Complete as of July 28, 2026. Sub-processors marked Essential cannot be disabled without the Service ceasing to function.
Stripe
Stripe, Inc. (United States) and Stripe Payments Europe, Ltd. (Ireland)
- Purpose
- Payment processing, Stripe Connect authorisation, retry execution against the card networks, and platform subscription billing.
- Data accessed
- End-user name, email, Stripe customer/invoice/subscription IDs, card metadata (brand, last four, expiry), payment outcomes. Full card numbers are held by Stripe and never reach our systems.
- Location
- United States, Ireland
- Transfer basis
- EU Standard Contractual Clauses; EU–U.S. Data Privacy Framework
DigitalOcean — Managed PostgreSQL
DigitalOcean, LLC
- Purpose
- Primary application database. Stores account records, campaign configuration, payment-attempt history, and email events.
- Data accessed
- All Customer Data and End-User Data stored by the Service.
- Location
- United States (region selected at provisioning)
- Transfer basis
- EU Standard Contractual Clauses
DigitalOcean Spaces
DigitalOcean, LLC
- Purpose
- Object storage for uploaded brand logos and exported reports.
- Data accessed
- Brand assets and generated export files, which may contain end-user identifiers.
- Location
- United States
- Transfer basis
- EU Standard Contractual Clauses
Resend
Resend, Inc.
- Purpose
- Transactional and recovery email delivery, bounce and complaint handling, open and click event capture.
- Data accessed
- Recipient email address and name, message subject and body, delivery/open/click events, IP address of the opening client.
- Location
- United States
- Transfer basis
- EU Standard Contractual Clauses
Google Gemini (Generative Language API)
Google LLC
- Purpose
- Generates personalised recovery email subject lines and body copy from campaign context.
- Data accessed
- Brand description and tone, invoice amount and currency, decline reason, and — where the template includes them — end-user first name and product name. Prompts are not used to train Google's models under the paid API terms.
- Location
- United States
- Transfer basis
- EU Standard Contractual Clauses
Google Analytics 4
Google LLC
- Purpose
- Aggregate traffic measurement on the public marketing pages only. Never loaded inside the authenticated dashboard.
- Data accessed
- Truncated IP address, device and browser metadata, page-view events.
- Location
- United States
- Transfer basis
- EU Standard Contractual Clauses; EU–U.S. Data Privacy Framework
Application hosting
The hosting provider operating the production environment
- Purpose
- Runs the Next.js application server and scheduled jobs; retains web-server access logs.
- Data accessed
- Request metadata and IP addresses in access logs; all data in transit through the application.
- Location
- United States
- Transfer basis
- EU Standard Contractual Clauses
3. Customer-Enabled Integrations
These are inactive unless you turn them on. When you do, you are sending your own data to a vendor of your own choosing, and you are the controller for that transfer — we are not engaging them as our sub-processor.
| Integration | Purpose | Note |
|---|---|---|
| Slack | Payment-failure and recovery alerts to a channel you nominate. | Active only if you configure an incoming webhook URL. Data flows directly to your workspace. |
| Outbound webhooks (Zapier, Make.com, n8n, custom endpoints) | Delivers payment.failed / payment.recovered / payment.exhausted events as JSON. | Active only if you register an endpoint. You are the controller for whatever receives it. |
| Custom SMTP | Sends recovery email through your own mail server instead of ours. | If configured, Resend is bypassed for your outbound mail. Credentials are encrypted with AES-256-GCM at rest. |
4. International Transfers
Our infrastructure is hosted in the United States. Where personal data originating in the EEA, the United Kingdom, or Switzerland is transferred to a sub-processor, the transfer is covered by the European Commission’s Standard Contractual Clauses (Decision 2021/914), together with the UK International Data Transfer Addendum where UK data is involved.
Where a sub-processor is additionally certified under the EU–U.S. Data Privacy Framework, that certification supplements — but does not replace — the contractual clauses. We conduct a transfer impact assessment before engaging a new sub-processor outside the EEA.
5. Notice of Changes
Before a new sub-processor begins processing personal data, we will give at least 30 days’notice by email to the address on the account owner’s profile, and update this page.
To receive these notices, keep your account owner email current. We do not operate a separate subscription list — the notice goes to the address we already hold.
In the exceptional case where a sub-processor must be replaced immediately to preserve the security or availability of the Service, we will notify you as soon as practicable and no later than 5 business days after the change.
6. Right to Object
You may object to a new sub-processor on reasonable data-protection grounds by emailing legal@paymentrecoverysystem.com within the notice period, stating the grounds.
We will work with you in good faith to find a commercially reasonable alternative — for example, disabling the feature that depends on the sub-processor. Where no alternative is available and the objection is well-founded, you may terminate the affected part of the Service on written notice and receive a pro-rata refund of prepaid fees for the unused remainder of the term.
7. Our Diligence Process
Before engaging a sub-processor we:
- Review its security posture and any published audit reports or certifications;
- Execute a written data-processing agreement imposing obligations no less protective than those in our own DPA;
- Confirm a valid transfer mechanism where data leaves the EEA or the UK;
- Limit the data it receives to what that specific function requires.
We remain fully liable to you for a sub-processor’s performance of its data-protection obligations, as Article 28(4) requires.
8. Contact
Payment Recovery System — Data Protection
Sub-processor questions and objections: legal@paymentrecoverysystem.com
Privacy requests: privacy@paymentrecoverysystem.com
Related: Data Processing Agreement · Privacy Policy · Security