Sub-processors

Effective July 28, 2026 · Last updated July 28, 2026

Payment Recovery System engages the third parties below to help deliver the Service. This page is the authoritative list referenced by Annex III of our Data Processing Agreement.
30-day advance noticeSCCs for all transfersGDPR Art. 28(2)

1. About This List

A sub-processor is a third party we engage that processes personal data on your behalf in the course of providing the Service. Article 28(2) of the GDPR requires us to tell you who they are and to give you the chance to object before we add a new one.

This list covers sub-processors engaged for all customers. Integrations you switch on yourself are listed separately in Section 3, because we are not the party engaging them — you are.


2. Current Sub-processors

Complete as of July 28, 2026. Sub-processors marked Essential cannot be disabled without the Service ceasing to function.

Stripe

Stripe, Inc. (United States) and Stripe Payments Europe, Ltd. (Ireland)

Essential
Purpose
Payment processing, Stripe Connect authorisation, retry execution against the card networks, and platform subscription billing.
Data accessed
End-user name, email, Stripe customer/invoice/subscription IDs, card metadata (brand, last four, expiry), payment outcomes. Full card numbers are held by Stripe and never reach our systems.
Location
United States, Ireland
Transfer basis
EU Standard Contractual Clauses; EU–U.S. Data Privacy Framework

DigitalOcean — Managed PostgreSQL

DigitalOcean, LLC

Essential
Purpose
Primary application database. Stores account records, campaign configuration, payment-attempt history, and email events.
Data accessed
All Customer Data and End-User Data stored by the Service.
Location
United States (region selected at provisioning)
Transfer basis
EU Standard Contractual Clauses

DigitalOcean Spaces

DigitalOcean, LLC

Optional
Purpose
Object storage for uploaded brand logos and exported reports.
Data accessed
Brand assets and generated export files, which may contain end-user identifiers.
Location
United States
Transfer basis
EU Standard Contractual Clauses

Resend

Resend, Inc.

Essential
Purpose
Transactional and recovery email delivery, bounce and complaint handling, open and click event capture.
Data accessed
Recipient email address and name, message subject and body, delivery/open/click events, IP address of the opening client.
Location
United States
Transfer basis
EU Standard Contractual Clauses

Google Gemini (Generative Language API)

Google LLC

Optional
Purpose
Generates personalised recovery email subject lines and body copy from campaign context.
Data accessed
Brand description and tone, invoice amount and currency, decline reason, and — where the template includes them — end-user first name and product name. Prompts are not used to train Google's models under the paid API terms.
Location
United States
Transfer basis
EU Standard Contractual Clauses

Google Analytics 4

Google LLC

Optional
Purpose
Aggregate traffic measurement on the public marketing pages only. Never loaded inside the authenticated dashboard.
Data accessed
Truncated IP address, device and browser metadata, page-view events.
Location
United States
Transfer basis
EU Standard Contractual Clauses; EU–U.S. Data Privacy Framework

Application hosting

The hosting provider operating the production environment

Essential
Purpose
Runs the Next.js application server and scheduled jobs; retains web-server access logs.
Data accessed
Request metadata and IP addresses in access logs; all data in transit through the application.
Location
United States
Transfer basis
EU Standard Contractual Clauses

3. Customer-Enabled Integrations

These are inactive unless you turn them on. When you do, you are sending your own data to a vendor of your own choosing, and you are the controller for that transfer — we are not engaging them as our sub-processor.

IntegrationPurposeNote
SlackPayment-failure and recovery alerts to a channel you nominate.Active only if you configure an incoming webhook URL. Data flows directly to your workspace.
Outbound webhooks (Zapier, Make.com, n8n, custom endpoints)Delivers payment.failed / payment.recovered / payment.exhausted events as JSON.Active only if you register an endpoint. You are the controller for whatever receives it.
Custom SMTPSends recovery email through your own mail server instead of ours.If configured, Resend is bypassed for your outbound mail. Credentials are encrypted with AES-256-GCM at rest.

4. International Transfers

Our infrastructure is hosted in the United States. Where personal data originating in the EEA, the United Kingdom, or Switzerland is transferred to a sub-processor, the transfer is covered by the European Commission’s Standard Contractual Clauses (Decision 2021/914), together with the UK International Data Transfer Addendum where UK data is involved.

Where a sub-processor is additionally certified under the EU–U.S. Data Privacy Framework, that certification supplements — but does not replace — the contractual clauses. We conduct a transfer impact assessment before engaging a new sub-processor outside the EEA.


5. Notice of Changes

Before a new sub-processor begins processing personal data, we will give at least 30 days’notice by email to the address on the account owner’s profile, and update this page.

To receive these notices, keep your account owner email current. We do not operate a separate subscription list — the notice goes to the address we already hold.

In the exceptional case where a sub-processor must be replaced immediately to preserve the security or availability of the Service, we will notify you as soon as practicable and no later than 5 business days after the change.


6. Right to Object

You may object to a new sub-processor on reasonable data-protection grounds by emailing legal@paymentrecoverysystem.com within the notice period, stating the grounds.

We will work with you in good faith to find a commercially reasonable alternative — for example, disabling the feature that depends on the sub-processor. Where no alternative is available and the objection is well-founded, you may terminate the affected part of the Service on written notice and receive a pro-rata refund of prepaid fees for the unused remainder of the term.


7. Our Diligence Process

Before engaging a sub-processor we:

  • Review its security posture and any published audit reports or certifications;
  • Execute a written data-processing agreement imposing obligations no less protective than those in our own DPA;
  • Confirm a valid transfer mechanism where data leaves the EEA or the UK;
  • Limit the data it receives to what that specific function requires.

We remain fully liable to you for a sub-processor’s performance of its data-protection obligations, as Article 28(4) requires.


8. Contact

Payment Recovery System — Data Protection

Sub-processor questions and objections: legal@paymentrecoverysystem.com

Privacy requests: privacy@paymentrecoverysystem.com

Related: Data Processing Agreement · Privacy Policy · Security