Sub-processors
Last updated: 2026-05-14
A sub-processor is a vendor we engage to help us deliver PrintingPay. Under GDPR Article 28(2) and the equivalent CCPA service-provider terms, we list our sub-processors so that broker tenants and end users can see who else may receive personal data on our behalf and on what legal basis. This list is the canonical disclosure referenced by Section 7.4 of our Privacy Policy.
For each sub-processor below we publish four data points: vendor name, service and category of data processed, country (or countries) of processing, and the transfer mechanism in force when personal data leaves the European Economic Area, the United Kingdom, or Switzerland. Each vendor is contractually bound to confidentiality, security, and use-restriction terms equivalent to or stricter than our Privacy Policy.
| Vendor | Service & data category | Data processed | Country of processing | Transfer mechanism |
|---|---|---|---|---|
| Stripe, Inc. | Payment processing (cards, ACH, Cash App, Link) | Cardholder name, billing address, last-four PAN, transaction metadata | United States | EU-US DPF + EU SCC Module 2 (fallback) + UK IDTA + Swiss SCC |
| Block, Inc. (Square) | Payment processing (cards, Cash App Pay) | Cardholder name, billing address, last-four PAN, transaction metadata | United States | EU-US DPF + EU SCC Module 2 (fallback) + UK IDTA + Swiss SCC |
| PayPal Holdings, Inc. | Payment processing (PayPal wallet, PayPal Pay Later) | Customer email, transaction metadata | United States | EU SCC Module 2 + UK IDTA + Swiss SCC |
| Cloudflare, Inc. | CDN, DNS, edge WAF, DDoS protection | Request metadata, IP address, browser user-agent | Global edge with United States primary | EU-US DPF + EU SCC Module 2 (fallback) + UK IDTA + Swiss SCC |
| Contabo GmbH | Application and database hosting (production primary + standby) | All Service data at rest and in transit through the host | European Union (Nuremberg, Germany) and United States (Saint Louis, MO) | N/A — EU-hosted for EEA/UK/CH operator data; EU SCC Module 3 for the US standby leg |
| Contabo Object Storage | Operator file uploads, artwork assets, backup snapshots | Uploaded artwork files, generated PDFs, encrypted backup archives | European Union (EU-central) and United States (US-central) | N/A — EU-hosted for EEA/UK/CH operator data; EU SCC Module 3 for the US-central storage class |
| M13 Vendor Portal | Vendor printing fulfillment (gangrun, printbrokersinc) | Ship-to name, address, order metadata, print-job specifications | United States | EU SCC Module 3 + UK IDTA + Swiss SCC |
| FedEx Corporation | Shipping rate quotes and label generation | Ship-to name, address, package dimensions, weight | United States | EU-US DPF + EU SCC Module 3 (fallback) + UK IDTA + Swiss SCC |
| Google LLC (Workspace) | Internal corporate email and document storage for Black Asterisk LLC staff | Operator support correspondence routed to PrintingPay staff | United States | EU-US DPF + EU SCC Module 2 (fallback) + UK IDTA + Swiss SCC |
| Infisical (self-hosted on Contabo) | Secrets management — vault for service credentials and API keys | Service credentials, API keys, machine identities (no end-user PII) | European Union | N/A — self-hosted |
| Glitchtip / Sentry-API (self-hosted on Contabo) | Application error tracking and performance telemetry | Request metadata, stack traces, scrubbed user identifiers | European Union | N/A — self-hosted |
| Mailcow community edition (self-hosted on Contabo) | Outbound transactional email | Recipient email address, message subject and body | European Union | N/A — self-hosted |
| Listmonk (self-hosted on Contabo) | Operator broadcast and announcement email | Operator email address, opt-in status, message body | European Union | N/A — self-hosted |
| PostgreSQL (self-hosted on Contabo) | Primary application database | All Service data — encrypted at rest, encrypted in transit | European Union | N/A — self-hosted |
| MinIO (self-hosted on Contabo) | S3-compatible object storage for build artifacts and backup egress | Encrypted backup archives, CI build artifacts | European Union | N/A — self-hosted |
Self-hosted vendors
Where a sub-processor is annotated “self-hosted on Contabo,” the underlying software is open-source and the compute is operated by Black Asterisk LLC inside Contabo VPS instances we control. The vendor name in the table refers to the upstream software project. No production data leaves Contabo infrastructure for those services, so the international transfer mechanism column reads “N/A — self-hosted.”
Transfer mechanisms in force
The transfer-mechanism column uses a short, consistent vocabulary that maps to the full legal instruments described in Section 7.3 of the Privacy Policy:
- EU SCC Module 2 — Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module 2 (Controller-to-Processor). PrintingPay is the controller, vendor is the processor.
- EU SCC Module 3 — Same SCC instrument, Module 3 (Processor-to-Sub-Processor). Used when PrintingPay processes broker-tenant personal data as their processor and onward-transfers it to a sub-processor.
- EU-US DPF — EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795). Listed as the primary safeguard for vendors that are self-certified to the Framework; the corresponding SCC Module operates as the fallback safeguard.
- UK IDTA — UK International Data Transfer Addendum to the EU Commission SCCs, issued under section 119A of the Data Protection Act 2018 and in force 21 March 2022. Executed alongside the EU SCCs for UK transfers.
- Swiss SCC — EU SCCs with the Swiss-specific amendments published by the Federal Data Protection and Information Commissioner (FDPIC) on 27 August 2021, applying Swiss FADP terminology and FDPIC supervisory authority.
- N/A — US-only — Vendor receives personal data collected directly in the United States; no cross-border transfer in the Article 44 sense occurs.
- N/A — EU-hosted — Vendor operates entirely in the European Union; no third-country transfer occurs.
- N/A — self-hosted — Service runs on Contabo infrastructure owned and operated by Black Asterisk LLC; no transfer to an external processor occurs at the platform layer.
Notice of changes
We will provide at least 30 days’ advance notice to broker tenants who have signed our Data Processing Agreement before a new sub-processor begins processing the tenant’s personal data, or before an existing sub-processor is replaced in a way that materially changes the data category, country of processing, or transfer mechanism. Notice is delivered by email to the tenant’s account administrators and by an update to this page reflected in the “Last updated” date above. Broker tenants may object to a new sub-processor through the objection procedure in their executed Data Processing Agreement.
A copy of the executed transfer mechanism for any named sub-processor is available on request from [email protected].
Contact
Questions, objections, or requests for the executed transfer mechanism for a named sub-processor should be sent to [email protected].
Return to the Privacy Policy for the full disclosure framework that this page implements.