Sub-processors
Last updated: September 25, 2026
These providers process personal data on our behalf to run Certrust. Each is bound by data-protection terms at least as protective as our Data Processing Agreement , which this list forms part of (Annex III).
We give customers at least 30 days' notice by email before adding or replacing a sub-processor. To object, write to privacy@certrust.app.
Cloudflare, Inc.
- Purpose
- Application hosting and containers, content delivery, DDoS protection, file storage (R2, including encrypted backups), sending credential and account emails, and routing emails sent to our addresses.
- Personal data
- All Service data in transit; uploaded files and backups; email addresses and email content.
- Location
- United States (company); global edge network; storage in the Asia-Pacific region.
Neon, Inc. (hosted on Amazon Web Services)
- Purpose
- Managed PostgreSQL database.
- Personal data
- All account, organisation and credential data.
- Location
- Singapore (AWS ap-southeast-1).
Stripe, Inc. and its affiliates
- Purpose
- Payment processing, subscriptions and invoices.
- Personal data
- Billing contact, billing email, payment card and transaction data (for paying customers only).
- Location
- United States, Ireland and other Stripe locations.
Google LLC
- Purpose
- Mailbox that receives messages sent to our support and privacy addresses. Website analytics (Google Analytics 4) only if enabled, only with the visitor's consent, and never on credential pages.
- Personal data
- Emails and attachments people send us; for analytics, pseudonymous usage data.
- Location
- United States and other Google locations.