DutchBSD B.V.
Subprocessors and Service Providers
Version 1.00 · Effective 27 August 2026
Document versions: 1.00 · 1.01
This document is available in English.
This page identifies providers integrated by DutchBSD Workspace and the processing they may perform. A provider is a subprocessor only to the extent it processes Customer Personal Data for DutchBSD; some providers act as independent controllers for parts of their service.
| Provider | Function | Primary location / transfer position | Status |
|---|---|---|---|
| Hetzner | Production compute, database and application storage. | Germany / EEA for the selected production region. | Production infrastructure; account contract and exact region require operator evidence. |
| Bunny | Generated-site storage, content delivery, custom-hostname delivery and related logs. | EEA provider; CDN processing can be distributed. Provider DPA and account settings govern transfers. | Integrated; exact zones, regions, logging and optional forwarding require dashboard evidence. |
| GitHub | Private customer site/project source and change history where remote repositories are enabled. | Global service with contractual transfer safeguards. | Integrated; exact organisation and enterprise terms require account evidence. |
| Resend | Transactional account, security, billing and support email. | United States provider using contractual transfer safeguards. | Integrated; sending account and DPA require operator evidence. |
| Stripe | Checkout, subscriptions, invoices, payment and fraud prevention. | EEA and global processing under Stripe's applicable privacy and transfer terms. | Payment provider; may act as an independent controller and processor depending on the operation. |
| Cloudflare Turnstile | Bot and abuse protection for public submission flows when enabled. | Global service with contractual transfer safeguards. | Feature-configured; include in the active list only when production configuration enables it. |
Changes
DutchBSD gives affected business customers at least 30 days' notice before a new subprocessor starts materially different Customer Personal Data processing. Contact privacy@dutchbsd.com for current transfer information or to raise a reasonable data-protection objection.
Operational verification: this first publication reflects repository integrations. Before treating the status column as production evidence, the operator must verify the contracted entity, account, selected region, DPA/SCC version, optional logging/forwarding and deletion settings in each vendor dashboard.