Sub-processor List

Last updated: October 4, 2026

This page lists the third parties that may process personal data on our behalf when we provide the Smailor service. It is the list referred to in Section 5 of our DPA and summarised on our Trust page.

Our core hosting, mail storage, and backups are in the European Union. The transfers listed below are limited to the specific purposes named.

1. Infrastructure and platform

Sub-processor Purpose Location Transfer mechanism
Hetzner Online GmbH Servers, storage, networking, backups 🇩🇪 Germany / 🇫🇮 Finland (EU) Within EEA — no transfer
Cloudflare, Inc. DNS, CDN, WAF, bot protection (Turnstile) 🇺🇸 USA Standard Contractual Clauses
Self-hosted inference (Ollama-compatible) AI drafting, triage, classification, translation, clustering, abuse detection 🇩🇪 Germany — infrastructure we operate No transfer outside the EEA

2. Payments

Sub-processor Purpose Location Transfer mechanism
Mollie B.V. Subscription and marketplace payment processing (billing data only) 🇳🇱 Netherlands (EU entity) Within EEA

We do not store full payment card numbers or seller bank-account credentials supplied to a payment provider.

3. Email delivery

Sub-processor Purpose Location Transfer mechanism
Resend (Plus Five Five, Inc.) Transactional, notification, and verification email delivery 🇺🇸 USA Standard Contractual Clauses

Outbound customer mail may also be delivered directly by our own mail infrastructure and sending nodes in the EU.

Proposed Telecom/SMS provider — not yet active

Opportunity (AllMySMS) is the proposed primary provider for SMS routing, delivery receipts, and optional replies. It would receive recipient numbers, sender identifiers, SMS content, and delivery metadata. The provider states that it hosts customer data in France; carrier delivery, especially to an international number, can involve other countries. This entry announces a proposed provider; it does not state that Telecom sales or SMS sending are live. Before activation we must verify the contracting entity, Article 28 terms, onward processors, retention, transfer safeguards, and the 14-day change-notice procedure in Section 7. The existing OVH route is configured as a disabled fallback and must undergo the same review before use.

These services support spam, phishing, and malware detection. Where a check requires it, a URL extracted from message content, or a sending domain or IP address, is transmitted to the service.

Sub-processor Purpose Location Transfer mechanism
Google LLC (Safe Browsing) URL reputation lookups for links found in mail 🇺🇸 USA Standard Contractual Clauses
The Spamhaus Project / Spamhaus Technology Ltd. Sender IP and domain reputation (DQS) 🇬🇧 United Kingdom / 🇨🇭 Switzerland UK and Swiss adequacy decisions
abuse.ch (URLhaus) Malicious URL reputation lookups 🇨🇭 Switzerland Adequacy decision

Results are cached for a limited operational period. See DPA Section 8 for what this means for transfers.

5. Identity and integrations you choose to connect

These process data only where you enable the relevant sign-in method or integration.

Sub-processor Purpose Location Transfer mechanism
Google Ireland Ltd. / Google LLC Google sign-in; Gmail integration where you connect it 🇮🇪 Ireland / 🇺🇸 USA Standard Contractual Clauses
Discord Netherlands B.V. / Discord Inc. Discord sign-in. Email you choose to copy to your own Discord channel goes to a recipient you select, not to a sub-processor engaged by Smailor (Terms, Section 10.1) 🇳🇱 Netherlands / 🇺🇸 USA Standard Contractual Clauses where applicable
Your calendar provider (Apple, Google, or another CalDAV host) Calendar display, creation, and sharing where you connect it Depends on the provider you choose Your own relationship with that provider

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. See the Privacy Policy.

6. Providers you bring yourself — not our sub-processors

Where you supply credentials for a sending provider, that provider processes data for you, under your own agreement with it. We transmit the data on your instruction, but we do not appoint the provider, do not control its processing, and are not responsible for it. This applies to, among others:

  • Brevo (Sendinblue SAS)
  • Mailjet (Sinch Email)
  • Resend, where you use your own account rather than ours
  • any SMTP server you nominate

The same applies to any third-party account you connect with your own credentials.

7. Changes to this list

We will post an updated list here and at smailor.com/trust at least 14 days before adding or replacing a sub-processor that processes customer data, and will notify business customers by email where possible. If you have a DPA with us, you may object on reasonable data-protection grounds within that period by writing to [email protected]; if we cannot resolve the objection, you may terminate the affected service without penalty.

Urgent replacements required for security, legal, or continuity reasons may take effect sooner, and we will tell you as soon as we can.

8. Contact

[email protected] — for sub-processor questions, objections, or a copy of the signed DPA.