Last updated: October 4, 2026
This page lists the third parties that may process personal data on our behalf when we provide the Smailor service. It is the list referred to in Section 5 of our DPA and summarised on our Trust page.
Our core hosting, mail storage, and backups are in the European Union. The transfers listed below are limited to the specific purposes named.
1. Infrastructure and platform
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Hetzner Online GmbH | Servers, storage, networking, backups | 🇩🇪 Germany / 🇫🇮 Finland (EU) | Within EEA — no transfer |
| Cloudflare, Inc. | DNS, CDN, WAF, bot protection (Turnstile) | 🇺🇸 USA | Standard Contractual Clauses |
| Self-hosted inference (Ollama-compatible) | AI drafting, triage, classification, translation, clustering, abuse detection | 🇩🇪 Germany — infrastructure we operate | No transfer outside the EEA |
2. Payments
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Mollie B.V. | Subscription and marketplace payment processing (billing data only) | 🇳🇱 Netherlands (EU entity) | Within EEA |
We do not store full payment card numbers or seller bank-account credentials supplied to a payment provider.
3. Email delivery
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Resend (Plus Five Five, Inc.) | Transactional, notification, and verification email delivery | 🇺🇸 USA | Standard Contractual Clauses |
Outbound customer mail may also be delivered directly by our own mail infrastructure and sending nodes in the EU.
Proposed Telecom/SMS provider — not yet active
Opportunity (AllMySMS) is the proposed primary provider for SMS routing, delivery receipts, and optional replies. It would receive recipient numbers, sender identifiers, SMS content, and delivery metadata. The provider states that it hosts customer data in France; carrier delivery, especially to an international number, can involve other countries. This entry announces a proposed provider; it does not state that Telecom sales or SMS sending are live. Before activation we must verify the contracting entity, Article 28 terms, onward processors, retention, transfer safeguards, and the 14-day change-notice procedure in Section 7. The existing OVH route is configured as a disabled fallback and must undergo the same review before use.
4. Anti-abuse, reputation, and link safety
These services support spam, phishing, and malware detection. Where a check requires it, a URL extracted from message content, or a sending domain or IP address, is transmitted to the service.
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Google LLC (Safe Browsing) | URL reputation lookups for links found in mail | 🇺🇸 USA | Standard Contractual Clauses |
| The Spamhaus Project / Spamhaus Technology Ltd. | Sender IP and domain reputation (DQS) | 🇬🇧 United Kingdom / 🇨🇭 Switzerland | UK and Swiss adequacy decisions |
| abuse.ch (URLhaus) | Malicious URL reputation lookups | 🇨🇭 Switzerland | Adequacy decision |
Results are cached for a limited operational period. See DPA Section 8 for what this means for transfers.
5. Identity and integrations you choose to connect
These process data only where you enable the relevant sign-in method or integration.
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Google Ireland Ltd. / Google LLC | Google sign-in; Gmail integration where you connect it | 🇮🇪 Ireland / 🇺🇸 USA | Standard Contractual Clauses |
| Discord Netherlands B.V. / Discord Inc. | Discord sign-in. Email you choose to copy to your own Discord channel goes to a recipient you select, not to a sub-processor engaged by Smailor (Terms, Section 10.1) | 🇳🇱 Netherlands / 🇺🇸 USA | Standard Contractual Clauses where applicable |
| Your calendar provider (Apple, Google, or another CalDAV host) | Calendar display, creation, and sharing where you connect it | Depends on the provider you choose | Your own relationship with that provider |
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. See the Privacy Policy.
6. Providers you bring yourself — not our sub-processors
Where you supply credentials for a sending provider, that provider processes data for you, under your own agreement with it. We transmit the data on your instruction, but we do not appoint the provider, do not control its processing, and are not responsible for it. This applies to, among others:
- Brevo (Sendinblue SAS)
- Mailjet (Sinch Email)
- Resend, where you use your own account rather than ours
- any SMTP server you nominate
The same applies to any third-party account you connect with your own credentials.
7. Changes to this list
We will post an updated list here and at smailor.com/trust at least 14 days before adding or replacing a sub-processor that processes customer data, and will notify business customers by email where possible. If you have a DPA with us, you may object on reasonable data-protection grounds within that period by writing to [email protected]; if we cannot resolve the objection, you may terminate the affected service without penalty.
Urgent replacements required for security, legal, or continuity reasons may take effect sooner, and we will tell you as soon as we can.
8. Contact
[email protected] — for sub-processor questions, objections, or a copy of the signed DPA.