Legal

Sub-processors

Effective date: 9 June 2026Last updated: 9 June 2026Controller: MB Firmavis · company code 307941710

The short version— a summary; the full text below governs.

  • 8 vendors help us run the service — hosting, payments, authentication, network delivery, analytics, email, verification, and error monitoring.
  • Application hosting and the primary database stay inside the EEA (Helsinki, Finland).
  • Transfers to US recipients rely on the EU-US Data Privacy Framework, with the 2021 Standard Contractual Clauses as fallback.
  • This page is updated before any new sub-processor takes effect — normally at least 30 days in advance.

This page lists the third-party service providers that MB Firmavis (Firmavis) engages to process personal data in connection with the service. Most act as our processors (sub-processors) on our documented instructions under Article 28 GDPR agreements; some additionally act as independent controllers for limited purposes of their own — for example payment regulation and fraud prevention, or a vendors own customer-account records — and these mixed roles are noted in the table. We publish this page for transparency in accordance with Articles 13(1)(e) and 14(1)(e) GDPR. It should be read together with our Privacy Policy.

1. Current sub-processors

Sub-processorServiceEntity locationProcessing locationTransfer mechanism
Hetzner Online GmbHApplication hosting and primary databaseGermanyHelsinki, FinlandIntra-EEA — no transfer mechanism required
Stripe Payments Europe, Ltd. / Stripe, Inc.Payment processing, tax calculation, billing and invoicing (engagement commences when payments go live; Stripe also processes payment data as an independent controller for its own regulatory and fraud-prevention purposes)Ireland (EEA) / United StatesIreland and United StatesEU-US Data Privacy Framework; 2021 SCCs as fallback
Clerk, Inc.User authentication and session management (Clerk also acts as an independent controller for limited account information of its own, as described in its DPA)United StatesUnited StatesEU-US Data Privacy Framework; 2021 SCCs as fallback
Cloudflare, Inc.Content delivery network, DDoS protection and web application firewallUnited StatesGlobal edge network, including EU points of presenceEU-US Data Privacy Framework; 2021 SCCs as fallback
Google Ireland Limited / Google LLCWebsite analytics (Google Analytics 4)Ireland (EEA) / United StatesIreland and United StatesEU-US Data Privacy Framework; 2021 SCCs as fallback
Plus Five Five, Inc. (Resend)Transactional email delivery (contact replies, export notices, data-removal confirmations, and GDPR Article 14 transparency notices — sent without open- or click-tracking)United StatesUnited States (primary)EU-US Data Privacy Framework; 2021 SCCs as fallback
GBD Software as a Service Private Limited Company (MillionVerifier)Business email-address deliverability verificationHungaryPrimarily Hungary (EEA); its policy permits processing outside the EEAIntra-EEA processing requires no mechanism; 2021 SCCs under its DPA for any non-EEA processing
Functional Software, Inc. (Sentry)Application error and performance monitoringUnited StatesUnited StatesEU-US Data Privacy Framework; 2021 SCCs as fallback

2. Changes and prior notice

We update this page before any new sub-processor that will process personal data takes effect — normally at least 30 days in advance — so that you have the opportunity to raise concerns. If we cannot resolve a reasonable objection, your remedy as a customer is to cancel your Subscription before the change takes effect; §13 of the Terms of Service applies.

3. How we engage sub-processors

We engage each sub-processor under a written data-processing agreement (Article 28(3) GDPR), incorporating, where applicable, the 2021 Standard Contractual Clauses for international transfers and the controller- processor terms required by Article 28(3) GDPR.

4. Transfers outside the EEA

Where a sub-processor processes personal data outside the European Economic Area, we rely on the EU-US Data Privacy Framework for DPF-certified recipients in the United States, with the 2021 Standard Contractual Clauses as a fallback. Data Privacy Framework certification status for U.S. sub-processors is verified against the official Data Privacy Framework list at dataprivacyframework.gov. The validity of the Framework is the subject of a pending appeal before the Court of Justice of the European Union; we monitor those proceedings and will update our transfer mechanisms if the legal position changes. Further detail on international transfers is in our Privacy Policy.

5. Contact

For any question about our sub-processors, contact us at [email protected].

MB Firmavis

Lithuanian company code: 307941710

Registered in the Register of Legal Entities of the Republic of Lithuania (administrator: State Enterprise Centre of Registers)

Registered office: Laisvės al. 85E-5, LT-44297 Kaunas, Lithuania

VAT number: LT100020426112

Privacy matters: [email protected]

General contact: [email protected]


This document is published in English. Translations into other supported languages may be published at a corresponding translated URL under /legal. In the event of any discrepancy between the English version and any translation, the English version prevails to the extent permitted by applicable law.

Back to top

Privacy questions: [email protected]