You are offline. New time records can only be saved when the connection returns.

Legal

Subprocessor List

All documents Dansk
Version
owner-decision-draft-2026-07-07
Last updated
2026-07-07
Contact
support@fejlgoblin.ovh
SHA-256
81dda97a0e88ad25cc5275f8c8eb9cf313a154d16188b738dd58fbc352eede59

Subprocessor List

Plain-language summary

This list must be completed before public use with real personal data. The reviewed code does not require advertising, analytics, social-media, map or tracking providers, but operations may require hosting, email, backup and possibly proxy/DNS providers.

Active subprocessors and operating providers

ProviderPurposeData categoriesCountry/regionDPA/statusRetention/deletion
Self-hosted serverApp and database hostingAccount, time, GPS/IP, pay estimates, audit, logsDenmark / EU/EEANot an external provider; internal operation must be documentedAccording to the retention policy
OVH / ZimbraSMTP/email for verification, password reset and app emailsEmail address, subject, message, delivery metadataMust be confirmed before public launchDPA/provider terms must be verifiedAccording to provider terms and app retention
Other self-hosted backup serverEncrypted backupsEncrypted database backup and metadataDenmark or EU/EEA preferredNot an external provider if owned/controlled by the operator; operation must be documented12 months encrypted
OVHcloudDNS for the domainDomain and DNS metadataMust be confirmed before public launchProvider terms/DPA status must be verifiedAccording to provider terms
Let’s EncryptTLS certificatesDomain name and certificate metadataGlobal CA infrastructureCertificate authority; not ordinary app data processorAccording to certificate/CA practice

No external reverse proxy/CDN is used for the production app according to the owner decision.

Configured example, not automatically active by default

Repository documentation mentions mail.taxoz.org as a current live SMTP profile example. It should not be listed as an active public subprocessor unless the owner confirms it is used in production and provider role/DPA/location are documented.

Not used at launch according to owner decision

  • advertising cookies;
  • marketing cookies;
  • ad targeting;
  • analytics trackers;
  • social-media pixels;
  • third-party fonts;
  • map providers;
  • external error tracking;
  • external monitoring/logging;
  • payment provider at launch.

Donations or payments may be added later through an external payment provider. Before activation, the terms, privacy policy, cookie policy and this list must be updated.

Contact

Questions: support@fejlgoblin.ovh

Terms Privacy Cookies Data rights GPS/IP Disclaimer Contact Subprocessors Security and retention