Legal
Subprocessor List
Subprocessor List
Plain-language summary
This list must be completed before public use with real personal data. The reviewed code does not require advertising, analytics, social-media, map or tracking providers, but operations may require hosting, email, backup and possibly proxy/DNS providers.
Active subprocessors and operating providers
| Provider | Purpose | Data categories | Country/region | DPA/status | Retention/deletion |
|---|---|---|---|---|---|
| Self-hosted server | App and database hosting | Account, time, GPS/IP, pay estimates, audit, logs | Denmark / EU/EEA | Not an external provider; internal operation must be documented | According to the retention policy |
| OVH / Zimbra | SMTP/email for verification, password reset and app emails | Email address, subject, message, delivery metadata | Must be confirmed before public launch | DPA/provider terms must be verified | According to provider terms and app retention |
| Other self-hosted backup server | Encrypted backups | Encrypted database backup and metadata | Denmark or EU/EEA preferred | Not an external provider if owned/controlled by the operator; operation must be documented | 12 months encrypted |
| OVHcloud | DNS for the domain | Domain and DNS metadata | Must be confirmed before public launch | Provider terms/DPA status must be verified | According to provider terms |
| Let’s Encrypt | TLS certificates | Domain name and certificate metadata | Global CA infrastructure | Certificate authority; not ordinary app data processor | According to certificate/CA practice |
No external reverse proxy/CDN is used for the production app according to the owner decision.
Configured example, not automatically active by default
Repository documentation mentions mail.taxoz.org as a current live SMTP profile example. It should not be listed as an active public subprocessor unless the owner confirms it is used in production and provider role/DPA/location are documented.
Not used at launch according to owner decision
- advertising cookies;
- marketing cookies;
- ad targeting;
- analytics trackers;
- social-media pixels;
- third-party fonts;
- map providers;
- external error tracking;
- external monitoring/logging;
- payment provider at launch.
Donations or payments may be added later through an external payment provider. Before activation, the terms, privacy policy, cookie policy and this list must be updated.
Contact
Questions: support@fejlgoblin.ovh