Subprocessors & Providers
Effective: 31 August 2026 · Version 2026-08-31
1. Cloudflare
The production account must incorporate Cloudflare’s applicable Data Processing Addendum. Transfers outside the EEA must rely on a valid Chapter V GDPR mechanism, such as the EU–US Data Privacy Framework where applicable or Standard Contractual Clauses with supplementary measures. See the Cloudflare DPA and Privacy Policy.
3. Dropbox selected by the Customer
Business, public-sector, school or association customers must verify that their Dropbox account and contract provide the processing terms, location and transfer safeguards required for their use.
2. Google Drive selected by the Customer
Business, public-sector, school or association customers should use an account and contract that provide the required Art. 28 GDPR terms, commonly an eligible Google Workspace arrangement. A personal consumer Drive account must not be presented as providing a business AVV/DPA and may be unsuitable where the Customer requires a processor under Art. 28 GDPR. The Customer remains responsible for this provider choice.
Google may process data outside the EEA. The Customer must verify the applicable Data Processing Addendum, data-region options and Chapter V transfer mechanism. See the Google Workspace Data Processing Amendment and Google Privacy Policy.
3. Operator-managed Google storage
Operator-managed Google Drive should not be used as SnapKey’s production managed-storage service unless the exact business account is covered by an appropriate Art. 28 agreement and has been documented here as a subprocessor. The intended managed-storage backend is Cloudflare R2 with EU jurisdiction; any temporary operator Google Drive connection must be removed after migration and verified deletion.
4. PayPal payment services
See PayPal’s Privacy Statement.
5. Changes and objections
SnapKey will update this register before adding or replacing a subprocessor that processes Customer personal data. Customers should receive reasonable advance notice and may object on substantiated data-protection grounds under the Data Processing Agreement. Emergency changes required for security or legal compliance may be notified as soon as reasonably possible.
6. Contact
Questions about providers, transfer safeguards or the current production configuration can be submitted through the contact form.