Sub-processors
Effective: 22 September 2026 · Last updated: 22 September 2026
Strimium S.R.L. ("legivel") uses the providers below. The first table lists providers that process personal data on our behalf — for our own processing of account, billing and support data, and as sub-processors under our Data Processing Agreement for data in customer documents. The second table lists providers that act as independent controllers.
Customer documents are processed in memory and never stored (see the Privacy Policy). Document content reaches only Hetzner, in the memory of our server, and Cloudflare, in transit; neither stores it.
Providers processing data on our behalf
| Provider | Purpose | Data | Location | Transfer safeguard |
|---|---|---|---|---|
| Hetzner Online GmbH | Server hosting (Falkenstein) and encrypted backups (Helsinki) | All service data; document content in server memory only | Falkenstein, Germany; Helsinki, Finland | Not required (EEA) |
| Cloudflare, Inc. | Content delivery, TLS termination, DDoS protection, bot protection (Turnstile) | All request traffic, including IP addresses and document content in transit | Global network | EU Standard Contractual Clauses; EU–US Data Privacy Framework where certified |
| Resend, Inc. | Transactional and account email delivery | Email addresses, email content | EU region (Ireland) | EU Standard Contractual Clauses; EU–US Data Privacy Framework where certified |
| Google (Google Workspace) | Support and business email, including support@ and report@ | Messages and addresses of people who write to us | Global | EU Standard Contractual Clauses; EU–US Data Privacy Framework where certified |
| Google (Google Analytics 4) | Website analytics, only after consent (see the Cookie Policy) | Online identifiers, usage events | Global | EU Standard Contractual Clauses; EU–US Data Privacy Framework where certified |
| Better Stack, Inc. | Public status page (status.legivel.com), uptime checks and service monitoring | Technical telemetry under opaque identifiers; no customer data | EU | EU Standard Contractual Clauses where processing leaves the EEA |
Independent controllers
| Provider | Role |
|---|---|
| Our payment provider (merchant of record, named at checkout) | Sells subscriptions to you, processes payment and card data under its own terms and privacy policy |
| Sign-in with Google (OAuth) | |
| GitHub, Inc. | Sign-in with GitHub (OAuth) |
Changes to this list
We will update this page and notify account holders by email at least 30 days before a new sub-processor begins processing personal data. If you object on reasonable data-protection grounds, you may terminate the affected service before the change takes effect, as set out in the Data Processing Agreement.