visz.ai

Subprocessors (Annex 2 to the DPA)

We use the following subprocessors. The list is part of the Data Processing Agreement (DPA).

SubprocessorPurposeLocationTransfer basisActive?
Hetzner Online GmbHHosting and object storageDE (Falkenstein/Nuremberg)EU — DPA Art. 28yes
ResendEmail (transactional)EU region Frankfurt (US parent)EU processing; US parent no routine access; support access via SCCyes
SentryError tracking (Visz-internal errors only)EU FrankfurtEU — DPAyes
Grafana CloudMetrics and logsEU regionDPA to be obtained before beta; SCC (US parent)yes
Better StackStatus page and SLA probeEU regionDPA to be obtained before beta; SCC (US parent)yes
Zoho MailSupport inbox info@visz.aiEU region (Amsterdam)DPA to be obtained before beta; SCCyes
CloudflareCDN (visz.ai marketing site only)globalDPF adequacy and SCCyes
GitHub ActionsCI/CDUSSCC — NEVER production/customer datayes
MaxMind GeoLite2Geo lookuplocal on own serverNOT a subprocessor (no external call)documented

Note: MaxMind GeoLite2 runs as a local database without any external call and is therefore not a subprocessor within the meaning of Art. 28. rrweb runs in the visitor's browser and is also not a subprocessor (code in the snippet, not a service provider).

Optional / conditional subprocessors

These are only listed when actually enabled:

  • Cloudflare R2 — optional object-storage backup (EU; DPA/SCC).
  • Vercel — optional marketing deploy (US; SCC; not a processor if marketing site only).
  • Slack — only if the customer connects an integration (US; the customer picks the channel and is responsible).
  • Postmark — optional mail backup (EU; Resend is primary).

Update process

New or changed subprocessors are announced to active customers with 30 days' prior notice. The controller has a right to object (DPA § 6). The list is versioned.

Subprocessors — visz.ai