Subprocessors
Version 1.0 · Effective 2026-09-18
This is a template drafted for VitalSite's launch. Confirm the actual hosting region for each provider before relying on it, and replace placeholders once real vendor contracts are in place.
A subprocessor is a third party we engage to help deliver the Service, who may process personal data on our behalf. Each subprocessor below operates under a data-processing agreement consistent with GDPR Art. 28.
| Subprocessor | Purpose | Location | Data categories |
|---|---|---|---|
| Vercel | Application hosting | EU/US | Request metadata, session cookies |
| PostgreSQL database host | Primary datastore | Configurable (EU recommended) | All application data |
| Cloudflare R2 | PDF report & evidence storage | EU-selectable | Generated reports, scan screenshots |
| Resend | Transactional email delivery | EU/US | Email address, notification content |
| Stripe | Payment processing & billing | EU/US | Billing contact, payment metadata (no card numbers stored by VitalSite) |
| Sentry | Error monitoring | EU/US | Technical error diagnostics, may incidentally include request metadata |
Change notifications
Before adding a new subprocessor that will process personal data, or replacing an existing one, we will update this page with the change and its effective date, and email organization owners at least 14 days in advance of that change taking effect. If you object to a new subprocessor, contact us at the address in our Privacy Notice before the effective date.
Changelog
- 2026-09-18 — Initial subprocessor list published.
Data Processing Agreement
If your organization requires a signed DPA (most do, under GDPR Art. 28), request one below — we will send it to your account email for countersignature.