Sub-processor List
Version 1.0 · Effective [LAUNCH DATE]
This page lists the third-party Sub-processors Closetforge engages to deliver the Service. We notify Customers at least thirty (30) days before adding or replacing a Sub-processor (see DPA Section 8). Customers can subscribe to update notifications by emailing privacy@closetforge.com.
Infrastructure
| Sub-processor | Service | Region | Transfer mechanism |
|---|
| Cloudflare, Inc. | CDN, DNS, DDoS protection, WAF | Global edge with EU primary | EU SCCs (2021/914), Module Three; DPF-certified |
| Cloudflare R2 | Object storage (textures, PDFs, thumbnails, brand assets) | EU jurisdiction (Ireland / Frankfurt) | Within EEA |
| Amazon Web Services (AWS) EMEA SARL | Database hosting (PostgreSQL via RDS), application servers | EU (Frankfurt — eu-central-1) | Within EEA; DPF-certified for any incidental US transfer |
Communication
| Sub-processor | Service | Region | Transfer mechanism |
|---|
| Twilio Ireland Limited | SMS one-time-password delivery | EU primary, global delivery | EU SCCs (2021/914) for any non-EEA delivery |
| Postmark / Resend / SendGrid (confirm choice) | Transactional email | EU primary | EU SCCs / DPF as applicable |
AI
| Sub-processor | Service | Region | Transfer mechanism |
|---|
| OpenAI Ireland Limited | LLM inference for AI chat (GPT-4.1 / GPT-5 family) | EU contracting entity, US processing | EU SCCs (2021/914) Module Three; data not used for training under enterprise terms |
Payments
| Sub-processor | Service | Region | Transfer mechanism |
|---|
| Stripe Payments Europe, Limited | Card processing | EU primary, US fraud screening | EU SCCs / DPF; Stripe acts as independent controller for some processing |
Analytics and product
| Sub-processor | Service | Region | Transfer mechanism |
|---|
| Plausible Insights OÜ (if used) | Privacy-focused web analytics | EU (Estonia / Germany) | Within EEA |
| PostHog Inc. (if used) | Product analytics, session replay (with PII redaction) | EU region selected | EU SCCs / DPF |
Customer support
| Sub-processor | Service | Region | Transfer mechanism |
|---|
| Intercom / Plain / HelpScout (confirm choice) | Helpdesk and live chat | EU primary | EU SCCs as applicable |
Internal operations (process Personal Data only incidentally)
| Sub-processor | Service | Region |
|---|
| Google Workspace | Email, calendar, documents | EU primary |
| Linear / Notion | Engineering and documentation | EU primary |
| GitHub | Source-code hosting (no production data) | US |
Notes
- Any Sub-processor that processes Personal Data on Closetforge's behalf is bound by a written agreement imposing data-protection obligations no less protective than those in the DPA.
- Sub-processors marked "DPF-certified" appear on the EU–US Data Privacy Framework list; transfers rely on the EU Commission's adequacy decision for the DPF.
- Where transfers fall outside an adequacy decision and DPF coverage, EU SCCs (2021/914) are used, supplemented by encryption in transit and at rest, contractual purpose limitations, and the Sub-processor's own technical and organisational measures.
Last review: [date]
Next scheduled review: [date + 6 months]
To request an updated list or detailed information about any entry, email privacy@closetforge.com.