Sunset Docs
PricingSecurityBlogSign inStart trialENESFRDEIT
Subprocessors

Service providers and subprocessors

Last updated: 15 August 2026

This page lists the main providers used to operate Sunset Docs. A provider is a subprocessor only where it processes customer personal data on our behalf. Some providers also act as independent controllers for their own regulated, account, or security activities.

Contents

  1. 1. How providers are selected
  2. 2. Current providers
  3. 3. International transfers
  4. 4. Changes to this list
  5. 5. Contact

1. How providers are selected

We review providers before use, limit the data sent to what the service needs, enter into appropriate data-protection terms, and review the arrangement when the service changes. Document contents are not sent to billing or outbound email providers.

2. Current providers

The role shown below describes the provider's main function for Sunset Docs. A provider may have a separate controller role for its own billing, fraud, abuse-prevention, or legal obligations.

ProviderRolePurposeDataRegion and safeguards
Hetzner Online GmbHSubprocessorPrimary application, database, and encrypted local-object hostingCustomer documents, workspace and account data, support data, and security eventsEuropean Union
Cloudflare, Inc.Subprocessor for contracted services; separate controller for limited account or network-security activity where applicableDNS and traffic protection, private encrypted R2 object mirror, and outbound transactional emailApplication-encrypted document objects, request and network metadata, recipient address, generic message content, and delivery metadataGlobal infrastructure; Cloudflare Customer DPA, applicable adequacy decisions, and Standard Contractual Clauses
Stripe Payments Europe, Limited and affiliatesProcessor and independent controller, depending on the payment activityHosted Checkout, subscriptions, invoices, tax calculation, and payment processingAccount contact, billing address, tax ID, subscription, invoice, and payment data. No customer document content.European Economic Area and other locations covered by Stripe's DPA and transfer terms

3. International transfers

Where a provider processes personal data outside the EEA, we use the transfer mechanism stated above and assess supplementary measures where required. Application-level encryption limits Cloudflare's access to document content stored in R2.

4. Changes to this list

We will notify workspace owners by email or in the service at least 30 days before a new or replacement subprocessor begins processing customer personal data. Customers may object during that period on reasonable data-protection grounds by emailing [email protected].

If we cannot offer a reasonable alternative, the customer may terminate the affected service and receive a pro-rata refund of prepaid fees for the unused period.

5. Contact

Questions about providers, roles, or transfer safeguards can be sent to [email protected].

Related documents

Privacy · Terms · DPA · Subprocessors · Security

Sunset Docs

Temporary intake for sensitive documents.

BlogSupportPrivacyDPASubprocessorsTermsRefundsCookiesLegal noticeSecurity