Sub-Processors
Effective date: 2 July 2026 Last updated: 3 July 2026 Version: 3 (added Sentry; corrected OVH's role to reflect our self-hosted mail server)
Sairaph Mail (operated by WELLDONE, Aleja Wyzwolenia 11/6, 70-552 Szczecin, Poland) engages the third-party sub-processors below to deliver the Service. Each processes personal data only on our documented instructions and under a data-processing agreement containing the Article 28 GDPR terms. This list is referenced by, and forms part of, our Privacy Policy and (for Business Customers) our Data Processing Agreement.
How to read the "transfer mechanism" column: where a sub-processor processes personal data in the EU/EEA, no Chapter V transfer mechanism is needed. Where data may be processed in, or accessed from, a third country (in practice the United States), the listed mechanism is the safeguard we rely on under Chapter V GDPR.
---
Active sub-processors
1. OVHcloud
- Legal entity: OVH SAS (France - EU). (Where contracting is through the Polish OVH entity OVH Sp. z o.o., that entity applies; both are EU-established.)
- Purpose: OVHcloud is our primary EU infrastructure provider and performs several roles: (a) domain name registration and management (OVH is the registrar) and DNS; (b) the EU virtual private servers on which we run our own self-hosted mail server (the authoritative store for your inbound and stored mail) and our inbound/outbound mail relay; and (c) application infrastructure hosting - the virtual private servers that run the Sairaph Mail application, PostgreSQL database, Redis, and background workers. OVHcloud provides the infrastructure and domain registration; it does not operate a managed email/mailbox product for us.
- Categories of data: Customer email content (messages, headers, attachments), mailbox credentials, domain owner-contact (registrant) details, DNS configuration; and, for the application infrastructure, all Account data, billing metadata, technical/audit metadata, and the encrypted body cache and credentials (encryption keys held by Sairaph Mail; see the Privacy Policy security section).
- Processing region: EU (OVHcloud EU data centres).
- International transfer: None required - processing is in the EU.
- Notes: Domain registrant contact details may additionally be processed/published under ICANN and registry rules, which is a separate controller relationship governed by those policies.
2. Amazon Web Services - Amazon SES
- Legal entity: Amazon Web Services EMEA SARL (Luxembourg); US parent: Amazon Web Services, Inc.
- Purpose: Outbound email relay (sending your outgoing mail) and processing of bounce and complaint notifications.
- Categories of data: Outbound message content and headers, sender/recipient addresses, delivery/bounce/complaint metadata.
- Processing region: eu-west-1 (Dublin, Ireland - EU).
- International transfer: Sending processing occurs in the EU. To the extent any personal data is accessed by the US parent, transfers are covered by the AWS GDPR Data Processing Addendum (incorporating the EU Standard Contractual Clauses) and Amazon's EU-US Data Privacy Framework certification.
3. Stripe
- Legal entity: Stripe Payments Europe, Ltd. (Ireland); US parent: Stripe, Inc.
- Purpose: Payment processing (subscription charges, renewals) and tax calculation (Stripe Tax, including EU VAT / reverse charge / OSS handling).
- Categories of data: Billing name, email, billing country, VAT ID (if provided), payment-method/card data (handled by Stripe as a PCI-DSS processor - Sairaph Mail does not store full card numbers), transaction records.
- Processing region: EU and US.
- International transfer: Covered by Stripe's DPA (incorporating the EU SCCs) and Stripe, Inc.'s EU-US Data Privacy Framework certification.
4. Cloudflare - Turnstile
- Legal entity: Cloudflare, Inc. (US); EU contracting entity where applicable: Cloudflare Germany GmbH.
- Purpose: Bot protection at signup (Cloudflare Turnstile) - distinguishing humans from automated bots on the signup form.
- Categories of data: IP address, browser/device signals, Turnstile challenge token, interaction metadata.
- Processing region: Global / US.
- International transfer: Covered by Cloudflare's DPA (incorporating the EU SCCs) and Cloudflare, Inc.'s EU-US Data Privacy Framework certification.
5. Plausible Analytics (self-hosted)
- Legal entity: Operated by WELLDONE (Sairaph Mail) on its own EU infrastructure - Plausible Community Edition is self-hosted, not the Plausible Insights OÜ managed cloud service. Listed here for transparency even though, being operator-controlled and first-party, it is arguably not a third-party sub-processor.
- Purpose: Privacy-first website analytics - understanding how the marketing site and dashboard are used. The baseline measurement is cookieless (no cookies, no device storage; legitimate-interest basis). A consent-gated enriched/attribution layer additionally stores a
sessionStorageattribution token on the user's device, and only runs after the user consents. - Categories of data: Aggregated/pseudonymous usage data - page URL, referrer, de-identified device/browser type, country (derived, no raw IP retained). Plausible does not store personal cross-site identifiers or use cookies for the baseline measurement.
- Processing region: EU (self-hosted on operator-controlled OVHcloud EU infrastructure).
- International transfer: None required - processing is in the EU.
6. IDrive e2
- Legal entity: IDrive Inc. (US).
- Purpose: Encrypted off-site backup storage. Nightly
pg_dumpsnapshots of the production PostgreSQL database (the full application dataset: Account data, mailbox/domain/message metadata, billing metadata, technical/audit metadata, and the still-encrypted body cache / credential ciphertexts) are streamed off the VM, encrypted in flight withage(a per-operator key pair whose private half is held offline, never on the VM), and uploaded to an IDrive e2 (S3-compatible) bucket viarclone. IDrive e2 only ever receives the age-encrypted artifact, not a plaintext dump. - Categories of data: An encrypted backup blob containing the same categories of data as the OVHcloud application-infrastructure row above (all Account data, billing metadata, technical/audit metadata, encrypted body cache and credentials) - opaque to IDrive e2 without the offline-held
ageprivate key. - Processing region: EU - IDrive e2 region
eu-central-2. - International transfer: None required - processing is in the EU. To the extent the US legal entity accesses the bucket for support/account administration, the backup content itself remains
age-encrypted end-to-end and unreadable without the offline private key.
7. Sentry
- Legal entity: Functional Software, Inc. d/b/a Sentry (US).
- Purpose: Error monitoring and crash reporting. Captures unhandled exceptions and error events from the backend application to help us detect, diagnose, and fix production incidents. A
before_sendscrubbing hook (backend/app/main.py) strips request/response bodies and sensitive headers and regex-redacts Stripe/AWS/Fernet-shaped secrets from every event before it leaves the process; frame-local variables are never captured (include_local_variables=False). Message content, credentials, and encryption key material are therefore not sent to Sentry. - Categories of data: Error/exception metadata - stack traces (local variables excluded), request path/method, sanitized headers, an account identifier (to correlate errors to accounts), timestamps, and environment/release metadata. No message bodies, credentials, or encryption keys.
- Processing region: EU - the organization is configured for Sentry's EU data-storage region (Frankfurt, Germany; ingest domain
de.sentry.io). - International transfer: To the extent Sentry's US legal entity accesses data for support or account administration, transfers are covered by Sentry's DPA (incorporating the EU Standard Contractual Clauses) and Sentry's EU-US Data Privacy Framework certification.
---
Change management
- We will give customers reasonable advance notice of any new or replacement sub-processor (e.g. by updating this versioned list and notifying by email or in-product notice), and an opportunity to object on reasonable data-protection grounds, before the new sub-processor begins processing.
- The DPA flows down equivalent Article 28 obligations to every sub-processor, and Sairaph Mail remains liable to the customer for its sub-processors' performance.
---
If you have questions about these terms, contact us at privacy.mail@sairaph.com.
*Sairaph Mail, operated by WELLDONE, Sairaph.com.*