Public Register · CS-DOC-PUBLIC-REG-003

Sub-Processors

Effective 27 April 2026 · Version 1.0 · Updated 14 days in advance of any material change

Purpose

This list identifies the sub-processors engaged by Certisyn, Inc. for the processing of personal data on behalf of its customers. It is published in fulfilment of the obligation under Article 28(2) of the General Data Protection Regulation to inform the controller in advance of intended changes concerning the addition or replacement of other processors.

Sub-processorServiceRegionDPA reference
Supabase, Inc.Database hosting and authenticationUnited States; EU regions availablesupabase.com/legal/dpa
Vercel, Inc.Application deployment and edge computeGlobalvercel.com/legal/dpa
Cloudflare, Inc.DNS, edge security, DDoS protectionGlobalcloudflare.com/cloudflare-customer-dpa
GitHub, Inc.Source-control management and CIUnited Statesgithub.com/customer-terms/github-data-protection-agreement
Anthropic, PBCAgentic-workforce LLM (Claude API)United Statesanthropic.com/legal/dpa
OpenAI, OpCo, LLCReserve LLM provider (failover only)United Statesopenai.com/policies/data-processing-addendum
Stripe, Inc.Payment processingUnited States; EU regionsstripe.com/legal/dpa
Resend, Inc.Transactional email deliveryUnited Statesresend.com/legal/dpa
Datadog, Inc.Observability and log aggregationUnited States; EU regionsdatadoghq.com/legal/data-processing-addendum
Doppler, Inc.Secrets managementUnited Statesdoppler.com/legal/data-processing-addendum
Subscribe to change notifications. Email subprocessors-notify@certisyn.com with the subject line SUBSCRIBE. We notify of additions, removals, or scope changes at least 14 days in advance.

Right to object

A customer may object to the use of a new sub-processor on reasonable grounds related to data protection. Where the objection cannot be resolved, the customer may terminate the affected processing as set out in the Data Processing Agreement.