Skip to main content
← Back to Privacy Policy

Sub-Processors

Last updated:

HumanKey uses the following third-party sub-processors to provide its services. All sub-processors are bound by Data Processing Agreements (DPAs) and process personal data only as instructed. Where data is transferred outside the EEA, Standard Contractual Clauses (SCCs) per GDPR Chapter V are in place.

ProcessorPurposeData LocationTransfer MechanismDPA
RailwayAPI server hosting & computeπŸ‡³πŸ‡± EU (Netherlands β€” Amsterdam)EU β€” no transferView DPA
NeonDatabase hostingπŸ‡©πŸ‡ͺ EU (Germany β€” Frankfurt)EU β€” no transferView DPA
VercelFrontend hosting & CDNπŸ‡©πŸ‡ͺ EU (Germany) + πŸ‡ΊπŸ‡Έ US (SCCs)Standard Contractual Clauses (SCCs)View DPA
CloudflareDNS, DDoS protection, CDNπŸ‡ΊπŸ‡Έ US + global edge networkStandard Contractual Clauses (SCCs)View DPA
StripePayment processing & subscription billingπŸ‡ΊπŸ‡Έ US (SCCs)Standard Contractual Clauses (SCCs)View DPA
ResendTransactional email (verification, password reset)πŸ‡ΊπŸ‡Έ US (SCCs)Standard Contractual Clauses (SCCs)View DPA
SentryError tracking β€” no PII transmitted (stripped before transmission)πŸ‡©πŸ‡ͺ EU (Germany β€” Sentry EU region)EU β€” no transferView DPA
MaxMindIP geolocation database β€” local file download only, no visitor data transferredπŸ‡ΊπŸ‡Έ Waltham, MA, USANo data transfer (local processing)View DPA
Cloudflare RadarASN metadata enrichment via public API β€” only ASN number queried, no PII transmittedπŸ‡ΊπŸ‡Έ US (Cloudflare global network)No personal data transfer (public API)View DPA
Anthropic, PBCAI-powered advisory analytics and chatbot assistance β€” only aggregated statistics and user chat text transmitted, no visitor data or PIIπŸ‡ΊπŸ‡Έ San Francisco, CA, USANo personal data transfer (aggregated statistics only)View DPA

GDPR Compliance

  • All EU-based processors are covered under GDPR directly β€” no transfer mechanism needed.
  • US-based processors (Vercel, Cloudflare, Stripe, Resend) have executed EU Standard Contractual Clauses (SCCs) per GDPR Chapter V.
  • Sentry operates in EU region (Germany) β€” no international transfer occurs.
  • PII is minimized before transmission to all processors β€” Sentry receives no email addresses or IP addresses.

We will update this page when sub-processors are added, removed, or changed. Significant changes will be communicated via email to account holders with active subscriptions. This page was last updated on 2026-04-06.

Sub-Processors | HumanKey | HumanKey