Last updated: 18 July 2026. Changes are posted here at least 14 days before a new subprocessor handles customer data (see DPA clause 5).
| Subprocessor | Purpose | Data touched | Location |
|---|---|---|---|
| Cloudflare, Inc. | Compute (Workers), key escrow and audit storage (Durable Objects), TLS, edge security | All service data described in the whitepaper — never file contents, which are not transmitted to the service at all | Global edge network (US-headquartered) |
| Resend, Inc. | Transactional email (delivery links, PINs, receipts, invites) | Recipient/sender email addresses, delivery email content (links, PINs, labels — never files) | US-headquartered; sending region EU (Ireland) |
| Twilio, Inc. | SMS delivery of PINs (only when SMS is enabled) | Recipient phone numbers, PIN messages | US-headquartered |
| Stripe Payments Europe / Stripe, Inc. | Payments, subscriptions, VAT invoicing | Billing details, card data (held by Stripe only — never by SecureSend) | EU/US |
| Google LLC | Optional dashboard sign-in (Google Identity Services) | Verified email address at sign-in; no other profile data requested | US-headquartered |
There are no other subprocessors: SecureSend has no analytics, no advertising technology, no error-tracking SaaS, and no data warehouse.
Questions or objections (per DPA clause 5): support@jadapps.app.