Skip to content
OpenDPP
Why ESPR How it works Standards Solutions Pricing FAQ Demo
Client Console Book a demo
Why ESPR How it works Standards Solutions Pricing FAQ Demo Client Console Book a demo
Terms of ServicePrivacy PolicyAPI TermsSupport PolicyData Processing AddendumSub-processor RegisterLegal Notice (Imprint)

OpenDPP — Sub-processor Register

This register is referenced by the DPA (Annex 3) and the Privacy Policy §5. All provider transfer safeguards are verified (2026-07-21). Changes to Section A require the 14-day advance notice of DPA §5.2. This page is the single source — publish it at a stable URL and link it from the DPA.

Last updated: 2026-07-31 · Version: 1.0

A. Sub-processors of Customer Personal Data (DPA §5)

Providers that may process personal data contained in Customer Content on our behalf:

Provider Entity Purpose Location of processing Transfer safeguard
Google Cloud (Cloud Run, Secret Manager, Cloud Logging) Google Cloud EMEA Ltd (Ireland) Application hosting and operations EU — europe-west1 (Belgium) EU processing; Google Cloud data-processing terms; SCCs/DPF for any ancillary US processing
Neon (managed PostgreSQL) Neon — a Databricks company (acquired 2025); DPF-listed as Neon, LLC under Databricks, Inc. Primary database EU — AWS eu-central-1 (Frankfurt, Germany), Neon Launch plan — region re-verified via the Neon API 2026-07-21 EU processing; Neon DPA incorporates the EU SCCs; EU–U.S. DPF Active (Databricks, Inc. certification covering Neon, LLC — dataprivacyframework.gov)
Resend (transactional email) Resend, Inc. (US) Service emails (invitations, account and billing notices) that may reference workspace content EU delivery — routed via Amazon SES eu-west-1 (Ireland) (our send.opendpp-node.eu bounce path); Resend platform/logs in the US Resend DPA incorporates the EU SCCs (Module Two, by reference; executed on signup) + EU–U.S. DPF & UK Extension (Active since 2025-03-06 — dataprivacyframework.gov #8907); SOC 2 Type II

B. Our own service providers (controller side — Privacy Policy)

Providers we use for our own processing (accounts, billing, website). Not Customer Content sub-processors:

Provider Purpose Location / safeguard
Google / Firebase (Identity Platform) Two-factor authentication (workspace opt-in) + platform-admin sign-in US processing — Firebase Authentication / Identity Platform runs only from US data centres, with no EU data-residency option (per firebase.google.com/support/privacy); project opendpp-node-mfa sits in the EU opendpp-node.eu GCP org. Primary workspace sign-in is email/password, processed in the EU (our database); only 2FA/MFA and platform-admin (Google + TOTP) sign-in route through Firebase. Transfer safeguard: Google LLC EU–U.S. DPF (Active) + EU SCCs
Stripe Payments Europe, Limited (Ireland) Payments, subscriptions, tax IDs EEA contracting entity for our LT/EUR account (Opendpp UAB, standard account); Stripe also acts as an independent controller for payment processing under its own terms; any US processing by Stripe, LLC under EU–U.S. DPF (Active — +UK +Swiss) + SCCs in the Stripe DPA
iubenda s.r.l. (Italy) Cookie-consent banner on the website EU
Google Tag Manager Tag container on the marketing site only, loading our analytics tag (Google Analytics); consent-gated via the Iubenda banner — held inert (type="text/plain") until the visitor consents (PR #1005) Google LLC EU–U.S. DPF (Active) + SCCs
Google Analytics Website analytics, loaded through Google Tag Manager — only after cookie consent Google LLC EU–U.S. DPF (Active) + SCCs
Google Workspace Business mailbox (support/legal correspondence) EU — Workspace Data Regions = Europe (data at rest) for covered core services incl. Gmail (Business Standard; confirmed in the Admin console 2026-07-21); EEA service under the Google Cloud/Workspace DPA (a Google EEA entity); Google LLC EU–U.S. DPF (Active) + EU SCCs for any ancillary US processing

Web fonts are self-hosted (PR #558) — no fonts CDN receives visitor traffic.

C. Optional / configuration-dependent integrations

Active only where the feature is enabled; listed for transparency:

Integration Trigger Personal data involved
European Commission EOS (EORI / AEO validation) Opt-in ingest advisory The declared operator registration ID (may identify a sole trader). The Commission service is an independent public-authority controller.
RFC 3161 Timestamping Authority (configurable) Opt-in sealing timestamp None — only a cryptographic hash is transmitted
IndexNow (Bing/Yandex/Seznam/Naver) Opt-in SEO notification None — public URLs only
EU DPP registry (live since 20 July 2026; not yet enabled here) Regulatory pointer registration Pointer/identifier data only — never passport content
DeepL SE (Germany) Build-time translation of our UI strings None — no user or customer data

Change log

Date Change
2026-07-31 Initial publication of the register.
OpenDPP

The no-code platform for EU Digital Product Passports. Issue, seal, and publish — ready before the first deadlines.

Product

How it works Solutions Pricing Interactive demo Client Console

Company

About Why ESPR Security & Trust Seal Audit Portal

Resources

ESPR timeline DPP standards (EN 182xx) EU DPP Registry Battery Passport guide API reference AI knowledge bundle (OKF) Open source

Legal

Contact Support Privacy Policy Terms of Service Cookie Policy Legal Notice
© 2026 OpenDPP UAB · ESPR 2024/1781 · EU-hosted & eIDAS-signed