Skip to main content

Provider register

Know which provider handles which record.

ScrubMetadata discloses 8 provider activities below. Check the data involved, location and contract route for each activity before relying on the service. A provider's legal role depends on that activity.

Register version subprocessors-2026-09-19-v1

Processing boundary

Supported customer file contents and raw extracted metadata stay in the local browser workflow. Account, subscription, audit and minimized compliance records use the providers below.

Zero-upload describes the raw-file processing boundary, not an absence of platform personal data. ScrubMetadata processes minimized account, authentication, security, device-trust, consent, billing, operational, error-monitoring, audit, compliance-evidence, and support data for the purposes described in the canonical public data-category register. It does not use visitor analytics, advertising pixels, retargeting cookies, or cross-site behavioral profiling.

Professional supports browser and local folder processing. Approved customer-controlled cloud integrations are not part of the current Professional offer. ScrubMetadata can receive minimized workflow evidence such as counts, categories, status, timestamps, and evidence hashes, but not raw file data through these supported processing paths. Support correspondence is separate: do not send raw customer files or raw metadata to support.

Provider activities

Select a provider to inspect its entity, data categories, operational boundary and contract route.

01Payment Processing - PaddleSubscription checkout, billing, invoicing, and tax handling as merchant of record
Legal entity
Paddle.com Inc. for US buyers, Paddle.com (Canada) Ltd. for Canadian buyers, and Paddle.com Market Limited for other buyers. The applicable supplier entity is determined separately by the supplier agreement.
Data categories
Billing contact and transaction details needed for checkout and subscription administration. Paddle, not ScrubMetadata, receives and processes payment-card data.
Location and operational limit
Paddle acts as an independent controller for its merchant-of-record activities. The applicable Paddle contracting entity depends on the buyer location. Paddle determines its own retention; deleting a ScrubMetadata account does not erase Paddle records or remove ScrubMetadata service obligations.
Contract route
The supplier MSA incorporates a controller-to-controller data-sharing addendum. This is not a processor DPA for merchant-of-record billing. The applicable supplier and transaction agreements identify the parties.
Provider contract
02Application Hosting - VercelHosting the web application and serverless request handlers
Legal entity
Vercel Inc.
Data categories
Account and application request traffic, including technical request information needed to serve the application. Customer file bytes and raw extracted metadata values are excluded from the supported browser-local processing path.
Location and operational limit
Application Functions are configured in iad1, a United States region, also recorded in the 4 September 2026 production deployment receipt. This is not an EU-only hosting claim or a complete inventory of CDN, logs, support, backup or other provider locations. Transfer safeguards and account-specific contractual assurance still require evidence.
Contract route
The DPA covers Pro and Enterprise under its agreement-entry or separate-execution provisions. Coverage depends on the applicable agreement and production team, not a mandatory separate PDF signature.
Provider contract
03Relational Database - Neon PostgreSQLAccount, organization, subscription, audit, and privacy-safe compliance workflow records
Legal entity
Current public Neon terms identify Databricks, Inc., parent of Neon, LLC. Legacy documents identify Neon Inc.; the applicable account regime remains to be established.
Data categories
User and organization account data plus minimized compliance records. Customer file bytes, local paths, raw filenames, and raw extracted metadata values are excluded from the supported browser-local processing path.
Location and operational limit
The production database project was observed in AWS us-east-1, United States, on 5 September 2026. Its configured restore history is six hours. That is not a complete backup-deletion guarantee or a statement about all provider access locations. The account contract and transfer safeguards remain to be established.
Contract route
The current Neon schedule incorporates the Databricks MCSA and its DPA. The legacy Neon DPA uses a signature-based route. An account agreement or valid migration record must establish which applies.
Provider contract
04Cache and Abuse Prevention - Upstash RedisDistributed rate limits, session-related controls, and bounded operational coordination
Legal entity
Upstash, Inc.
Data categories
IP-address identifiers and hourly allowed or blocked request counts for application abuse prevention, plus other minimized identifiers, counters and control state for reliable operation. No customer file content or raw metadata values.
Location and operational limit
Security-critical paths fail closed when their required distributed control is unavailable. The rate-limit window does not establish analytics retention. Actual analytics retention, residency and transfer safeguards remain account-specific evidence requirements.
Contract route
The service terms incorporate the DPA for instructed customer-data processing. The production account agreement and applicable transfer annexes must be evidenced; a separate signature is not inherently required.
Provider contract
05Email and Magic-Link Delivery - ResendTransactional email, account-security messages, compliance alerts, and opted-in communications
Legal entity
Plus Five Five, Inc. (Resend)
Data categories
Recipient email address, bounded message content, and delivery status needed to send and reconcile the message.
Location and operational limit
The verified scrubmetadata.com sending domain was observed in us-east-1, United States, on 5 September 2026, with open and click tracking disabled. Resend publishes a 30-day retention period for email content, metadata, delivery events, logs and metrics on Free, Pro and Scale. This does not delete copies in our application, recipient mailboxes or Zoho Mail, or establish complete provider backup erasure. The sending region does not establish every storage or support location. Zoho Mail separately handles contact mailbox replies. Marketing and newsletter messages require explicit opt-in and remain suppressible.
Contract route
The service agreement incorporates the DPA through its acceptance provisions, including the applicable free-plan signup route. Account agreement coverage, not a separate countersignature alone, establishes applicability.
Provider contract
06Contact Mailbox Hosting - Zoho MailReceiving and replying to privacy, security, support, billing, and legal enquiries sent to the published ScrubMetadata contact addresses
Legal entity
The public geographic schedule assigns Nepal customers to Zoho Corporation Pte. Ltd., Singapore, subject to the actual Mail account agreement.
Data categories
Sender and recipient addresses, message content, attachments, and delivery metadata supplied by the person who contacts ScrubMetadata. Customers must not send raw files or raw metadata through these contact channels.
Location and operational limit
Zoho Mail hosts the monitored contact mailbox and aliases. Processing location, retention, transfer mechanism, DPA, incident-contact, and change-notice facts remain owner, legal, and provider evidence gates.
Contract route
Zoho provides an administrator-initiated electronic DPA execution process. A request or signing invitation is not completed execution. The accepted Mail agreement and completed DPA must identify the applicable entity and annexes.
Provider contract
07Privacy-Filtered Error Monitoring - SentryApplication error diagnosis and security/availability alerting
Legal entity
Functional Software, Inc. d/b/a Sentry
Data categories
Privacy-filtered technical error context and an internal account identifier where set. This is not necessarily anonymous. Customer file bytes, local paths, raw filenames, raw metadata values, authorization credentials, and message bodies are excluded.
Location and operational limit
Monitoring is governed by the application redaction boundary. Provider enablement and production monitoring evidence remain separate release gates.
Contract route
An organization Owner or Billing member accepts the DPA in Legal & Compliance. A separate DocuSign copy is optional. The production organization acceptance record remains necessary.
Provider contract
08DNS and Bot Protection - CloudflareDNS, network protection, and configured Turnstile bot checks on public intake surfaces
Legal entity
Cloudflare, Inc.
Data categories
Technical network and challenge information, including IP address, TLS fingerprint, user-agent, site key and associated origin for Turnstile; no customer file content or raw metadata values.
Location and operational limit
Cloudflare is not an interactive authentication provider. Its Turnstile notice distinguishes processing on the website operator's behalf for bot protection from its independent controller processing to improve bot detection. Exact enabled services, locations, and transfer safeguards remain owner/legal/provider evidence gates.
Contract route
The self-serve agreement incorporates the DPA. Coverage depends on the applicable account agreement and enabled services; a separate enterprise agreement must be assessed on its own terms.
Provider contract

Change notice and roles

When a new provider appears in a change notice, check which processing activities and data categories it would handle, its location and contract route, and who must authorise the change. A name in this register starts that review; it does not finish the account-specific transfer or subprocessor decision.

The register records current technical purposes, categories, minimization, retention criteria, and provider paths. Owner and privacy or legal review must confirm the final controller-processor roles, lawful basis, retention periods, transfer safeguards, and notice approval. This register does not determine legal compliance.

Under the accepted DPA, new or changed subprocessors need prior written authorization. If general written authorization applies, the customer receives notice of intended additions or replacements and an opportunity to object. Automated change emails are not currently promised.

A provider is our subprocessor only for customer-instructed processing. Providers used for our own administration can have a different role. Paddle acts as an independent controller for merchant-of-record billing.

Linked provider terms show contractual routes; they do not establish the agreement, SCCs or transfer mechanism applicable to a specific account. Those details must be confirmed before a provider is incorporated into a customer agreement.

Our privacy contact is an enquiry channel, not an appointed EU or UK representative. See our Privacy Notice.

Questions: privacy@scrubmetadata.com. Do not email raw files or raw metadata.

Providers and Subprocessors | ScrubMetadata