Skip to main content

Trust center

Trace the data before you approve the supplier.

A privacy-office procurement review needs to know what stays in the browser and which providers handle the records that do not. Review ScrubMetadata Professional's agreement, provider roles, locations and technical measures here.

DPA version dpa-2026-09-19-v1. Opening the document does not execute an agreement.

The procurement file

Where data goes

Local files and platform records have different boundaries.

Raw files. Supported files are processed in the browser; raw file bytes and extracted raw metadata are not uploaded to ScrubMetadata on that path.

Workspace records. Account, subscription, audit and minimized compliance records are stored by the platform. Zero-upload describes the raw-file processing boundary, not an absence of platform personal data. ScrubMetadata processes minimized account, authentication, security, device-trust, consent, billing, operational, error-monitoring, audit, compliance-evidence, and support data for the purposes described in the canonical public data-category register. It does not use visitor analytics, advertising pixels, retargeting cookies, or cross-site behavioral profiling.

Workspace access. A copied record link cannot be treated as permission to open another organization's work. Organization-scoped requests check the signed-in membership before access; the active selection is an authorization boundary, not a list filter.

Location and transfers. Application Functions use Vercel's US iad1 region; the production Neon database was observed in US east. The provider register describes location limits and transfer safeguards.

Change notice. Under the accepted DPA, a new or changed subprocessor needs prior written authorization. Where general written authorization is agreed, customers receive notice of intended changes and an opportunity to object. Automated change emails are not part of the current commitment.

The provider landscape

Role and data categories vary by activity. The full register provides the contract and location details.

Payment Processing - PaddleSubscription checkout, billing, invoicing, and tax handling as merchant of record
Application Hosting - VercelHosting the web application and serverless request handlers
Relational Database - Neon PostgreSQLAccount, organization, subscription, audit, and privacy-safe compliance workflow records
Cache and Abuse Prevention - Upstash RedisDistributed rate limits, session-related controls, and bounded operational coordination
Email and Magic-Link Delivery - ResendTransactional email, account-security messages, compliance alerts, and opted-in communications
Contact Mailbox Hosting - Zoho MailReceiving and replying to privacy, security, support, billing, and legal enquiries sent to the published ScrubMetadata contact addresses
Privacy-Filtered Error Monitoring - SentryApplication error diagnosis and security/availability alerting
DNS and Bot Protection - CloudflareDNS, network protection, and configured Turnstile bot checks on public intake surfaces
Read the full provider register

Security measures by layer

Infrastructure

Application Functions run in US iad1; the production database was observed in AWS us-east-1.

Read the boundary

Application

Application-level AES-256-GCM protects integration credentials and selected sensitive fields.

Read the boundary

Access

Authenticated membership is checked for organization-scoped requests before a record is read or changed. Sign-in uses email magic links.

Read the boundary

Data

Supported raw files and extracted raw metadata stay in the browser. Minimized compliance evidence is stored for the workspace.

Read the boundary

Audit integrity

Canonical audit writes include SHA-256 hash-chain controls. This does not establish independent verification of every route, retention policy, legal hold, backup or restore path.

Read the boundary

Verify local processing

A browser check of a supported file, not a legal or cryptographic assurance result.

  1. 01

    Open Network

    Open browser DevTools and select the Network tab.

  2. 02

    Process a file

    Use a supported synthetic file in the Professional dashboard.

  3. 03

    Inspect requests

    Confirm that no outbound request contains raw file bytes.

Direct answers

Is the service EU-hosted?
No. Application Functions run in US iad1, and the production database was observed in AWS us-east-1. This is not an EU-only residency offer.
Are transfer safeguards complete?
An SCC link in a transfer record identifies a document to review; it does not establish that the clauses cover this activity or make the transfer lawful. No account-specific transfer mechanism or SCC coverage is represented as complete. The applicable agreement and transfer annexes must be established for each provider activity.
Is there independent security certification?
No SOC 2 or ISO certification or independent penetration-test opinion is claimed. The security page describes technical measures and their exact scope.
Is AI processing part of Professional?
No AI add-on is included in the controlled Professional offer. The published provider register lists no AI model processor for that offer.

Breach and contact

When acting as processor, ScrubMetadata notifies the customer controller without undue delay after becoming aware of a personal data breach. The controller handles authority and data-subject notification decisions under applicable law. The full obligation is in the DPA.

Report security issues to security@scrubmetadata.com. Do not include raw files or raw metadata in email.

The provider register covers 8 activities. The Professional offer excludes 2 AI add-ons. Technical measures are scoped descriptions, not independent certification or a legal-compliance determination.

Trust Center | ScrubMetadata