Skip to content
OpenDPP
Why ESPR How it works Standards Solutions Pricing FAQ Demo
Client Console Book a demo
Why ESPR How it works Standards Solutions Pricing FAQ Demo Client Console Book a demo
Terms of ServicePrivacy PolicyAPI TermsSupport PolicyData Processing AddendumSub-processor RegisterLegal Notice (Imprint)

OpenDPP — Sub-processor Register

This register is referenced by the DPA (Annex 3) and the Privacy Policy §5. All provider transfer safeguards are verified (2026-07-21). Changes to Section A require the 14-day advance notice of DPA §5.2. This page is the single source — publish it at a stable URL and link it from the DPA.

Last updated: 2026-07-21 · Version: 1.1

A. Sub-processors of Customer Personal Data (DPA §5)

Providers that may process personal data contained in Customer Content on our behalf:

Provider Entity Purpose Location of processing Transfer safeguard
Google Cloud (Cloud Run, Secret Manager, Cloud Logging) Google Cloud EMEA Ltd (Ireland) Application hosting and operations EU — europe-west1 (Belgium) EU processing; Google Cloud data-processing terms; SCCs/DPF for any ancillary US processing
Neon (managed PostgreSQL) Neon — a Databricks company (acquired 2025); DPF-listed as Neon, LLC under Databricks, Inc. Primary database EU — AWS eu-central-1 (Frankfurt, Germany), Neon Launch plan — region re-verified via the Neon API 2026-07-21 EU processing; Neon DPA incorporates the EU SCCs; EU–U.S. DPF Active (Databricks, Inc. certification covering Neon, LLC — dataprivacyframework.gov)
Resend (transactional email) Resend, Inc. (US) Service emails (invitations, account and billing notices) that may reference workspace content EU delivery — routed via Amazon SES eu-west-1 (Ireland) (our send.opendpp-node.eu bounce path); Resend platform/logs in the US Resend DPA incorporates the EU SCCs (Module Two, by reference; executed on signup) + EU–U.S. DPF & UK Extension (Active since 2025-03-06 — dataprivacyframework.gov #8907); SOC 2 Type II

B. Our own service providers (controller side — Privacy Policy)

Providers we use for our own processing (accounts, billing, website). Not Customer Content sub-processors:

Provider Purpose Location / safeguard
Google / Firebase (Identity Platform) Two-factor authentication (workspace opt-in) + platform-admin sign-in US processing — Firebase Authentication / Identity Platform runs only from US data centres, with no EU data-residency option (per firebase.google.com/support/privacy); project opendpp-node-mfa sits in the EU opendpp-node.eu GCP org. Primary workspace sign-in is email/password, processed in the EU (our database); only 2FA/MFA and platform-admin (Google + TOTP) sign-in route through Firebase. Transfer safeguard: Google LLC EU–U.S. DPF (Active) + EU SCCs
Stripe Payments Europe, Limited (Ireland) Payments, subscriptions, tax IDs EEA contracting entity for our LT/EUR account (Opendpp UAB, standard account); Stripe also acts as an independent controller for payment processing under its own terms; any US processing by Stripe, LLC under EU–U.S. DPF (Active — +UK +Swiss) + SCCs in the Stripe DPA
iubenda s.r.l. (Italy) Cookie-consent banner on the website EU
Google Tag Manager Tag container on the marketing site only, loading our analytics tag (Google Analytics); consent-gated via the Iubenda banner — held inert (type="text/plain") until the visitor consents (PR #1005) Google LLC EU–U.S. DPF (Active) + SCCs
Google Analytics Website analytics, loaded through Google Tag Manager — only after cookie consent Google LLC EU–U.S. DPF (Active) + SCCs
Google Workspace Business mailbox (support/legal correspondence) EU — Workspace Data Regions = Europe (data at rest) for covered core services incl. Gmail (Business Standard; confirmed in the Admin console 2026-07-21); EEA service under the Google Cloud/Workspace DPA (a Google EEA entity); Google LLC EU–U.S. DPF (Active) + EU SCCs for any ancillary US processing

Web fonts are self-hosted (PR #558) — no fonts CDN receives visitor traffic.

C. Optional / configuration-dependent integrations

Active only where the feature is enabled; listed for transparency:

Integration Trigger Personal data involved
European Commission EOS (EORI / AEO validation) Opt-in ingest advisory The declared operator registration ID (may identify a sole trader). The Commission service is an independent public-authority controller.
RFC 3161 Timestamping Authority (configurable) Opt-in sealing timestamp None — only a cryptographic hash is transmitted
IndexNow (Bing/Yandex/Seznam/Naver) Opt-in SEO notification None — public URLs only
EU DPP registry (when live and enabled) Regulatory pointer registration Pointer/identifier data only — never passport content
DeepL SE (Germany) Build-time translation of our UI strings None — no user or customer data

Change log

Date Change
2026-07-08 Initial draft register.
2026-07-08 Google Fonts removed as a recipient — fonts self-hosted (PR #558).
2026-07-16 Business mailbox moved from Proton AG to Google Workspace (Proton subscription cancelled).
2026-07-21 Verified the provider transfer-safeguard flags against authoritative sources. Neon — EU (Frankfurt, Launch plan), now a Databricks company; EU–U.S. DPF Active via Databricks, Inc. (covering Neon, LLC), SCCs in the Neon DPA. Resend — EU delivery via Amazon SES eu-west-1 (Ireland); DPA incorporates the EU SCCs (executed on signup) + EU–U.S. DPF Active (since 2025-03-06). Firebase / Identity Platform — auth data is US-only (no EU residency; firebase.google.com/support/privacy), under Google LLC DPF (Active) + SCCs. Google (Cloud/Workspace) — Google LLC EU–U.S. DPF Active + SCCs; Workspace Data Regions = Europe (data at rest) confirmed in the Admin console 2026-07-21.
2026-07-21 Added Google Tag Manager to §B (marketing-site tag container that loads Google Analytics; consent-gated on the Iubenda banner, held inert until consent — PR #1005). Disclosed in Privacy Policy §4/§5.
2026-07-21 Verified Stripe against the live account + primary sources: EEA contracting entity Stripe Payments Europe, Limited (Ireland) for our LT/EUR "Opendpp UAB" standard account; independent controller for payment processing; any US processing by Stripe, LLC under EU–U.S. DPF (Active, +UK +Swiss) + SCCs in the Stripe DPA.
2026-07-21 Scoped the Firebase / Identity Platform row to its real use (confirmed in code): US processing covers 2FA/MFA (workspace opt-in) + platform-admin sign-in; primary workspace sign-in is email/password, processed in the EU. Aligned Records of Processing C4 + Privacy Policy §5/§6, matching the /security page (#1010).
OpenDPP

The no-code platform for EU Digital Product Passports. Issue, seal, and publish — ready before the first deadlines.

Product

How it works Solutions Pricing Interactive demo Client Console

Company

About Why ESPR Security & Trust Seal Audit Portal

Resources

ESPR timeline DPP standards (EN 182xx) EU DPP Registry Battery Passport guide API reference AI knowledge bundle (OKF) Open source

Legal

Contact Support Privacy Policy Terms of Service Cookie Policy Legal Notice
© 2026 OpenDPP UAB · ESPR 2024/1781 · EU-hosted & eIDAS-signed