Legal
Sub-processors
The third parties that process data on our behalf to run Spodus Cloud. Named, not categorised.
Effective July 28, 2026
A sub-processor is any company we let touch your data in order to deliver the service. Plenty of vendors disclose these as vague categories like “cloud hosting provider.” That is not much use to anyone doing a real vendor review, so here is the actual list.
1. Current sub-processors
| Provider | Purpose | Location | Certifications |
|---|---|---|---|
| Hetzner Online GmbH | Application hosting, database and backups | Nuremberg, Germany | ISO 27001:2022, PCI DSS 4.0 |
| Cloudflare, Inc. | DNS, CDN, TLS termination, DDoS protection, and object storage for uploaded files (R2) | Global edge network | SOC 2 Type II, ISO 27001, ISO 27701, PCI DSS Level 1 |
| Stripe, Inc. | Payment processing for Spodus subscriptions | United States | PCI DSS Level 1, SOC 2 Type II |
| Resend (Plus Five Five, Inc.) | Transactional and notification email | United States | SOC 2 Type II |
| Plausible Analytics | Privacy-focused website analytics on the marketing site (no cookies, no cross-site tracking) | European Union | GDPR-focused; EU-hosted |
| Google LLC | OAuth sign-in and Google Calendar sync, only for a workspace that connects a Google account | United States | ISO 27001, SOC 2 Type II, SOC 3 |
| Microsoft Corporation | Microsoft Entra OAuth and Outlook/Graph calendar sync, only for a workspace that connects a Microsoft account | United States | ISO 27001, SOC 2 Type II |
Certifications in that last column are held by the provider named on that row. They are not ours, and we don’t present them as ours. What Spodus itself does and does not hold is set out on our security page.
2. Our own staff and infrastructure
Beyond the providers above, your data is accessible only to Spodus personnel who need it to operate and support the service. That access is authenticated, limited to what the task requires, and logged. We do not use your business records to train machine-learning models, our own or anyone else’s, and we do not sell them.
3. What we require of a sub-processor
Before a provider goes on that list, we require that it:
- enters a written data processing agreement with us that binds it to no less protection than we owe you;
- processes data only on our documented instructions, and not for its own purposes;
- maintains an independently assessed security program appropriate to what it handles; and
- is reviewed by us before it is engaged, and again when its role materially changes.
4. How we notify you of changes
We will publish any new or replacement sub-processor on this page at least 30 days before it begins processing your data, and update the effective date at the top.
To be told directly rather than checking this page, email [email protected] and we’ll add you to the notification list. There’s no charge and it is not tied to a plan tier.
5. Objecting to a new sub-processor
If you have a reasonable, documented objection to a sub-processor we propose to add, tell us within the notice window and we will work with you in good faith to find an alternative arrangement. Where we cannot, you may terminate the affected subscription and receive a pro-rated refund of fees you have already paid for the unused remainder of the term.
Olum LLC8206 Louisiana Blvd NESte A #8845Albuquerque NM 87113