Skip to content

Sub-processors

Third parties that process customer personal data on Sylphx’s behalf to deliver the platform. We update this list at least 10 days before a new sub-processor processes customer personal data. Canonical inventory: docs/compliance/subprocessors.md.

Definition

What counts as a sub-processor on this page — and which third parties deliberately do not.

A sub-processor is a third party that processes customer personal data on Sylphx's behalf. This does not include third parties selected by a customer to front or operate their own app. Sylphx Email BaaS is self-hosted Stalwart + smtp-relay on declared infrastructure — not a separate legal sub-processor.

Sub-processor
A third party that processes customer personal data on Sylphx’s behalf to deliver the platform.
Customer personal data
Personal data a customer — or that customer’s end users — entrusts to the platform, which Sylphx processes on the customer’s behalf under the Data Processing Agreement (DPA).
Sylphx’s role
Under the DPA, Sylphx processes customer personal data on the customer’s behalf as a processor. The executed DPA with each provider below is the evidence of the chain.
Controller and processor
The Data Processing Agreement names the customer as the data controller and Sylphx as the processor: the customer decides what goes into the platform, and Sylphx processes it on the customer’s behalf.
Third parties you choose
A CDN or other service a customer picks to front or operate its own app is not a Sylphx sub-processor. Those relationships run on the customer’s own contracts.
Software Sylphx operates
Our own infrastructure services — mail, databases, object storage and the image registry — run on declared infrastructure operated by Sylphx, so they are not separate legal sub-processors.

Where this list comes from

docs/compliance/subprocessors.md is the canonical inventory. This page mirrors it as of 2026-07-12. A provider removed from that file is not re-added here without an executed DPA and the notice in Notice and change policy.

Active sub-processors

Every provider engaged for customer personal data today, with the region and the contract that governs it.

Active sub-processors as published on 2026-07-12. docs/compliance/subprocessors.md is the canonical inventory and wins any conflict with this table.
ProviderServiceData processedRegionContract
Hetzner Online GmbHBare-metal hosting (FSN1 datacenter, Falkenstein DE)All customer data at rest + in transit through the service runtime boundaryEU (DE)DPA executed; SOC 2 Type II inherited
Cloudflare, Inc.Edge + DDoS protection for *.sylphx.com and *.api.sylphx.comRequest metadata only — no customer data persists at the edgeGlobal edgeDPA executed
Stripe, Inc.Billing + payment processingCardholder data (Stripe is the controller); customer-of-Sylphx billing-contact metadataUS (with EU sub-processors per Stripe DPA)DPA executed; PCI DSS Level 1 inherited
GitHub, Inc.Source-code hosting, GitHub App webhooks/API, and Actions control plane; execution uses Sylphx self-hosted CI ComputeSylphx-internal source and repository-event metadata — listed for completenessGitHub service regionsStandard GitHub Enterprise terms

Pending / proposed

Rows listed for transparency: none of them processes customer personal data today.

None of the entries below currently processes customer personal data. Before one is activated, it is moved to the active list as described in Notice and change policy.

Wired-but-inactive and self-hosted rows, kept here so the list never reads as complete when it is not.
ProviderProposed serviceStatus
Sentry (Functional Software, Inc.)Error-tracking sink for level >= error log linesWired but inactive (no DSN provisioned)
Tempo / Loki / Mimir (Grafana Labs OSS — self-hosted)Distributed-tracing + log warehouseSelf-hosted, no third-party sub-processor relationship

Activating any row above is an addition, with the same notice as any other.

Notice and change policy

We update this list at least 10 days before a new sub-processor starts; removals need no notice.

We tell customers of an intended addition or replacement by updating this list at least 10 days before the new sub-processor processes customer personal data. Email hi@sylphx.com to be subscribed to change notices.

Notice windows as published in docs/compliance/subprocessors.md and mirrored here.
Change typeNotice
AdditionThis list is updated at least 10 days before activation; you may object within that period — see Customer rights.
ReplacementSame as an addition.
RemovalThe list is updated; no objection window applies.

Customer rights

Request the list, object within 10 days of a change, or ask for DPA evidence under NDA.

Request the list
At any time. This document is the canonical answer; email the address below and we will confirm the current version.
Object to a new sub-processor
On reasonable data protection grounds, within 10 days of the list being updated. Your remedy is to stop using the affected part of the service; we may, at our discretion, offer an alternative instead.
DPA evidence
Request confirmation of our DPA with a specific sub-processor, under NDA; we may redact commercial terms.
Subscribe to changes
Email the address below to be added to sub-processor change notices.

For the surrounding controls, read the security overview, and for the processing story behind this list, read the Privacy Policy.

Where this document lives

Canonical route, the addresses that redirect to it, and the file that wins any conflict.

Canonical route
/legal/sub-processors — the URL to cite and to subscribe against.
Alias route
The addresses this document used to answer at — /sub-processors and /legal/subprocessors — now answer a permanent redirect to the canonical route.
Canonical inventory
docs/compliance/subprocessors.md, dated 2026-07-12. If this page and that file ever disagree, the file is correct and this page is a bug — tell us at hi@sylphx.com.

Sub-processor requests

Request the current list, object to a proposed addition, or ask for executed DPA evidence. Ask to be subscribed to change notices from this address.

Sylphx Limited, a company registered in England and Wales (company number 16438428). Registered office: 128 City Road, London EC1V 2NX. Phone: +44 333 335 7935. Email: hi@sylphx.com.