Sub-processors
Every third party that touches data on our side, what it does and what it can see. This is the annex to attach to a data processing agreement.
Last updated 27 August 2026.
| Provider | Purpose | Data it holds | Location |
|---|---|---|---|
| Google Cloud Google Ireland Ltd / Google LLC |
Firestore, Cloud Functions, Hosting, Authentication — everything the service runs on | Account email and id, findings, monitored sites, alert address, server logs | Frankfurt europe-west3 |
| Resend Resend Inc, sending via AWS SES |
Delivering monitoring alert emails | The alert address and the contents of the alert: the site, which criteria started failing, which pages stopped loading | Ireland eu-west-1 |
That is the whole list. There is no analytics provider, no error tracker, no customer messaging tool, no CDN in front of the report pages and no advertising network — not as a privacy feature we are selling, but because the product has not needed one.
Transfers
Both companies are incorporated in the United States. The data itself is stored and processed in the EU regions named above, and both providers offer the European Commission's standard contractual clauses, which we rely on.
We say this rather than "your data never leaves the EU" because the second sentence reads better and is harder to defend. Where the bytes sit and where the company sits are two different questions, and a buyer's legal team will ask both.
What none of them sees
- The markup of pages you audit — it is removed before anything is uploaded.
- Screenshots — never taken.
- Anything behind a login on the sites you audit.
- Your local audit history, which stays in your browser unless you share a report.
Changes
Adding a sub-processor changes this page and the date on it, and account holders are emailed before it starts processing anything. If a new one is unacceptable to you, that is a reason to leave and we will not argue about the notice period.
Questions: privacy@skiplink.app.