Subprocessors
The third-party service providers BizKitHub relies on to deliver its platform — with location, purpose, and the safeguards we require of them.
Overview
To deliver the BizKitHub platform we partner with a small number of specialist vendors. This page lists every sub-processor that may process customer data on our behalf, the location of that processing, and the safeguards in place. It forms part of the Data Processing Agreement (DPA) and Master Service Agreement (MSA) entered into between the customer and BizKitHub.
Last updated
May 12, 2025.
Current sub-processors
| Vendor | Category | Location | Purpose |
|---|---|---|---|
| AWS | Infrastructure | Global (EU, US, AP) | Cloud infrastructure — compute, storage, networking. |
| Vercel | Hosting | Global (EU, US) | Frontend hosting and edge deployment. |
| Neon | Database | EU, US | Managed PostgreSQL hosting. |
| Cloudflare | Security | Global | CDN, DDoS protection, DNS, edge compute. |
| Google Analytics | Analytics | Global | Website analytics and behaviour tracking. |
| Google Workspace | Productivity | Global | E-mail, document collaboration, productivity tools. |
| Stripe | Payments | Global (EU, US) | Payment processing and financial transactions. |
| Comgate | Payments | Czech Republic, EU | Local payment gateway for Czech and European markets. |
| Resend | US, EU | Transactional e-mail delivery. | |
| Sentry | Monitoring | US, EU | Error tracking and application performance monitoring. |
| Notion | Productivity | US, Global | Internal documentation and knowledge base. |
| Slack | Communication | US, Global | Internal team communication. |
Our commitments
- GDPR compliance — every sub-processor is contractually bound to GDPR-equivalent obligations.
- Data Processing Agreements — a signed DPA is in place with every vendor that processes customer data.
- Regular audits — continuous security assessments and periodic vendor reviews.
- Incident notification — we forward relevant security incidents to affected customers without undue delay.
Security standards required of vendors
- SOC 2 Type II — where applicable to the vendor's service.
- ISO 27001 — for infrastructure vendors handling customer data at scale.
- Encryption — TLS in transit and encryption at rest with vendor-managed key hierarchies.
- Penetration testing — regular vulnerability assessments by an independent third party.
Regional compliance
European Union
All sub-processors handling EU customer data comply with GDPR. Transfers outside the EU are protected by the European Commission's Standard Contractual Clauses. EU-anchored processors — Neon, Comgate, and EU regions of AWS / Cloudflare — allow data to stay within the block for customers that require it.
United States
US-based sub-processors operate under Standard Contractual Clauses (SCCs) and maintain the certifications required for lawful international transfers. Key US processors: AWS, Vercel, Stripe, Google services.
Change notifications
We notify affected customers at least 30 days before adding a new sub-processor that handles customer data. Contact privacy@bizkithub.com if you would like to be added to the notification list.