Legal

Subprocessors

Last Updated: 2026-05-05

DeData uses the third-party service providers listed below to deliver the Service. Each subprocessor processes only the categories of data necessary for its stated purpose. We sign a Data Processing Agreement (DPA) with every subprocessor that handles personal data and rely on Standard Contractual Clauses (SCC) for international transfers where required.

This list is incorporated by reference into our Privacy Policy. Material changes will be announced at least 30 days before they take effect.

Current Subprocessors

SubprocessorPurposeData ProcessedLocationTransfer Mechanism
Stripe, Inc.Payment processing & subscription billingBilling email, payment method tokens, customer nameUSASCC + DPA
Wildbit, LLC (Postmark)Transactional email (verification, receipts, account events)User email, name, account eventsUSASCC + DPA
Railway Corp.Application hosting, Postgres database, Redis, object storageAll PII categories stored by the ServiceUSASCC + DPA
Bright Data Ltd.Residential proxy network for broker scans and removalsUser name, address, phone (transient — passed in request bodies during scan; not persistently stored by provider)Global egress IPs (US-residential pool used by default)SCC + DPA
SentryError monitoring & crash reportingIP address, error stack traces (scrubbed of PII server-side)USASCC
Cloudflare, Inc.CDN, DDoS protection, WAFIP address, request metadata, TLS fingerprintGlobal edge networkSCC

Get notified of subprocessor changes

We will email you at least 30 days before any new subprocessor that handles personal data is added. Send a blank email to the address below with the subject line “Subscribe: subprocessor updates.”

privacy@dedatalabs.org
Questions or DPA requests? Email privacy@dedatalabs.org.