This page lists the third parties Watasu LTD (“Watasu”) engages as subprocessors to provide the Watasu platform (the “Service”). Each subprocessor is bound by a written agreement requiring data protection terms no less protective than those Watasu commits to in its Data Processing Agreement.
How we manage subprocessors
We engage subprocessors only where necessary to operate the Service. Before engaging any new subprocessor, we conduct a security and data protection review covering:
- Their certifications and audit reports (ISO 27001, SOC 2, etc.);
- Their data protection terms and ability to support GDPR Article 28 obligations;
- Their location and the cross-border transfer mechanism, if applicable;
- Their incident response and breach notification commitments.
Customers may subscribe to subprocessor change notifications by emailing subprocessors@watasu.io with the subject line “Subscribe”. We give at least 30 days’ advance notice of any new or replacement subprocessor.
Current subprocessors
Infrastructure
| Subprocessor | Service provided | Location of processing | Transfer mechanism |
|---|---|---|---|
| Hetzner Online GmbH | Bare-metal and virtual server hosting; data centre operations; storage. DPA: hetzner.com/AV/DPA_en.pdf | Germany (Nuremberg, Falkenstein); Finland (Helsinki) | UK→EEA adequacy; intra-EEA |
Payments
| Subprocessor | Service provided | Location of processing | Transfer mechanism |
|---|---|---|---|
| Stripe Payments UK Limited (SPUKL) | Payment processing for Credit purchases; UK merchant entity. FCA-authorised electronic money institution (FRN 900461). Affiliate Stripe Payments Europe Ltd performs EU card scheme routing. | United Kingdom; Ireland (affiliate processing); United States (Stripe Inc. fraud prevention infrastructure) | UK-domestic for SPUKL; UK→EEA adequacy for Stripe Europe affiliate; SCCs / DPF for any onward US transfer by Stripe Inc. |
Communications
| Subprocessor | Service provided | Location of processing | Transfer mechanism |
|---|---|---|---|
| Twilio Inc. (operating SendGrid) | Transactional and notification email delivery to customers | United States (with optional EU-region sending available for some workloads) | EU-US Data Privacy Framework + UK Extension to the EU-US DPF (primary); EU Standard Contractual Clauses + UK International Data Transfer Addendum (backstop) |
EU GDPR Article 27 representative
| Entity | Role | Location of processing | Transfer mechanism |
|---|---|---|---|
| Euverify Ltd | EU GDPR Article 27 representative for data subjects in the EEA. Receives and routes Data Subject inquiries via gdpr.euverify.com. | Ireland (Cork) | Intra-EEA |
Scope
Customer Personal Data hosted on the Watasu platform is stored within the European Economic Area at Hetzner data centres in Germany and Finland. Subprocessors outside the EEA process only limited operational data as described above, not customer-deployed application data.
Notification of changes
We notify customers of:
- Additions or replacements of subprocessors that process Customer Personal Data, at least 30 days in advance;
- Material changes in scope of an existing subprocessor’s processing, at least 30 days in advance;
- Removal of subprocessors, contemporaneously.
Customers may object to a new subprocessor on reasonable data protection grounds within 15 days of notice; if the objection cannot be resolved, the affected Service component may be terminated with a pro-rata refund of unused prepaid Credits, as described in our DPA.
Contact
Questions, objections, or notification subscriptions: subprocessors@watasu.io
This page is the authoritative list of Watasu’s subprocessors. The list is reviewed and updated as our infrastructure evolves.