Everyone who touches your data.
Four providers. Under GDPR Art. 28 a sub-processor is any third party that can access personal data we hold - not just an outsourced service - so infrastructure counts even when we run the software on it ourselves. Our hosting provider is identified by category and location rather than by name, an operational-security choice; we disclose its identity to any data subject who asks.
EU hosting provider
GERMANY (EU)- DATA IT SEES
- Everything Pepdor stores: waitlist and back-in-stock email addresses, wholesale enquiries (email, company, message), submitted test reports, and uploaded COA files.
- TRANSFER SAFEGUARD
- Processing stays inside the EU, so no third-country transfer applies. Covered by a data processing agreement. We identify this provider by category rather than by name as an operational-security measure; its identity is disclosed to you on request.
Vercel Inc.
UNITED STATES- DATA IT SEES
- Technical request data needed to serve pages (IP address, user agent), plus cookieless analytics: page URL, referrer, coarse location (country/region/city), browser, device type and page-speed measurements.
- TRANSFER SAFEGUARD
- 2021 Standard Contractual Clauses (Module Two, controller to processor) and the UK IDTA, under Vercel's Data Processing Addendum.
Resend, Inc.
UNITED STATES- DATA IT SEES
- The recipient's email address and the contents of the message, for confirmation, unsubscribe, back-in-stock and wholesale-reply emails only.
- TRANSFER SAFEGUARD
- Standard Contractual Clauses under Resend's Data Processing Addendum.
Cloudflare, Inc.
UNITED STATES (GLOBAL EDGE NETWORK)- DATA IT SEES
- Traffic to our API passes through Cloudflare's network for DDoS protection, so it can technically see what forms submit - email addresses and messages - in transit. It also resolves DNS for pepdor.com and forwards mail sent to our own addresses.
- TRANSFER SAFEGUARD
- EU-U.S. Data Privacy Framework certification, with Standard Contractual Clauses as a fallback, under Cloudflare's customer DPA. Traffic is re-encrypted between Cloudflare and our server.
Deliberately not on this list
Web fonts are self-hosted and served from our own domain, so no request reaches a font CDN and no visitor data is shared with one. There are no advertising pixels, no tag managers, no session recorders, and no payment processor - Pepdor is pre-launch and collects no payments, so no card or wallet data exists to share.
Changes and objections
This page changes when the list does - adding a payment processor at launch will appear here first. To ask about a sub-processor, object to one, or request a copy of the underlying agreements, email legal@pepdor.com.
Read this next to the privacy policy, which covers what we collect and how long we keep it. Research use only - not for human or veterinary use.