Skip to content
SUB-PROCESSORS

Everyone who touches your data.

Four providers. Under GDPR Art. 28 a sub-processor is any third party that can access personal data we hold - not just an outsourced service - so infrastructure counts even when we run the software on it ourselves. Our hosting provider is identified by category and location rather than by name, an operational-security choice; we disclose its identity to any data subject who asks.

What the frontend host never sees.The waitlist, back-in-stock, wholesale and test submission forms post from your browser to our API in Germany - never through the frontend host. The one stop on the way is Cloudflare's network, which shields the API from attacks; traffic is encrypted to Cloudflare and re-encrypted from Cloudflare to our server.

EU hosting provider

GERMANY (EU)
Backend hosting and database
DATA IT SEES
Everything Pepdor stores: waitlist and back-in-stock email addresses, wholesale enquiries (email, company, message), submitted test reports, and uploaded COA files.
TRANSFER SAFEGUARD
Processing stays inside the EU, so no third-country transfer applies. Covered by a data processing agreement. We identify this provider by category rather than by name as an operational-security measure; its identity is disclosed to you on request.

Vercel Inc.

UNITED STATES
Frontend hosting, Web Analytics and Speed Insights
DATA IT SEES
Technical request data needed to serve pages (IP address, user agent), plus cookieless analytics: page URL, referrer, coarse location (country/region/city), browser, device type and page-speed measurements.
TRANSFER SAFEGUARD
2021 Standard Contractual Clauses (Module Two, controller to processor) and the UK IDTA, under Vercel's Data Processing Addendum.
Vercel data processing terms

Resend, Inc.

UNITED STATES
Transactional email delivery
DATA IT SEES
The recipient's email address and the contents of the message, for confirmation, unsubscribe, back-in-stock and wholesale-reply emails only.
TRANSFER SAFEGUARD
Standard Contractual Clauses under Resend's Data Processing Addendum.
Resend data processing terms

Cloudflare, Inc.

UNITED STATES (GLOBAL EDGE NETWORK)
DNS, security proxy in front of our API, inbound email forwarding
DATA IT SEES
Traffic to our API passes through Cloudflare's network for DDoS protection, so it can technically see what forms submit - email addresses and messages - in transit. It also resolves DNS for pepdor.com and forwards mail sent to our own addresses.
TRANSFER SAFEGUARD
EU-U.S. Data Privacy Framework certification, with Standard Contractual Clauses as a fallback, under Cloudflare's customer DPA. Traffic is re-encrypted between Cloudflare and our server.
Cloudflare data processing terms

Deliberately not on this list

Web fonts are self-hosted and served from our own domain, so no request reaches a font CDN and no visitor data is shared with one. There are no advertising pixels, no tag managers, no session recorders, and no payment processor - Pepdor is pre-launch and collects no payments, so no card or wallet data exists to share.

Changes and objections

This page changes when the list does - adding a payment processor at launch will appear here first. To ask about a sub-processor, object to one, or request a copy of the underlying agreements, email legal@pepdor.com.

Read this next to the privacy policy, which covers what we collect and how long we keep it. Research use only - not for human or veterinary use.