merkleset
المستندات القانونية

النسخة: 2026-09-09سارٍ من: 2026-09-09معلوماتي

هذا المستند يُنشر بالإنجليزية فقط. النص الإنجليزي هو المرجع المعتمد: يُسجَّل القبول مقابل قيمة SHA-256 للمصدر الإنجليزي، فلا يمكن أن تكون أي ترجمة هي النص الذي وافقت عليه.

Subprocessor Annex

Version 2026-09-09. Effective 2026-09-09. Supersedes the version of 2026-08-19.

This is the complete list of third parties involved in processing personal data for merkleset. There are four. It is referenced by section 6 of the Privacy Policy and incorporated into the Data Processing Agreement as Annex II.

What changed in this version. No provider was added or removed, and no new company sees your data. On 2026-09-09 object storage moved off the application host into DigitalOcean Spaces, DigitalOcean's own managed object storage — the same legal entity that already hosts the platform. What changed is where inside that provider the data sits: release artifacts and internal raw evidence are now in a Space in region sfo3 (San Francisco, United States), while the application host remains a droplet in nyc1 (New York, United States). Earlier versions of this annex said object storage was self-hosted and that the hosting provider was therefore also the storage provider; the second half is still true, the first half is not. Two US regions of one US provider instead of one — the third-country transfer analysis is unchanged in substance.

Values marked placeholder have not been verified yet and will be filled in before this annex is published as final. We would rather show you a visible gap than a confident guess.

1. The list

ProviderRolePersonal dataLocationTransfer mechanism
DigitalOcean, LLCInfrastructure hosting and object storage. A single virtual host runs the whole platform; release artifacts and internal raw evidence live in a DigitalOcean Spaces bucket operated by the same providerAll service data at rest and in transit inside the host: account records, consent records, entitlements, application and web server logs. In object storage: dataset release artifacts and the unscreened raw source snapshots kept as provenance evidenceUnited States company. Two US regions: application host nyc1 (New York, United States) — verified from the provider's own metadata service on the host itself — and object storage sfo3 (San Francisco, United States)Provider data processing agreement plus EU Standard Contractual Clauses: {{TRANSFER_MECHANISM}} (placeholder)
StripeMerchant of record for the purchase, plus payment processing, billing and invoicing, tax determination and remittance, fraud and dispute handling, and payment-related customer support. Contracting entity: {{STRIPE_CONTRACTING_ENTITY}} (placeholder)Name, email address, billing address, tax identification number, transaction and payment metadata. Card data never reaches our systemsEuropean Union and United StatesProvider data processing agreement plus EU Standard Contractual Clauses: {{TRANSFER_MECHANISM}} (placeholder)
Mailgun (Sinch)Transactional email: one-time login codes and contact form messagesRecipient email address, message content (a login code, or the contact form's name, company and message)European Union — EU region confirmed. Mail is sent through the provider's EU relayNone required for the EU region
GoogleWebsite analytics only — Google Analytics 4, measurement ID G-HZFYWX9XE4. Loaded only after the visitor accepts analytics in the consent banner; denied by default under Google Consent Mode v2. No advertising, remarketing or conversion product is used, and the property is not linked to a Google Ads accountA randomly generated analytics identifier stored in a first-party cookie on the visitor's device, pages viewed and events recorded, approximate location derived from the IP address, and device/browser characteristics. No account data: no email address, no user id, no order or wallet data, and the Google Analytics User-ID feature is not usedUnited States company. Processed on Google infrastructure operated globally, including in the United StatesProvider data processing terms plus EU Standard Contractual Clauses: {{TRANSFER_MECHANISM}} (placeholder)

We use no content delivery network, no session recording, no advertising network, no customer support platform, and no third-party script on the website other than the consent-gated Google Analytics tag described above.

2. Notes that matter for a procurement review

2.1 Stripe is not merely our processor. As merchant of record Stripe invoices you, collects and remits applicable taxes and handles payment disputes, determining its own purposes for that relationship. For billing data it therefore acts as an independent controller, and its own privacy notice governs it. We remain the controller for your account and your use of the service.

2.2 DigitalOcean is a United States company, and both of our regions are United States datacentres. The application host's region — nyc1, New York — was read from the droplet's own DigitalOcean metadata service, a first-party fact rather than a netblock inference. Object storage is in sfo3, San Francisco. Data at rest therefore sits in the United States, so hosting is a third-country transfer as such, not merely a potential one, and we rely on the provider's data processing agreement together with the Standard Contractual Clauses. Adding a second region of the same provider does not add a transfer leg to a different country, a different company or a different contract.

2.3 Object storage is the same provider as hosting, in a managed service rather than on our own host. Until 2026-09-09 release artifacts and internal raw evidence lived in MinIO running on the application host itself; since then they live in DigitalOcean Spaces, region sfo3. That is a change of service, not of company, so no provider is added to this list — but the earlier claim that object storage was self-hosted no longer describes reality, which is why this version exists. The bucket is private: the objects are reachable only through short-lived signed URLs we issue to an entitled customer, and only the ingestion pipeline holds credentials that can write.

2.4 Mailgun sees email addresses and message bodies. That is unavoidable for a service that authenticates by emailing a code. It is used in the EU region so that this data stays inside the European Economic Area.

2.5 Google touches the website, not the product. Google Analytics runs on the public website only. It is not present in the API, in the download path, in the account area's data flows or in the ingestion pipeline, and it never receives dataset content, release artifacts, entitlements or billing records. The two things that make this leg unusual on this list are worth stating plainly for a reviewer: it is the only provider here whose processing depends on a visitor's consent and therefore does not happen at all for a visitor who refuses; and it is the only one that processes data about visitors rather than about customers. Google's own role designation for Google Analytics, and the exact contractual instrument for the US leg, are part of the {{TRANSFER_MECHANISM}} item still open above.

2.6 No employees, no contractors with access. The service is operated by one individual. There is no support outsourcing, no offshore team and no third-party administrator.

3. Changes to this list

3.1 Adding or replacing a provider means publishing a new version of this annex. So does a material change in where an existing provider processes the data, which is what produced this version.

3.2 Customers who have signed the Data Processing Agreement get at least 30 days' notice by email before a new subprocessor starts processing their data, and may object on data protection grounds under clause 5.3 of that agreement.

3.3 This annex is versioned by effective date, like every other document in this set.

4. Contact

Questions, or a request for a copy of a provider's data processing terms: privacy@merkleset.com.

sha256 210702994bfc…f6d15237e20d