Version 2026-07-10 · provider: Minerics UG (haftungsbeschränkt), HRB 768686
Cloudflare sub-processor. Purpose: Compute, routing, access control and security. Data: Requests, response data, transient application payloads. Locations: Global edge; account/service controls apply. Assessment: Assess Cloudflare DPA, service path, remote access, applicable adequacy/DPF scope or SCC module and supplementary measures.
Cloudflare sub-processor. Purpose: Primary relational persistence. Data: Tenant, user, link, visitor, event, OAuth, acceptance and operational records. Locations: D1 placement determined by current database configuration; global service access may remain. Assessment: Storage placement alone does not decide Chapter V; include support/admin access, backups and Cloudflare corporate recipients.
Cloudflare sub-processor. Purpose: Serve tenant-hosted content. Data: Customer-uploaded bundles and revisions. Locations: R2 placement and global delivery depend on account/bucket configuration. Assessment: Verify bucket jurisdiction/localisation and CDN/access path; do not infer no transfer from an EU placement label.
Cloudflare sub-processor. Purpose: Distributed short-lived state and restore suppression. Data: Sessions, short-lived account/gate tokens, billing cache, deletion tombstones. Locations: Cloudflare global KV infrastructure. Assessment: Cloudflare DPA and relevant transfer tool/supplementary measures; minimise values and rely on TTL/deletion.
Cloudflare sub-processor/recipient subject to enabled configuration. Purpose: Optional signup/report bot defence. Data: Browser challenge/network data and verification token. Locations: Cloudflare global service. Assessment: Disabled by default; before enablement update notice and verify DPA, data flow, location and transfer basis.
Resend sub-processor. Purpose: Conditional transactional mail. Data: Recipient email, plain-text message, delivery metadata. Locations: United States and listed subprocessors. Assessment: Use only with account DPA evidence and a scope-matched transfer mechanism; supplier SCCs do not cover other flows.
Role split: processor/service provider for some merchant data; independent controller/MoR for legal payment duties. Purpose: Conditional billing and Merchant-of-Record functions. Data: Tenant/subscription metadata; Polar-collected buyer/payment data. Locations: United States and Polar-listed recipients. Assessment: Map each flow and role; apply Polar DPA/SCCs only where the processor transfer conditions are met.
PostHog sub-processor. Purpose: Conditional control-plane product analytics. Data: Allowlisted pseudonymous MCP product events. Locations: EU ingestion endpoint; US entity/support and subprocessors assessed separately. Assessment: EU Cloud is not conclusive. Require executed DPA, current list, remote-access analysis and appropriate transfer tool before enablement.
Public resolver recipient governed by its public privacy terms; not assumed to be a contracted Sendhey sub-processor for this free resolver call. Purpose: Resolve tenant destination before SSRF checks. Data: Signal-destination hostname and DNS query metadata; no visitor payload. Locations: Cloudflare global resolver. Assessment: Minimise to hostname/query type; public resolver logs and APNIC access follow Cloudflare's resolver policy. Reassess or replace for assured processing.
Public resolver recipient under Google Public DNS/Google privacy terms; not assumed to be a contracted Sendhey sub-processor for this resolver call. Purpose: Validate email-gate deliverability only when a tenant enables audience validation. Data: Visitor email-domain hostname, MX query/response metadata, Worker egress network address; no full visitor email or visitor IP. Locations: Google global resolver infrastructure, including possible United States processing. Assessment: Google documents temporary query/network logs for 24–48 hours and longer abuse exceptions, then sampled query/location statistics. Google states Google LLC's DPF participation; before relying on Article 45, verify the active certification and service/data scope for this actual flow. Otherwise do not enable audience validation for the pilot or replace it with a contracted assessed resolver. Sources: https://developers.google.com/speed/public-dns/privacy and https://policies.google.com/privacy/frameworks
Recipient role chosen and documented by tenant; not automatically a minerics UG sub-processor. Purpose: Customer-instructed notification/integration. Data: Tenant-allowlisted event fields, optionally confirmed raw visitor email. Locations: Tenant-configured region and HTTPS endpoint. Assessment: Tenant records recipient role, region and mechanism. Sendhey blocks private endpoints and does not claim the tenant's text proves Chapter V compliance.
Cloudflare sub-processor. Purpose: Security and reliability diagnostics. Data: Explicit redacted operational errors. Locations: Cloudflare observability service. Assessment: Automatic invocation logs/traces are disabled; verify account retention/access and Cloudflare transfer terms before pilot.
Cloudflare sub-processor. Purpose: Operational recovery. Data: Encrypted database restore points. Locations: Cloudflare D1 backup infrastructure. Assessment: Provider-controlled 7/30-day window; include backup access/location in Cloudflare assessment and reapply deletion tombstones after restore.
minerics UG independent controller for its support/security purpose; email vendors may be processors. Purpose: Customer support, security and account administration. Data: Account contact, voluntary support content, restricted operational context. Locations: Germany and configured email/provider support locations. Assessment: Minimise tickets, restrict access, separate controller records from tenant instructions, and verify Namecheap/other enabled support provider terms.
minerics UG personnel. Purpose: Administration only if later approved. Data: No standing third-country personnel access authorised for the Lean pilot. Locations: Germany for the current pilot baseline. Assessment: Any new remote country or contractor is a change requiring role, confidentiality, access, subprocessor and Chapter V review before access.
Contact support@sendhey.app. This operational baseline is not a legal-compliance certification.
About · Privacy · Legal notice · Report illegal content · Terms · DSA