Legal

Subprocessors

Every third party that may process personal data on our behalf, what they do, where they are, and how transfers to them are protected.

Effective
26 July 2026
Version
1.0

DropTheDoc uses a small number of infrastructure vendors to run the service. Each is a subprocessor under Article 28 of the GDPR and a Data Processor under the Digital Personal Data Protection Act, 2023, each is bound by a written contract that limits them to our documented instructions and imposes confidentiality and security obligations at least as protective as our own, and each is listed here.

1.Current subprocessors

Provider

Vercel Inc. (United States)

What it does for us

Application hosting, serverless compute, content delivery and scheduled jobs. Everything you do in the product passes through it.

Personal data it may process

All data in transit, request logs including IP address, and anything held in memory during a request.

Location

United States, with edge delivery from regions worldwide.

Transfer safeguard

Standard Contractual Clauses. Provider publishes a SOC 2 Type II report.

Provider

Neon Inc. (United States)

What it does for us

Managed PostgreSQL database.

Personal data it may process

Account and profile data, workspace and membership records, document metadata, recipient names and email addresses, field values, and the audit trail.

Location

The cloud region configured for the deployment.

Transfer safeguard

Standard Contractual Clauses. Provider publishes a SOC 2 Type II report.

Provider

Vercel Blob (Vercel Inc., United States)

What it does for us

Object storage for uploaded and completed document files.

Personal data it may process

Document files only, and each one is encrypted by us with AES-256-GCM before it is written, so the provider holds ciphertext rather than readable documents.

Location

United States and the provider's storage regions.

Transfer safeguard

Standard Contractual Clauses, plus encryption where we hold the key.

Provider

Resend, Inc. (United States)

What it does for us

Transactional email delivery: signing invitations, reminders, completion notices, password resets and verification emails.

Personal data it may process

Recipient and sender names and email addresses, document titles, signing links, and email delivery metadata.

Location

United States.

Transfer safeguard

Standard Contractual Clauses. Provider publishes a SOC 2 Type II report.

Provider

Inngest, Inc. (United States)

What it does for us

Background job orchestration for reminders, expiry sweeps and other scheduled work, where configured for the deployment.

Personal data it may process

Document and job identifiers, and event metadata. Not document contents.

Location

United States.

Transfer safeguard

Standard Contractual Clauses.

2.Used only if you turn them on

These are not used unless you choose a feature that requires them, so most accounts never touch them.

Provider

Google LLC, GitHub, Inc., Microsoft Corporation

When it is used

Only if you sign in with Google, GitHub or Microsoft single sign-on.

Data involved

The account identifier, email address and display name that the provider returns to us when you authorise sign-in. We send them nothing about your documents.

Provider

Payment processor

When it is used

Only on a paid plan.

Data involved

Billing contact details and payment credentials, which go to the processor directly and are never stored on our systems. The processor is named on your invoice and in the refund and cancellation policy.

3.Our own people

[your registered company name] personnel in India may access personal data where necessary to operate the service, respond to a support request or investigate an incident. Access is limited to those who need it, is subject to confidentiality obligations that survive the end of their engagement, and is not a substitute for the customer's own controls.

4.How we change this list

Our data processing addendum gives us a general authorisation to appoint subprocessors, subject to the following, which is the protection that makes a general authorisation acceptable:

  1. We give at least 30 days' notice before a new subprocessor starts processing personal data, by email to workspace owners and by updating this page.
  2. You may object on reasonable data protection grounds within those 30 days by writing to privacy@dropthedoc.xyz.
  3. If we cannot resolve your objection, you may terminate the affected part of the service and receive a pro-rata refund of prepaid fees for the unused period, and you will not be charged a termination fee.
  4. We impose data protection obligations on every subprocessor that are no less protective than those in our own addendum, and we remain fully liable to you for their performance.

To receive notice of changes, email privacy@dropthedoc.xyz with the subject "subprocessor notifications" and we will add you to the list.

5.International transfers

We operate from India and our providers are established in the United States, so personal data crosses borders. For data originating in the EEA we rely on the Standard Contractual Clauses in Commission Decision (EU) 2021/914, for the UK on the International Data Transfer Addendum, and for Switzerland on the SCCs as amended for Swiss law. Section 16 of the DPDP Act permits transfer out of India except to countries the Central Government restricts by notification.

Because document files are encrypted with a key we hold, storage providers hold ciphertext rather than readable content. That is a supplementary measure for the purposes of a transfer impact assessment, and it is described in clause 1 of the security page.

Version history

  • Version 1.0 · 26 July 2026

    First publication.