Subprocessors
Every third party that may process personal data on our behalf, what they do, where they are, and how transfers to them are protected.
- Effective
- 26 July 2026
- Version
- 1.0
DropTheDoc uses a small number of infrastructure vendors to run the service. Each is a subprocessor under Article 28 of the GDPR and a Data Processor under the Digital Personal Data Protection Act, 2023, each is bound by a written contract that limits them to our documented instructions and imposes confidentiality and security obligations at least as protective as our own, and each is listed here.
1.Current subprocessors
Provider
Vercel Inc. (United States)
What it does for us
Application hosting, serverless compute, content delivery and scheduled jobs. Everything you do in the product passes through it.
Personal data it may process
All data in transit, request logs including IP address, and anything held in memory during a request.
Location
United States, with edge delivery from regions worldwide.
Transfer safeguard
Standard Contractual Clauses. Provider publishes a SOC 2 Type II report.
Provider
Neon Inc. (United States)
What it does for us
Managed PostgreSQL database.
Personal data it may process
Account and profile data, workspace and membership records, document metadata, recipient names and email addresses, field values, and the audit trail.
Location
The cloud region configured for the deployment.
Transfer safeguard
Standard Contractual Clauses. Provider publishes a SOC 2 Type II report.
Provider
Vercel Blob (Vercel Inc., United States)
What it does for us
Object storage for uploaded and completed document files.
Personal data it may process
Document files only, and each one is encrypted by us with AES-256-GCM before it is written, so the provider holds ciphertext rather than readable documents.
Location
United States and the provider's storage regions.
Transfer safeguard
Standard Contractual Clauses, plus encryption where we hold the key.
Provider
Resend, Inc. (United States)
What it does for us
Transactional email delivery: signing invitations, reminders, completion notices, password resets and verification emails.
Personal data it may process
Recipient and sender names and email addresses, document titles, signing links, and email delivery metadata.
Location
United States.
Transfer safeguard
Standard Contractual Clauses. Provider publishes a SOC 2 Type II report.
Provider
Inngest, Inc. (United States)
What it does for us
Background job orchestration for reminders, expiry sweeps and other scheduled work, where configured for the deployment.
Personal data it may process
Document and job identifiers, and event metadata. Not document contents.
Location
United States.
Transfer safeguard
Standard Contractual Clauses.
2.Used only if you turn them on
These are not used unless you choose a feature that requires them, so most accounts never touch them.
Provider
Google LLC, GitHub, Inc., Microsoft Corporation
When it is used
Only if you sign in with Google, GitHub or Microsoft single sign-on.
Data involved
The account identifier, email address and display name that the provider returns to us when you authorise sign-in. We send them nothing about your documents.
Provider
Payment processor
When it is used
Only on a paid plan.
Data involved
Billing contact details and payment credentials, which go to the processor directly and are never stored on our systems. The processor is named on your invoice and in the refund and cancellation policy.
3.Our own people
[your registered company name] personnel in India may access personal data where necessary to operate the service, respond to a support request or investigate an incident. Access is limited to those who need it, is subject to confidentiality obligations that survive the end of their engagement, and is not a substitute for the customer's own controls.
4.How we change this list
Our data processing addendum gives us a general authorisation to appoint subprocessors, subject to the following, which is the protection that makes a general authorisation acceptable:
- We give at least 30 days' notice before a new subprocessor starts processing personal data, by email to workspace owners and by updating this page.
- You may object on reasonable data protection grounds within those 30 days by writing to privacy@dropthedoc.xyz.
- If we cannot resolve your objection, you may terminate the affected part of the service and receive a pro-rata refund of prepaid fees for the unused period, and you will not be charged a termination fee.
- We impose data protection obligations on every subprocessor that are no less protective than those in our own addendum, and we remain fully liable to you for their performance.
To receive notice of changes, email privacy@dropthedoc.xyz with the subject "subprocessor notifications" and we will add you to the list.
5.International transfers
We operate from India and our providers are established in the United States, so personal data crosses borders. For data originating in the EEA we rely on the Standard Contractual Clauses in Commission Decision (EU) 2021/914, for the UK on the International Data Transfer Addendum, and for Switzerland on the SCCs as amended for Swiss law. Section 16 of the DPDP Act permits transfer out of India except to countries the Central Government restricts by notification.
Because document files are encrypted with a key we hold, storage providers hold ciphertext rather than readable content. That is a supplementary measure for the purposes of a transfer impact assessment, and it is described in clause 1 of the security page.
Version history
- Version 1.0 · 26 July 2026
First publication.