# DPP GRID SUBPROCESSOR AND THIRD-PARTY SERVICES NOTICE

**Version 1.2 — 31 July 2026**

## 1. Purpose

DPP Grid uses carefully selected service providers to operate the platform. This Notice distinguishes:

- **Sub-processors** that process customer-controlled personal data for DPP Grid;
- **independent controllers** that determine parts of their own processing; and
- **customer-connected services** selected and controlled by the customer.

The classification may depend on the service and configuration. Our Data Processing Addendum governs Sub-processors.

## 2. Material Sub-processors

| Provider legal name | Service | Data / purpose | Processing region | Transfer safeguard | Status / notice date |
|---|---|---|---|---|---|
| OVH Ltd | Dedicated application, database and private file hosting | Account, product, evidence and service data | United Kingdom | OVH contract and applicable UK transfer terms | Active; verified 24 July 2026 |
| Microsoft Ireland Operations Limited / Microsoft 365 service | Transactional email | Name, email and message metadata | Microsoft 365 tenant region | Microsoft data-protection terms for the tenant | Active SMTP configuration; mailbox delivery is monitored separately |
| OpenAI, L.L.C. | Customer-requested AI assistance where enabled | Selected text or document extracts | Provider service region | OpenAI data-processing terms for the configured project | Feature enabled only where the workspace entitlement and provider mode allow it |
| Stripe Payments Europe, Limited / applicable Stripe contracting entity | Checkout, payment processing and subscription administration | Billing identity, payment method tokens and subscription events | Stripe service region | Stripe data-protection terms and applicable transfer mechanism | Billing integration; DPP Grid does not receive full card numbers |
| Cloudflare, Inc. | Turnstile abuse prevention for protected forms | Request metadata and challenge signals | Provider service region | Cloudflare data-processing terms | Active on protected forms |
| Ahrefs Pte. Ltd. | Public page performance and search-visibility analytics | Public page interaction and technical request data | Provider service region | Ahrefs privacy and data-processing terms | Active public-page script; not used for customer evidence |

No separate object-storage, error-monitoring, support, e-signature or Registry provider is configured in this release. Managed registration remains a provider-neutral workflow until the customer appoints a signing or Registry route.

## 3. Other important third parties

### Stripe

DPP Grid uses Stripe for secure checkout, payment processing and subscription administration. Stripe receives billing and payment information and acts under its own terms and data-protection role for parts of the payment service. DPP Grid does not receive full card numbers.


### Shopify and other customer-connected platforms

A customer may connect Shopify or another commerce, PIM, ERP, PLM, marketplace or supplier platform. The connected provider is selected by the customer and may act as an independent controller or customer-appointed processor. DPP Grid accesses only the approved scopes through supported delegated authentication.

### European Commission DPP Registry

When the customer activates Registry services, DPP Grid may transmit the approved registration data to the European Commission's DPP Registry. The Commission operates the Registry under Union law and is not treated as a DPP Grid Sub-processor merely because it receives a registration.

### Identity and qualified trust-service providers

The customer or DPP Grid may use an identity, qualified electronic signature or qualified electronic seal provider for Registry verification. The relevant provider's own terms and privacy notice apply. DPP Grid must not claim a provider relationship unless it is actually configured or contracted.

## 4. Changes and customer notice

For customer personal data processed under our DPA, we provide notice before a new material Sub-processor begins processing. Customers may object on reasonable data-protection grounds in accordance with the DPA.

A version history should record:

| Date | Change | Effective date |
|---|---|---|
| 24 July 2026 | Production provider inventory reconciled for the current release | 24 July 2026 |
| 31 July 2026 | Removed internal publication instructions from the visitor-facing text | 31 July 2026 |

## 5. Contact

Questions about providers or transfers: **support@dppgrid.com**, subject “Subprocessor enquiry”.
