Secretus legal center
Providers & Sub-processors
The third parties used to operate Secretus, what they receive and where their processing takes place.
This register identifies who supports Secretus, what they process, and whether their role is sub-processor, service provider for our controller activity, or independent controller. AWS can receive encrypted ciphertext in Standard mode; none of these providers receives the URL-fragment decryption key from Secretus.
1. How We Classify Providers
A sub-processor handles Customer Personal Data for Secretus when Secretus itself acts as processor for a business customer. Other providers may process account-holder data for Secretus as controller, or act as independent controllers for their own identity, payment, fraud, tax, or legal purposes. We show those distinctions instead of labelling every provider a sub-processor.
- Encrypted payloads are still in scope
- In Standard mode, ciphertext is stored in AWS even though the fragment decryption key and plaintext do not reach Secretus or AWS. Ciphertext may remain personal data under GDPR. In P2P mode the payload is not stored by Secretus, and Team Split shares are not uploaded through the Team Split workflow.
- Business-customer notice
- Business customers covered by the standard or signed DPA receive addition or replacement notices and objection rights under that DPA. The public version history on this page is the operational provider register.
2. Customer-DPA Sub-processor
- Amazon Web Services EMEA SARL and authorised AWS affiliates
- Purpose: core hosting, S3 ciphertext storage, DynamoDB account/metadata/audit storage, Cognito authentication, Amazon SES transactional email, compute, networking and TURN relay, queues, logs, monitoring, and security. Data: encrypted Standard-mode payloads plus account, authentication, network, audit, and operational metadata relevant to the selected feature. SES additionally receives the recipient email address, transactional message type, delivery metadata, and, where needed, a time-limited Cognito verification code or temporary password, or the optional display name and trial-end date. AWS does not receive Secretus plaintext secret content or URL-fragment decryption keys through the email flow. Primary application and SES region: Frankfurt, Germany (eu-central-1), with limited provider support/security access as described by AWS. Safeguards: AWS Data Processing Addendum, EU-region configuration, and applicable adequacy or Standard Contractual Clause mechanisms for restricted transfers.
3. Independent Controllers and User-Chosen Services
- Google — optional sign-in identity provider
- If a user chooses Continue with Google, Google processes identity and security data under its own terms and may act as independent controller. AWS Cognito receives the identity attributes needed to authenticate the Secretus account. Email/password sign-in is available as an alternative. Provider: Google Ireland Limited and relevant Google affiliates; processing may involve transfers outside the EEA under Google's stated safeguards.
- Stripe and Link — checkout and merchant of record
- Stripe hosts checkout. Through Stripe Managed Payments, Link (Sold through Link, LLC) acts as merchant of record for payment collection, fraud prevention, transaction tax, receipts/invoices, and payment support under its own terms and controller responsibilities. Card and bank details do not reach Secretus. Secretus receives only limited subscription, customer-reference, period, and entitlement data needed to supply the plan.
4. Providers Used for Secretus's Own Controller Purposes
These providers support the public website and Secretus's direct relationship with visitors or account holders. They are not authorised to receive plaintext secret content and are not listed as Customer-DPA sub-processors for encrypted customer payloads.
- Google Analytics — consented public-site analytics
- Purpose: optional aggregate website analytics after analytics consent. Provider: Google Ireland Limited and relevant affiliates. It is disabled on withdrawal and is not used on secret, authentication, or account routes under the stricter third-party policy. Any restricted transfer relies on Google's applicable safeguards. The consent interface is self-hosted by Secretus and is not a third-party provider.
5. Safeguards, Changes, and Requests
- Contracts and transfers
- We use GDPR Article 28 terms for processors and sub-processors. A provider acting as independent controller remains responsible for its own transparency and lawful bases. For restricted transfers we use an adequacy decision, the European Commission transfer SCCs, supplementary measures, or another lawful mechanism as applicable.
- Provider changes
- We update this page when a provider or role materially changes. Security or continuity emergencies may require shorter notice, followed by an explanation where legally permitted. Contractual DPA notice rights continue to apply.
- DPA and transfer information
- The standard DPA is available at https://secretus.app/dpa. Business customers may request a signed or negotiated DPA, or information about a relevant transfer safeguard, at legal@secretus.app. Confidential provider terms may be supplied only in summary or redacted form.
See our Privacy Policy for the full processing notice and our Terms of Service for contractual rules.
Data Protection Contact
MUNTEANU C. D. MIHAI PERSOANĂ FIZICĂ AUTORIZATĂ
ONRC F2026008193001 · CUI 53962936 · EU VAT (VIES) RO54197611
București, Sector 1, Bulevardul Bucureștii Noi, Nr. 136, Cod poștal 012366, România
WhatsApp: Contact us on WhatsApp
DPA and privacy requests: legal@secretus.app
