Secretus logoSecretus

Providers & Sub-processors

Last Updated: July 21, 2026

Effective Date: July 21, 2026

This register identifies who supports Secretus, what they process, and whether their role is sub-processor, service provider for our controller activity, or independent controller. AWS can receive encrypted ciphertext in Standard mode; none of these providers receives the URL-fragment decryption key from Secretus.

1. How We Classify Providers

A sub-processor handles Customer Personal Data for Secretus when Secretus itself acts as processor for a business customer. Other providers may process account-holder data for Secretus as controller, or act as independent controllers for their own identity, payment, fraud, tax, or legal purposes. We show those distinctions instead of labelling every provider a sub-processor.

Encrypted payloads are still in scope
In Standard mode, ciphertext is stored in AWS even though the fragment decryption key and plaintext do not reach Secretus or AWS. Ciphertext may remain personal data under GDPR. In P2P mode the payload is not stored by Secretus, and Team Split shares are not uploaded through the Team Split workflow.
Business-customer notice
Customers with a signed DPA receive addition or replacement notices and objection rights under that DPA. The public version history on this page is the operational provider register.

2. Customer-DPA Sub-processor

Amazon Web Services EMEA SARL and authorised AWS affiliates
Purpose: core hosting, S3 ciphertext storage, DynamoDB account/metadata/audit storage, Cognito authentication, compute, networking and TURN relay, queues, logs, monitoring, and security. Data: encrypted Standard-mode payloads plus account, authentication, network, audit, and operational metadata relevant to the selected feature. Primary region: Frankfurt, Germany (eu-central-1), with limited provider support/security access as described by AWS. Safeguards: AWS Data Processing Addendum, EU-region configuration, and applicable adequacy or Standard Contractual Clause mechanisms for restricted transfers.

3. Independent Controllers and User-Chosen Services

Google — optional sign-in identity provider
If a user chooses Continue with Google, Google processes identity and security data under its own terms and may act as independent controller. AWS Cognito receives the identity attributes needed to authenticate the Secretus account. Email/password sign-in is available as an alternative. Provider: Google Ireland Limited and relevant Google affiliates; processing may involve transfers outside the EEA under Google's stated safeguards.
Stripe and Link — checkout and merchant of record
Stripe hosts checkout. Through Stripe Managed Payments, Link (Sold through Link, LLC) acts as merchant of record for payment collection, fraud prevention, transaction tax, receipts/invoices, and payment support under its own terms and controller responsibilities. Card and bank details do not reach Secretus. Secretus receives only limited subscription, customer-reference, period, and entitlement data needed to supply the plan.

4. Providers Used for Secretus's Own Controller Purposes

These providers support the public website and Secretus's direct relationship with visitors or account holders. They are not authorised to receive plaintext secret content and are not listed as Customer-DPA sub-processors for encrypted customer payloads.

Cybot A/S / Cookiebot — consent management
Purpose: display the consent interface, store consent choices, and help demonstrate those choices. Location: Denmark/EEA, subject to Cybot's provider terms and disclosed hosting/subcontracting arrangements. Cookiebot loads before optional analytics so the choice can be applied.
Google Analytics — consented public-site analytics
Purpose: optional aggregate website analytics after statistics consent. Provider: Google Ireland Limited and relevant affiliates. It is disabled on withdrawal and is not used on authenticated secret-sharing routes under the stricter third-party policy. Any restricted transfer relies on Google's applicable safeguards.

5. Safeguards, Changes, and Requests

Contracts and transfers
We use GDPR Article 28 terms for processors and sub-processors. A provider acting as independent controller remains responsible for its own transparency and lawful bases. For restricted transfers we use an adequacy decision, the European Commission transfer SCCs, supplementary measures, or another lawful mechanism as applicable.
Provider changes
We update this page when a provider or role materially changes. Security or continuity emergencies may require shorter notice, followed by an explanation where legally permitted. Contractual DPA notice rights continue to apply.
DPA and transfer information
Business customers may request a signed DPA or information about a relevant transfer safeguard at legal@secretus.app. Confidential provider terms may be supplied only in summary or redacted form.

See our Privacy Policy for the full processing notice and our Terms of Service for contractual rules.

Data Protection Contact

MUNTEANU C. D. MIHAI PERSOANĂ FIZICĂ AUTORIZATĂ

ONRC F2026008193001 · CUI 53962936

București, Sector 1, Bulevardul Bucureștii Noi, Nr. 136, Cod poștal 012366, România

Telephone: +40 750 487 485

DPA and privacy requests: legal@secretus.app