1. How We Classify Providers
A sub-processor handles Customer Personal Data for Secretus when Secretus itself acts as processor for a business customer. Other providers may process account-holder data for Secretus as controller, or act as independent controllers for their own identity, payment, fraud, tax, or legal purposes. We show those distinctions instead of labelling every provider a sub-processor.
- Encrypted payloads are still in scope
- In Standard mode, ciphertext is stored in AWS even though the fragment decryption key and plaintext do not reach Secretus or AWS. Ciphertext may remain personal data under GDPR. In P2P mode the payload is not stored by Secretus, and Team Split shares are not uploaded through the Team Split workflow.
- Business-customer notice
- Customers with a signed DPA receive addition or replacement notices and objection rights under that DPA. The public version history on this page is the operational provider register.
2. Customer-DPA Sub-processor
- Amazon Web Services EMEA SARL and authorised AWS affiliates
- Purpose: core hosting, S3 ciphertext storage, DynamoDB account/metadata/audit storage, Cognito authentication, compute, networking and TURN relay, queues, logs, monitoring, and security. Data: encrypted Standard-mode payloads plus account, authentication, network, audit, and operational metadata relevant to the selected feature. Primary region: Frankfurt, Germany (eu-central-1), with limited provider support/security access as described by AWS. Safeguards: AWS Data Processing Addendum, EU-region configuration, and applicable adequacy or Standard Contractual Clause mechanisms for restricted transfers.
3. Independent Controllers and User-Chosen Services
- Google — optional sign-in identity provider
- If a user chooses Continue with Google, Google processes identity and security data under its own terms and may act as independent controller. AWS Cognito receives the identity attributes needed to authenticate the Secretus account. Email/password sign-in is available as an alternative. Provider: Google Ireland Limited and relevant Google affiliates; processing may involve transfers outside the EEA under Google's stated safeguards.
- Stripe and Link — checkout and merchant of record
- Stripe hosts checkout. Through Stripe Managed Payments, Link (Sold through Link, LLC) acts as merchant of record for payment collection, fraud prevention, transaction tax, receipts/invoices, and payment support under its own terms and controller responsibilities. Card and bank details do not reach Secretus. Secretus receives only limited subscription, customer-reference, period, and entitlement data needed to supply the plan.
4. Providers Used for Secretus's Own Controller Purposes
These providers support the public website and Secretus's direct relationship with visitors or account holders. They are not authorised to receive plaintext secret content and are not listed as Customer-DPA sub-processors for encrypted customer payloads.
- Cybot A/S / Cookiebot — consent management
- Purpose: display the consent interface, store consent choices, and help demonstrate those choices. Location: Denmark/EEA, subject to Cybot's provider terms and disclosed hosting/subcontracting arrangements. Cookiebot loads before optional analytics so the choice can be applied.
- Google Analytics — consented public-site analytics
- Purpose: optional aggregate website analytics after statistics consent. Provider: Google Ireland Limited and relevant affiliates. It is disabled on withdrawal and is not used on authenticated secret-sharing routes under the stricter third-party policy. Any restricted transfer relies on Google's applicable safeguards.
5. Safeguards, Changes, and Requests
- Contracts and transfers
- We use GDPR Article 28 terms for processors and sub-processors. A provider acting as independent controller remains responsible for its own transparency and lawful bases. For restricted transfers we use an adequacy decision, the European Commission transfer SCCs, supplementary measures, or another lawful mechanism as applicable.
- Provider changes
- We update this page when a provider or role materially changes. Security or continuity emergencies may require shorter notice, followed by an explanation where legally permitted. Contractual DPA notice rights continue to apply.
- DPA and transfer information
- Business customers may request a signed DPA or information about a relevant transfer safeguard at legal@secretus.app. Confidential provider terms may be supplied only in summary or redacted form.
MUNTEANU C. D. MIHAI PERSOANĂ FIZICĂ AUTORIZATĂ
ONRC F2026008193001 · CUI 53962936
București, Sector 1, Bulevardul Bucureștii Noi, Nr. 136, Cod poștal 012366, România
Telephone: +40 750 487 485
DPA and privacy requests: legal@secretus.app