This page is not finished and must not be relied on. The following are unresolved:
The contracting entity (Ristmark SIA) is in formation. Its registered name, number and address are placeholders below.
The Auth0 production tenant has not been created. Our only tenant today is a US-region development tenant holding our own test accounts (04-ops/2026-08-21-auth0-setup.md).
Object storage is configured but not deployed: both Fly manifests select it, and neither the production application nor its two access-key values exist on the platform yet. The row above says "not processing yet" on that basis, and it must be re-read the day the first deploy lands.
The storage region of our Migadu mailboxes has not been read out of Migadu's control panel and recorded. Confirm it and state it above before publishing — the Swiss adequacy decision only covers data actually held in Switzerland.
The B2B-only, VAT-number-gated checkout is not built — there is no VAT/tax-id collection anywhere in the codebase. Until it is, the payment row's "VAT/registration number" is what Stripe WILL hold, not what it holds today.
No transfer mechanism is confirmed for Fly.io, Neon or Okta (Auth0), and the Stripe contracting entity is not settled. Confirm each against the vendor's own agreement, or those rows keep saying "Not confirmed" — which is honest but is not a position to sell from.
No data-processing agreement has been executed with any party on this list. Some are auto-incorporated into vendor terms and need no signature; others need signing. Until that is done the page cannot say each party is engaged under a written agreement, and it does not.
FOUNDER DECISION — the notice channel. This page promises only that it is updated here, because that is the only channel that exists: there is no billing-contact or admin-contact concept anywhere in the codebase (memberships record a role, not a contact type) and nothing sends a change notice to anybody. An earlier draft promised notice "by email to your workspace's admin and billing contacts"; that was removed. Decide whether we build that channel, and who receives it.
FOUNDER DECISION — the notice period. 30 days is the market standard and what a customer's DPA will look for, but it is a contractual commitment on our side that nothing enforces. Confirm 30, choose another number, or decide we make no commitment at all.
FOUNDER DECISION — what objecting to a new sub-processor entitles a customer to. An earlier draft promised termination of the affected subscription plus a refund of the unused prepaid balance. No code path can perform a refund, and the recorded posture is the opposite (_dashboard/decisions/2026-08-11-closeout-decisions.md: cancel at period end, "no refund logic needed"). The promise was removed rather than softened. Decide the real answer before publishing.
Which of us is the controller depends on which data you mean, so this page says it per party rather than once at the top.
The documents and template content you put into the service. You are the controller and we are your processor. The parties markedsub-processor below handle that content on our behalf — this is the list your own Article 28 obligations point at.
Your account and sign-in records, your billing identity, and anything you write to our support address. We are the controller of these: we decide why they are held and for how long, because running the account, taking payment and keeping the invoices we issue require it. The parties marked processor below handle those for us.
Authoritative DNS and mail routing; TLS, CDN and static hosting once the sites deploy
Processor to us — we are the controller
Processing now
Purpose
Runs the DNS for our domains and the records that route our mail. When the website and the application are deployed it will also terminate TLS and serve them to your browser, and every request you make to us will arrive through it.
Data it touches
Today: the DNS queries resolvers make for our domains — no visitor reaches a page, because no page is deployed. Once the sites are live it also sees connection metadata for every visitor: IP address, user agent, requested URL. No document content reaches it by this route; the object store below is the route that does.
Location
Global. Requests are served from whichever Cloudflare location is nearest, which may be outside the EU. We do not have Cloudflare's Data Localization Suite — the paid add-on that would confine TLS termination and edge metadata to the EU — so edge processing is not confined to the EU, and we do not claim that it is. Both zones were on the Free Website plan when last measured, 2026-08-20.
Our relationship
We are the controller of the connection metadata a visit to our site produces, and this is our processor for it. This row covers the edge only; the object storage below is a separate relationship with the same company and is a sub-processor of your content.
Transfer basis
Standard Contractual Clauses — A US company. Its data-processing addendum is baked into the self-serve subscription agreement — so it applies to our account without a separate signature — and incorporates the EU Standard Contractual Clauses. Read 2026-08-17.
Cloudflare, Inc.
R2 — object storage for uploaded documents and generated output
Sub-processor — you are the controller
Chosen and configured — not processing yet
Purpose
Holds the bytes: every source document you upload, the page images it is rasterized into, every image extracted from it, and every document the service generates for you. This is where your content lives at rest.
Data it touches
The full content of every document you put into the service or generate from it, including any personal data inside those documents. It is the widest data exposure on this list.
Location
European Union. Both buckets were created under Cloudflare's `eu` jurisdiction — a setting fixed at creation and not changeable afterwards, which holds stored objects and their metadata in the EU. That guarantee is about data at rest in these buckets and does not extend to the edge row above.
Status
Chosen, provisioned and wired, and holding nothing: the buckets were created on 2026-08-19, both Fly manifests were pointed at them on 2026-08-24, and the adapter was round-tripped against the real buckets the same day. What has not happened is a deploy — the production api app does not exist yet, the two access-key values have not been staged onto it, and no customer has ever uploaded a document. It starts processing on the first upload after launch, not before.
Our relationship
Sub-processor for your document content — you are the controller of what is in those documents and we are your processor. None of your account, billing or support data is stored here.
Transfer basis
Standard Contractual Clauses — The same company and the same addendum as the edge row above: auto-incorporated into the self-serve subscription agreement and carrying the EU Standard Contractual Clauses. Read 2026-08-17. Note that the Clauses are what covers a transfer; the `eu` jurisdiction setting is a separate, stronger control that keeps these objects in the EU in the first place.
Fly.io, Inc.
Fly Machines — application and document-conversion compute
Both — see below
Chosen and configured — not processing yet
Purpose
Runs the API and the document converter. Every document you migrate, edit or generate passes through this compute.
Data it touches
Document content in transit and in memory, account identifiers, request metadata, and application logs.
Location
Frankfurt, Germany (Fly region fra). Fly.io, Inc. is a US company.
Status
Chosen and written into a deployment manifest, and running nothing of yours: the production application does not exist as a Fly app at all. Measured 2026-08-22 — the account holds only two staging machines, both suspended. Nothing you send us has ever run here.
Our relationship
Both, on one machine. Your document content passes through it as our sub-processor; our own account, usage and log records pass through it as our processor.
Transfer basis
Not confirmed — Compute is pinned to Frankfurt, but the contracting entity is American and no transfer mechanism has been confirmed for our account. Research read 2026-08-17 records that Fly.io self-certifies under the EU-US Data Privacy Framework and that no Standard-Contractual-Clauses fallback was found in its published terms. We do not rely on the Framework — see the note below the list — so this is the mechanism we are least able to state, and it is listed as unresolved.
Neon, Inc.
Managed PostgreSQL
Both — see below
Chosen and configured — not processing yet
Purpose
The application database — accounts, workspaces, templates, jobs and usage records.
Data it touches
Your email address, the opaque identifier your identity provider issues for you, your workspace membership and role, template content and structure, job history, and usage counters.
Location
AWS eu-central-1 (Frankfurt, Germany). Neon, Inc. is a US company.
Status
Chosen and provisioned, holding no customer data: no customer account has ever been created, because the service has not launched. The database exists and the schema is deployed to it; the rows described above are the ones it will hold, not ones it holds.
Our relationship
Both, in one database. Template content and structure sit there as our sub-processor; account, membership and usage records sit there as our processor.
Transfer basis
Not confirmed — The bytes are in Frankfurt, but the contracting entity is American. A data-processing agreement is published for signature and research read 2026-08-17 records a vendor claim of Standard Contractual Clauses for cross-border transfer — we have neither read that agreement nor executed it, so the mechanism is unresolved.
Amazon Web Services, Inc.
AWS infrastructure underlying the managed database — engaged by Neon, Inc., not by us
Both — see below
Chosen and configured — not processing yet
Purpose
Our database provider runs on AWS. AWS supplies the compute and storage the database sits on; it is not engaged by us directly for this purpose.
Data it touches
Everything in the database, at rest on AWS storage.
Location
AWS eu-central-1 (Frankfurt, Germany).
Status
Follows the database above exactly: the storage is provisioned and holds no customer data, because no customer account exists yet.
Our relationship
Both, and one level down: it holds the same two classes the database above does, under a contract our database provider holds rather than one we hold.
Transfer basis
Standard Contractual Clauses — The AWS data-processing addendum is incorporated automatically into the AWS Service Terms with no separate signature and carries the June-2021 EU Standard Contractual Clauses, applying whenever AWS moves data outside the EEA. Read 2026-08-17.
Amazon Web Services, Inc.
Amazon SES — transactional email
Processor to us — we are the controller
Chosen and configured — not processing yet
Purpose
Sends the transactional messages the service depends on: welcome, usage-cap warnings, payment failures, and workspace-deletion notices.
Data it touches
Recipient email address, and the content of the message — which names your workspace and, for usage and billing messages, your plan and usage figures.
Location
AWS eu-north-1 (Stockholm, Sweden), recorded 2026-08-18. Amazon Web Services, Inc. is a US company.
Status
Set up and unable to reach you. Measured 2026-08-24: our sending domain is verified and sending is enabled, but the account is still in the provider's sandbox — production access has not been granted, so it will only deliver to addresses we have verified ourselves, at 200 messages a day. The production deployment does not select an email provider at all; it is listed there as a known blocker rather than configured. No message has ever gone to a customer.
Our relationship
We decide what transactional mail goes out and why, so we are the controller of it and this is our processor. This is a direct relationship with AWS, separate from and additional to the one underneath our database provider above.
Transfer basis
Standard Contractual Clauses — The same AWS addendum as the row above: auto-incorporated into the AWS Service Terms, carrying the June-2021 EU Standard Contractual Clauses. Read 2026-08-17.
Anthropic PBC
Claude API
Sub-processor — you are the controller
Chosen and configured — not processing yet
Purpose
The AI half of template migration: reading a document's pages and proposing which text is a variable field, naming those fields, and explaining proposed merges. Deterministic parsing, layout and generation do not use it.
Data it touches
The full visual content of documents you migrate. Pages are rasterized to images and sent to the model, so anything printed on the page reaches it — including any personal data inside the document itself.
Location
United States.
Status
Chosen and built against, with no key: both production manifests select this backend, and the credential it needs is held by nobody, so a deployment would refuse the work rather than do it. Development and evaluation run against a personal subscription on the founder's own machine, never against a customer's document.
Our relationship
Sub-processor only, and the narrowest scope on this list: it sees the pages of documents you migrate and nothing else. No account record, billing detail or correspondence reaches it.
Transfer basis
Standard Contractual Clauses — Its data-processing addendum makes it the processor and carries the EU Standard Contractual Clauses, Modules Two and Three, with a UK addendum. The addendum does not reference the EU-US Data Privacy Framework, and neither do we. Read 2026-08-11.
Okta, Inc. (Auth0)
Auth0 — identity and sign-in
Processor to us — we are the controller
Chosen and configured — not processing yet
Purpose
Authenticates users and issues the tokens the application and API rely on.
Data it touches
Email address, the identifier the identity service issues for a user, and sign-in events including IP address and timestamp. Today the only accounts in it are our own test accounts — no customer has ever signed in against it.
Location
United States. Okta, Inc. is a US company and our only tenant is in its US-5 region, measured 2026-08-21. The EU tenant that will hold real customer identities does not exist yet.
Status
Chosen and wired, holding no customer identity: the only tenant that exists is a US-region development one containing our own test accounts, measured 2026-08-21. The EU production tenant that will hold real identities has not been created, and no customer has ever signed in.
Our relationship
We are the controller of the sign-in records for the people who use your workspace, and this is our processor for them. No document content reaches it.
Transfer basis
Not confirmed — A US company holding identity records in a US region, and no transfer mechanism has been confirmed against its agreement. Unresolved, and it must be settled before the EU production tenant holds a single real identity.
Stripe, Inc. / Stripe Payments Europe, Ltd.
Stripe Checkout, Billing and the customer portal
Processor to us — we are the controller
Chosen and configured — not processing yet
Purpose
Takes payment, hosts the checkout and the self-service billing portal, and issues invoices.
Data it touches
Billing name and email address, business address, VAT/registration number, and payment-instrument details. Card numbers are entered on its own pages and never reach us. None of it is held yet: no live account exists, so nothing has been charged and nothing has been billed.
Location
European Union and United States. Which of those our account sits in is not settled, because the account is not yet opened — see the transfer basis below.
Status
Chosen and integrated, with no account: nothing has been charged, no invoice has been issued and no billing identity is held, because the account cannot be opened until the contracting company is registered. The checkout and portal described above are built and unreachable.
Our relationship
We are the controller of your billing identity: we decide why it is held and for how long, because we — not you — are the party that has to issue the invoice and keep it. This is our processor for that data. Your document content never reaches it.
Transfer basis
Not confirmed — Which entity we contract with is not settled: the account is not yet opened in the SIA's name. Research read 2026-08-05 records that the European entity is Irish, which would raise no transfer question, while the US entity would. Unresolved until the account exists.
Migadu Email Ltd.
Hosted mailboxes for our support and billing addresses
Processor to us — we are the controller
Processing now
Purpose
Receives mail sent to us — support requests, and replies to any transactional message. Anything you write to us is stored in one of its mailboxes.
Data it touches
Your email address and whatever the correspondence itself contains, including any attachment you send us.
Location
Migadu Email Ltd. is a Swiss company; mailboxes recorded active on 2026-08-18. The storage region of those mailboxes is not recorded anywhere in this repository, so it is listed as unresolved below rather than guessed at here.
Our relationship
We are the controller of correspondence you send us, and this holds the mailbox on our behalf. A document you attach to a support email lands here under this relationship, not as part of the service — which is a reason to send us a description rather than the document itself.
Transfer basis
Adequacy decision (Switzerland) — conditional — Switzerland has its own European Commission adequacy decision, so a transfer there needs no additional mechanism. That holds only for data actually held in Switzerland, and we have not confirmed where these mailboxes are stored, so it is unresolved. Research read 2026-08-17.
Transfers out of the EEA
Most of these parties are US companies, so most rows describe a transfer out of the EEA. Where we can state a mechanism it is the Standard Contractual Clauses, never the EU-US Data Privacy Framework: the Framework has been struck down twice before on the same ground — that US oversight of it is not independent enough for EU purposes — and as of the research read on 2026-08-17 it faces a live challenge on that same theory again. A list resting on it would be describing a mechanism that may not exist by the time you rely on it. Where the mechanism is not confirmed, the row says "Not confirmed" and the item appears in the unresolved list above; none of those is settled by publishing this page.
Categories with nobody in them
Stated because an absence is not visible on a list of what we do use, and because each of these is a category a buyer would otherwise have to ask about. Two different things are listed together here and the difference is marked: a category we have decided to stay out of, and one we have decided to enter and have not yet chosen a supplier for. Where the second applies, it says so — and the supplier appears on the list above, with its own row, before it handles anything.
Error tracking / crash reporting
No error-tracking or crash-reporting vendor is engaged, and the code refuses to name one: the only value the setting accepts is "report nothing", so a half-configured vendor cannot look configured. Errors are recorded in our own logs.We have decided we will run one, on the server side only — never in the browser, because a client-side error SDK writes to your users' own browser storage and that reopens a consent question we have deliberately closed. The vendor is not chosen. It appears here, with its own row, before it receives a single report.
Managed log storage
No log-storage vendor is engaged today; application logs stay on our own infrastructure, and the application writes them to its own output rather than shipping them anywhere.We have decided we will replace the self-hosted log store with a managed one in an EU region. The vendor is not chosen, and no log has ever left our infrastructure. It appears here, with its own row, before it holds anything.
Uptime and availability monitoring
No monitoring vendor is engaged. Nothing is watching the service from outside it today, which is a gap in our operations rather than a privacy position, and we would rather say so than leave the category unmentioned.We have decided we will run external uptime checks against the application, the API and this website. Such a service sees a URL and a response code, not your data. The vendor is not chosen, and it appears here before it is engaged.
Hosted secret management
No hosted secret-management vendor is engaged, and that is a settled position rather than an omission: the credentials the service needs are held by the platforms that need them, where they cannot be read back. Assessed and declined 2026-08-19 — a vendor here would be one more third party holding the keys to the others.
Host-specific platform SDKs
We reach the database and object storage over standard, portable protocols rather than a host's own SDK, so the hosts listed above can be replaced without rewriting the product — a rule we wrote down on 2026-08-20 rather than left to habit. The hosts themselves are listed above on their own merits.
Web or product analytics
No analytics or product-telemetry vendor is engaged, in the browser or anywhere else, and none is planned. There is no tracking script on this site and no cookie banner, because there is nothing to consent to.
GitHub — source hosting and CI
Source-code hosting and our build pipeline. No customer data is stored in the repository or made available to a build, so it processes nothing of yours.
Ubicloud — CI runners
The machines that compile and test the product, chosen 2026-08-18. They run against fixed test files and have no access to production systems or customer data.
Porkbun — domain registrar
Our domain registrar, recorded 2026-08-18. It holds our own registration details and nothing belonging to a customer; the names themselves resolve through the edge provider listed above, not through it.
How this list changes
At least 30 days before a new sub-processor begins processing your data, it is added to this page and the date at the top changes. That is a commitment about this page, which is the one we can keep without asking anything of you: there is nothing to subscribe to and nothing you have to configure.
If you object to an addition, write tosupport@ristmark.app and a human will read it.
One exception, stated plainly rather than buried: where a sub-processor must be replaced urgently to keep the service running or to close a security problem, we make the change first and tell you as soon as we reasonably can. A notice period we would predictably break in an outage is worse than an honest one.
We remain responsible to you for what these parties do with your data.
Publisher
[UNRESOLVED — Ristmark SIA is in formation; no registered entity yet]Registration number: [UNRESOLVED — no registration number exists yet][UNRESOLVED — no registered office yet]Trading as Ristmark. Contact:support@ristmark.app