Sub-processors
Itnetic Technologies
Last updated: 13 August 2026
This is the authoritative list of the sub-processors Itnetic engages. It is referenced by Annex A of the Privacy Policy and Annex III of the Data Processing Addendum, and the three are kept identical.
Under the DPA, customers receive at least 30 days' notice before we add or replace a sub-processor, and may object on reasonable data-protection grounds.
1. Current sub-processors
| Sub-processor | Role | Touches End-User traffic data? | Location | Transfer mechanism |
|---|---|---|---|---|
| Linode, LLC (Akamai Technologies, Inc.) | Servers running the Toronto and Singapore points of presence, and the control plane | Yes | Company established in the US; processing at Toronto, Canada and Singapore | Canada: adequacy decision 2002/2/EC. Singapore: SCCs |
| Datalix (sole trader, Florian Kolb, Estenfeld) | Servers running the Frankfurt point of presence | Yes | EU (Germany) | N/A — EU |
| X4B | Upstream volumetric (L3/L4) DDoS mitigation in front of the Frankfurt point of presence | Yes | Provider established in Australia (Victoria) | SCCs |
| Railway Corp. | Hosting for the dashboard, the marketing website and our self-hosted analytics instance | No — customer-account data only | Data stored in the EU region; provider is US-incorporated | SCCs |
| Stripe Payments Europe, Ltd. | Payment processing, billing, payment fraud prevention | No — customer-account and billing data only | EU / USA | SCCs |
| MailerSend, Inc. | Account, verification, support and alert email | No — customer-account data only | USA (New York) | EU–U.S. Data Privacy Framework; SCCs under their DPA |
| Cloudflare, Inc. | Turnstile bot check on Itnetic's own sign-in and sign-up forms | No — customer-account data only | USA | SCCs |
Three sub-processors touch end-user traffic: Datalix, Linode (Akamai) and X4B. Traffic served from Frankfurt is processed inside the EU. Traffic served from Toronto is processed in Canada under the European Commission's adequacy decision; traffic served from Singapore is processed there under SCCs. The upstream mitigation layer in front of Frankfurt is operated by a provider established in Australia, also under SCCs.
2. Deliberately not sub-processors
| Party | Why not |
|---|---|
| Umami (analytics) | Self-hosted by Itnetic at a.itnetic.com on Railway's EU region. No analytics vendor receives any data. |
| DB-IP (IP geolocation) | We download the free "lite" databases monthly and query them on our own servers. No visitor data is ever sent to DB-IP. |
| Discord, Inc. | Only reachable if you enable a Discord webhook for attack alerts and supply the URL. That is a transfer you direct to a recipient you chose — see DPA Section 6. Alert payloads contain the hostname and aggregate traffic counts, never visitor IP addresses. |
| Your alert email address | Same reasoning: you choose the destination. |
| Your origin, your DNS provider, your object storage | Your own infrastructure, under your own contracts. |
3. Where data is processed
| Data | Where |
|---|---|
| End-user traffic passing through the edge (IPs, request metadata, security signals) | Frankfurt (EU), Toronto (Canada) or Singapore — whichever point of presence serves the visitor |
| Request logs and analytics rollups | EU only (control-plane database) |
| Customer account, domains, configuration | EU region (Railway) |
| Email delivery | MailerSend (USA, under the EU–U.S. Data Privacy Framework) |
| Billing | Stripe (EU entity; group processing may reach the USA under SCCs) |
| Sign-in bot check | Cloudflare (USA, under SCCs) — only the sign-in page, never a protected site's visitors |
4. Changes and notification
We publish changes on this page. Material changes are notified to customers by email at least 30 days before the new sub-processor begins processing, as required by Section 6 of the DPA.
Questions or objections: chlibekbusiness@gmail.com.