Sub-processors
Last updated 15 August 2026. Contact: info@capsakey.com
Capsakey acts as a processor on behalf of the site owner who installs it. The parties below are our sub-processors under Article 28(2) GDPR: each one is engaged under a written contract with data-protection obligations no less protective than our own.
We give 14 days' notice before adding or replacing a sub-processor. To be told, write to info@capsakey.com and ask to be added to the notice list. A customer who objects to a new sub-processor on reasonable data-protection grounds may terminate without penalty and export their data first.
Current sub-processors
| Sub-processor | What it does for us | What it can see | Where |
|---|---|---|---|
| Cloudflare, Inc. (US) | Object storage (R2), compute (Workers), tenant databases (Durable Objects, D1), DNS and TLS | The files themselves, at rest and in transit; all application data | Buckets created with the EU jurisdiction restriction, so objects are stored in the European Union |
| Resend, Inc. (US) | Sending notification email | The recipient's email address and the notification text. Never a file and never a file name. The owner's own copy does carry the space name — the name the owner gave that client — because its subject has to say which client sent something. A client's copy carries no name at all | The sending domain is configured in Ireland (eu-west-1), so this data does not leave the EU either |
| Wix.com Ltd. (Israel) | The marketplace, billing, and the identity of site members | Not a sub-processor of ours in the strict sense — Wix is the platform the site owner already uses, and holds the member identities we authenticate against | Per Wix's own terms |
Every sub-processor handles this data inside the European Union. Resend's region is fixed per sending domain and was set to Ireland when the domain was added; it is not a runtime setting that can drift. What that does not change is corporate nationality — see below.
The caveat we are not going to bury
Cloudflare is a company incorporated in the United States. Creating a bucket with the EU jurisdiction guarantees that objects are stored in the European Union — it does not change the nationality of the processor, and it does not put the company outside the reach of US law.
For most customers this is the ordinary posture of European SaaS and is covered by the standard contractual clauses in our DPA. For a customer whose policy requires an EU-owned processor, it is not, and we would rather say so here than be asked in a procurement questionnaire.
What no sub-processor ever receives
- We do not index, scan, thumbnail, transcode, or train anything on file contents.
- We use no analytics provider, no session recording, no advertising network, and no third-party script in the portal.
- Notification email contains no file name — and no space name in a client's copy, so the mail provider learns nothing about who a site's clients are from the messages they receive. An owner's copy names the space, because that is the one thing that makes it actionable. So from a client's message the mail provider learns only that something was shared, and with whom; from an owner's, additionally the name that owner gave one of their client spaces.