Sub-processors
Wrendex engages the following sub-processors to deliver the Service. Each entry lists the processing purpose, the type of data the sub-processor sees, and the region where the data is processed. We notify customers thirty days before adding a new sub-processor.
Active sub-processors
Stripe, Inc.
- Purpose: subscription billing, payment processing.
- Data accessed: billing contact name + email, payment method, billing address.
- Region: United States.
- Reference: stripe.com/privacy
Hetzner Online GmbH
- Purpose: cloud hosting and compute for our production servers, including the self-managed database cluster that stores crawl results, audit metadata, and account data. Every server uses full disk encryption.
- Data accessed: all customer data at rest in our production database and logs.
- Region: Hetzner EU (Helsinki, Finland).
- Reference: hetzner.com/legal/privacy-policy
Wasabi Technologies, Inc.
- Purpose: object storage for crawl archives and customer exports.
- Data accessed: stored crawl archive files and export files customers generate.
- Region: EU.
- Reference: wasabi.com/privacy-policy
Mailgun (Sinch)
- Purpose: transactional email delivery (audit alerts, password resets, billing receipts).
- Data accessed: recipient email address, the body of the email being sent.
- Region: EU.
- Reference: mailgun.com/privacy-policy
Optional, customer-configured
The following are integrations the customer chooses to enable. Wrendex acts as a data exporter only when configured.
- Slack: alert delivery to the customer’s Slack workspace; data exposed is the alert body the customer composed.
- Microsoft Teams: alert delivery via incoming webhook; data exposed is the alert body the customer composed.
- PagerDuty: severity-mapped paging; data exposed is the alert title and severity.
- Customer-provided webhooks: outbound HTTPS webhooks to URLs the customer configures.
Notifications & objections
We notify customers of new sub-processors at least thirty days in advance. Customers with reasonable grounds for objection may raise them via /contact. If we cannot satisfy the objection, the customer may terminate the affected service.