Skip to content
← Legal centre

Subprocessors

The named subprocessors we rely on to deliver hosting, payments, email, domains and analytics, where they are located, and how to object to a change.

Version in force · Last updated 6 February 2026

1. Purpose of this page

  • 1.1 This page identifies the subprocessors that Alta Ignite B.V. ("Alta Ignite", "we") engages to process Personal Data on behalf of customers ("Customer", "you") in connection with the design, development, hosting, domain registration and business email Services, and forms part of, and is incorporated by reference into, our Data Processing Agreement under Article 28(2) and Article 28(4) of the GDPR.
  • 1.2 A "subprocessor" is any third party engaged by Alta Ignite that processes Personal Data on our behalf as part of delivering the Services. This page does not list suppliers that do not process Customer Personal Data, such as suppliers used solely for our own corporate administration without access to Customer data.

2. General authorisation and this list

  • 2.1 By accepting the Data Processing Agreement, the Customer authorises Alta Ignite to engage the subprocessors listed in clause 4, and any future subprocessor added in accordance with clause 5.
  • 2.2 We keep this list current and will update it promptly when a subprocessor is added, replaced or ceases to be used.

3. Due diligence over subprocessors

  • 3.1 Before engaging a subprocessor, Alta Ignite assesses its data protection and security practices, including, where relevant, its certifications (such as ISO/IEC 27001 or SOC 2), its data centre locations, and its own subprocessing chain.
  • 3.2 Every subprocessor is bound by a written agreement imposing data protection obligations that are substantially equivalent to those Alta Ignite owes the Customer under our Data Processing Agreement, including confidentiality, security, breach notification and deletion obligations.
  • 3.3 We periodically re-assess subprocessors and remove or replace any subprocessor that no longer meets our security and compliance requirements.

4. Current subprocessors

  • 4.1 Stripe Payments Europe, Limited — Purpose: payment processing, card storage tokenisation, subscription billing and fraud prevention for checkout and recurring charges. Location: Ireland (EU), with global payment-network processing. Transfer safeguard: Stripe is a data importer under Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) for any transfer outside the EEA and maintains PCI DSS Level 1 certification.
  • 4.2 Cloudflare, Inc. — Purpose: content delivery network, DNS resolution, DDoS mitigation and web application firewall protection for hosted websites. Location: EU edge points of presence with a global anycast network; corporate entity in the United States. Transfer safeguard: Cloudflare's EU-to-non-EU transfers are governed by Standard Contractual Clauses and Cloudflare's participation in the EU-U.S. Data Privacy Framework.
  • 4.3 Hetzner Online GmbH — Purpose: primary web and application hosting infrastructure for Customer websites and databases. Location: Germany (Falkenstein and Nuremberg data centres), European Union. Transfer safeguard: not applicable — data remains within the EU/EEA.
  • 4.4 Supabase, Inc. (operating on AWS eu-central-1) — Purpose: managed PostgreSQL database, authentication and storage services underlying certain Customer websites and applications. Location: AWS Frankfurt region, Germany, European Union. Transfer safeguard: EU data residency for the eu-central-1 region; any incidental transfer to Supabase's U.S. corporate entity for support purposes is governed by Standard Contractual Clauses.
  • 4.5 Transactional mail delivery provider (Fastmail/Purelymail-class managed mail platform) — Purpose: hosting of business email mailboxes and delivery of inbound/outbound mail included with each subscription. Location: European Union data centres where available, with failover capacity in other jurisdictions. Transfer safeguard: Standard Contractual Clauses apply to any transfer outside the EEA; mailbox content is encrypted at rest and in transit.
  • 4.6 Resend, Inc. — Purpose: delivery of transactional and system emails, such as order confirmations, password resets and billing receipts, sent by the Platform. Location: United States, with EU-region sending infrastructure. Transfer safeguard: Standard Contractual Clauses and, where applicable, EU-U.S. Data Privacy Framework self-certification.
  • 4.7 Functional Software, Inc. (Sentry) — Purpose: application error monitoring and diagnostic logging to detect and remediate software defects affecting the Services. Location: United States, with an EU data-residency option enabled for our account. Transfer safeguard: Standard Contractual Clauses and EU-U.S. Data Privacy Framework self-certification; error events are configured to minimise inclusion of Personal Data.
  • 4.8 Plausible Insights OÜ (Plausible Analytics) — Purpose: privacy-preserving, cookie-less website analytics used to measure aggregate traffic and conversion trends. Location: European Union (Germany/Estonia hosted infrastructure). Transfer safeguard: not applicable — EU-hosted with no cross-border transfer and no use of cookies or persistent identifiers by default.
  • 4.9 OpenProvider B.V. — Purpose: ICANN-accredited domain name registration, renewal, DNS management and WHOIS/RDDS compliance for domains included with or purchased through a subscription. Location: Netherlands, European Union. Transfer safeguard: not applicable within the EEA; where WHOIS/RDDS publication is mandated by ICANN policy, only the minimum data required by the ICANN Registrar Accreditation Agreement and applicable Temporary Specification is disclosed.
  • 4.10 Google Ireland Limited (Google Workspace) — Purpose: internal business operations, including staff email, calendaring, document storage and support-ticket collaboration, which may incidentally involve Customer Personal Data shared with our support team. Location: European Union (Google's EU data regions, where configured), Google's global network for service delivery. Transfer safeguard: Google Workspace's Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework, as set out in Google's data processing terms.

5. Notification of new or replacement subprocessors

  • 5.1 We will update this page and, for Customers who have subscribed to subprocessor update notices via their account settings, send an email at least 14 days before a new subprocessor begins processing Customer Personal Data, or before an existing subprocessor is replaced.
  • 5.2 In an emergency requiring an immediate change to preserve the security, availability or integrity of the Services, we may engage a replacement subprocessor with shorter or contemporaneous notice, and will confirm the change on this page and by email as soon as reasonably practicable afterwards.

6. Right to object

  • 6.1 A Customer may object to our engagement of a new subprocessor on reasonable data protection grounds by emailing privacy@altaignite.com within 14 days of the notice described in clause 5.1, explaining the specific grounds for objection.
  • 6.2 On receipt of a timely objection, we will work in good faith with the Customer to address the concern, which may include providing additional information about the subprocessor's safeguards or, where feasible, offering an alternative configuration that avoids the new subprocessor.
  • 6.3 If the parties are unable to reach a mutually acceptable resolution within 30 days of the objection, the Customer's sole and exclusive remedy is to terminate the affected subscription by written notice to legal@altaignite.com, without early-termination penalty, effective from the date the new subprocessor would otherwise begin processing the Customer's Personal Data.

7. Onward subprocessing

  • 7.1 Several subprocessors listed in clause 4 may themselves engage further subprocessors (for example, a cloud infrastructure provider underlying a SaaS supplier). We require our subprocessors to impose data protection obligations on any onward subprocessor that are substantially equivalent to those imposed on them.
  • 7.2 Details of significant onward subprocessing chains are available on request from privacy@altaignite.com.

8. Relationship to the Data Processing Agreement

  • 8.1 This Subprocessors page is incorporated by reference into our Data Processing Agreement and should be read together with it, in particular clause 8 of that agreement (subprocessing).
  • 8.2 In the event of any conflict between this page and the Data Processing Agreement regarding the process for adding or objecting to a subprocessor, the Data Processing Agreement prevails.

9. Contact

  • 9.1 Questions about our subprocessors, requests for onward-subprocessing detail, or objections under clause 6, should be sent to privacy@altaignite.com, with a copy to legal@altaignite.com, or by post to Alta Ignite B.V., Keizersgracht 391, 1016 EJ Amsterdam, the Netherlands, KvK 76392014, VAT NL860627193B01.

Subprocessor questions and objections: privacy@altaignite.com — Alta Ignite B.V., Keizersgracht 391, 1016 EJ Amsterdam, the Netherlands.