> Every subprocessor Runsite uses, named, with its legal entity, jurisdiction and transfer basis. Plus where your data is processed and how to get a signed GDPR Data Processing Agreement.

# Compliance

Last updated September 13, 2026

Plenty of platforms describe their subprocessors by category and leave you to guess which companies are behind the words. This page names them and marks the two that sit outside the EEA. If you are running a vendor review and something you need is missing, ask and we will add it.

## Where your data is processed

Application containers, environment variables, build artifacts, managed PostgreSQL and its WAL archive, Redis instances, object storage, backups and logs all run on Hetzner infrastructure in Germany. Nothing replicates to a non-EU region and nothing falls back to overseas infrastructure. Account email leaves through Sweego in France.

Public assets from static sites and public buckets are cached on Cloudflare's edge network so a visitor in Sydney is served from nearby. That cache holds public files. Your database contents, private objects and logs never reach it.

## Subprocessors

Every third party that touches customer data, with the legal entity you would actually be relying on:

| Subprocessor | What it does                                                             | Legal entity                                                 | Data location                                          | Transfer basis                               |
| ------------ | ------------------------------------------------------------------------ | ------------------------------------------------------------ | ------------------------------------------------------ | -------------------------------------------- |
| Hetzner      | Compute, managed PostgreSQL and Redis, object storage, backups, logs     | Hetzner Online GmbH — Gunzenhausen, Germany                  | Germany                                                | Inside the EEA, no transfer mechanism needed |
| Sweego       | Transactional and account email delivery                                 | Mindbaz SAS — Lille, France                                  | France                                                 | Inside the EEA, no transfer mechanism needed |
| Cloudflare   | DNS, TLS termination, and edge caching of public assets and static sites | Cloudflare, Inc. — San Francisco, United States              | Global edge network                                    | Standard Contractual Clauses                 |
| Creem        | Payments, invoicing and VAT, acting as Merchant of Record                | Armitage Labs OÜ (registry code 16977866) — Tallinn, Estonia | EEA, with onward transfers including the United States | Standard Contractual Clauses                 |

Two of the four are worth reading twice. Cloudflare is a US company, which means US law reaches it whatever the edge node's postcode says; it holds public assets only. Creem is Estonian, but its own DPA lists onward transfers to the United States, so the payment and invoicing layer is not EEA-only in the way the infrastructure is. Both are covered by Standard Contractual Clauses.

## Data Processing Agreement

Under GDPR you are the controller for personal data your application handles, and Runsite is the processor. Article 28 requires that relationship to be written down. Write to [support@runsite.app](mailto:support@runsite.app) and you get a signed DPA. Every plan includes it, the free one included. Here is how each obligation is actually met:

| Article  | Obligation                                    | How it is met                                                                                                                                            |
| -------- | --------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------- |
| 28(3)(a) | Process only on documented instructions       | We process customer content only to run the services you have enabled. We do not read it, mine it, or train anything on it.                              |
| 28(3)(b) | Confidentiality of personnel                  | One person operates the platform, under the confidentiality terms of the DPA itself.                                                                     |
| 28(3)(c) | Article 32 security measures                  | Encryption in transit with TLS and at rest with AES-256, isolated per-tenant containers and databases, and access to production limited to the operator. |
| 28(3)(d) | Conditions for engaging subprocessors         | The list on this page is the complete set. Each is bound by its own DPA, and we give notice here before adding one.                                      |
| 28(3)(e) | Assistance with data subject rights           | Export and deletion run from the dashboard. Anything the dashboard cannot do, write to us and we will do it.                                             |
| 28(3)(f) | Assistance with Articles 32 to 36             | We notify you without undue delay of a breach affecting your data, with what we know at the time rather than after an investigation completes.           |
| 28(3)(g) | Deletion or return at the end of the contract | Delete a service and its data and backups are removed within 30 days. Ask for an export first and you get one.                                           |
| 28(3)(h) | Information and audits                        | This page, the DPA, and answers to whatever your security review asks.                                                                                   |

## Who operates Runsite

Runsite is not a registered company. It is operated by an individual developer resident in the EU, which is worth stating plainly because it is the one column where Runsite answers differently from Scalingo SAS or Clever Cloud SAS. If your procurement process needs a company registration number in an EU member state, one of those is the better answer and we would rather you find that out now.

What it does mean is that no US parent company sits above the platform, so there is no entity in the structure that the CLOUD Act can reach. There is also no SOC 2 report and no ISO 27001 certificate. Those cost more than a one-person platform in beta can justify, and claiming an equivalent would be worse than saying so.

## Questions a security review usually asks

Where is my data processed?

Compute, databases, cache, object storage, backups and logs run on Hetzner infrastructure in Germany. Email is delivered by Sweego in France. Both are inside the EEA, so no transfer mechanism applies to them.

Does Runsite use any non-EU subprocessors?

Two. Cloudflare, a US company, handles DNS, TLS and edge caching of public assets. Creem, an Estonian company, handles payments as Merchant of Record and its own subprocessor list includes onward transfers to the United States. Both are covered by Standard Contractual Clauses. Neither holds your database contents, your object storage, or your application logs.

How do I get a signed Data Processing Agreement?

Write to support@runsite.app and we send a signed DPA. It is included on every plan, the free one included, and there is no upgrade, negotiation or sales call in front of it.

What legal entity am I contracting with?

Runsite is not a registered company. It is operated by an individual developer resident in the EU. If your procurement process requires a company registration number in an EU member state, that is a real limitation and you should weigh it before signing.

## Changes to this list

Adding a subprocessor changes who can touch your data, so this page is updated before the change takes effect rather than after, and the date at the top moves with it. If you want to be told directly instead of watching a page, say so at [support@runsite.app](mailto:support@runsite.app).

---

Source: https://runsite.app/compliance
