chartping

Subprocessors

Effective 30 July 2026 · Version 2026-06

A subprocessor is a third party that processes personal data on our behalf — either for our own processing as controller, or further down the chain where we act as a Developer's processor under the Data Processing Agreement. This page is the register: who they are, what each one receives, where it is, and the safeguard the transfer relies on.

It is the same list as the “Who receives your data” section of our Privacy Notice, presented for the people who need it as a register — a Developer's procurement review, a data-protection counterparty, an auditor. If the two ever disagree, the Privacy Notice governs and we will have made a mistake here.

Current subprocessors

  • Hetzner Online GmbH · Germany, with a standby site in Finland

    Our platform: the dedicated servers we rent, and the databases holding all server-side data. The Finnish site takes over if the German one becomes unavailable.

    Receives: All data you hold in Chartping.

    Safeguard: A transfer out of the UK relying on UK adequacy for the EEA — no Article 46 instrument is required. Governed by Hetzner's Article 28 data-processing agreement.

  • Microsoft Azure Key Vault · United Kingdom

    Secrets management only: the keys and credentials the service needs to run.

    Receives: Our own secrets. No account data and no monitoring data.

    Safeguard: No restricted transfer — processed in the United Kingdom.

  • Telnyx · United States

    SMS delivery, phone verification and STOP handling.

    Receives: Your verified phone number and the alert text, which can contain trading information.

    Safeguard: Provider data-processing agreement incorporating the EU SCCs with the UK Addendum.

  • Brevo · European Union

    Transactional and alert email.

    Receives: Your email address and the message content.

    Safeguard: UK-to-EU adequacy — no Article 46 instrument required while adequacy stands.

  • RevenueCat · United States

    Subscription management for app-store billing.

    Receives: An internal user identifier and subscription events.

    Safeguard: Provider data-processing agreement incorporating the EU SCCs with the UK Addendum.

  • Stripe · United States

    Developer-licensing billing.

    Receives: A customer identifier and subscription state. Card data stays with Stripe.

    Safeguard: Provider data-processing agreement incorporating the EU SCCs with the UK Addendum.

  • Google (Firebase Cloud Messaging) · United States and global

    Mobile push notifications.

    Receives: The push token, and the notification title and body — which carry the same alert text.

    Safeguard: Google data-processing terms incorporating the EU SCCs with the UK Addendum.

  • Cloudflare · Global edge

    The network edge for our hostnames, and the anti-bot check on the waitlist form.

    Receives: All traffic transits and is decrypted at the edge, so its content passes through it; at rest, traffic metadata such as IP addresses.

    Safeguard: Provider data-processing agreement incorporating the EU SCCs with the UK Addendum.

  • Google (Google Analytics) · United States and global

    Analytics for this marketing website only — never inside the product, and only if you consent.

    Receives: The analytics identifier in your browser, pages viewed, referring source, truncated IP address and device characteristics. Nothing flows until you accept.

    Safeguard: Google Ads data-processing terms incorporating the EU SCCs with the UK Addendum, plus IP anonymisation, Google Signals and advertising features off, and no join to anything you do inside the product.

Changes, and your right to object

For any subprocessor touching data we process under the Data Processing Agreement, we give 30 days' prior notice of an addition or a replacement, by email to the Developer account on file and by updating this page. A Developer may object on reasonable data-protection grounds by writing to [email protected]; if we cannot resolve the objection, the Developer may terminate the affected service under our Terms.

We may replace a subprocessor without prior notice where security, legal compliance or continuity of service requires it. In that case we notify as soon as reasonably practicable, and the same objection and termination rights apply after the fact.

To be told about changes, email [email protected] and ask to be added to the subprocessor change list. For changes affecting our own processing as controller, we update this page and the Privacy Notice, and give notice of material changes as described in that notice.

What we require before any of them receives data

  • Written Article 28 terms containing the full mandatory clauses — documented instructions, confidentiality, security, flow-down to their own subprocessors, assistance with rights requests, assistance with our security, breach and impact-assessment obligations, deletion or return, audit and information, and the duty to tell us if an instruction would break data protection law.
  • Where the provider is outside the UK, an identified transfer mechanism and a transfer risk assessment, scoped to the data that actually flows rather than the smallest category.
  • Data minimisation: whether the integration can send less — identifiers instead of email addresses, content-free events instead of message bodies.
  • Obligations no less protective than those we owe under the Data Processing Agreement. We remain fully liable to Developers for a subprocessor's performance.

When we stop using a provider we instruct deletion or return of the data, confirm it where the provider offers confirmation, and record the removal here.

Not subprocessors

These receive data, and are deliberately not on the list above. Listing them as subprocessors would misdescribe who is responsible for what.

  • Notification endpoints you configure

    Webhook URLs, Discord, Slack, Telegram, Microsoft Teams, ntfy or any custom endpoint. You choose the recipient and we deliver where you point us, so these are recipients you direct — not parties processing on our behalf.

  • Your own broker or exchange

    When you add a read-only API connection, we read from a service that is already yours under your own relationship with it.

  • Apple and Google, for sign-in and store billing

    They act as independent controllers under their own notices, not as our processors.

  • Your Developer, if you activate their product

    A Developer is a separate controller for their own end users' data; where we process it, we do so as their processor under the Data Processing Agreement.

Copies of the safeguards

You can request a copy of the transfer safeguard relied on for any provider above — redacted where necessary for commercial confidentiality — by writing to [email protected]. See also how to make a data request.

Contact

TrendSoft Ltd, Aa House 54, 27 Old Gloucester Street, London, WC1N 3AX, United Kingdom. Company No. 16144241. Privacy and data protection: [email protected]. General: [email protected].