Who else touches your data
Version 1.1 — in force from 12 August 2026. The only change from 1.0: the payment processor is gone. It was listed ahead of being used, and a list of who touches your data should name only who touches it.
Part of the Privacy Policy. These are every outside service involved in running Deklarify that can see personal data, what each one sees, where it sits, and what keeps it lawful.
If we add one, it appears here.
Processors — they act on our instructions
Amazon Web Services
Amazon Web Services EMEA SARL, Luxembourg (EU).
- What it does: sends our email — confirming your address when you register or ask for the link again, and password resets. Those two, and nothing else. Report files are not stored with AWS: they sit in object storage on our own server, covered by the Hosting entry below.
- What it sees: your email address, and the contents of mail we send you.
- Where: email is sent from Frankfurt (eu-central-1), chosen so that EU users' addresses stay in the EU.
- Leaving the EU: not for email. AWS's Standard Contractual Clauses cover support access from outside the EU.
- Art. 28 basis: the AWS GDPR Data Processing Addendum, incorporated into the AWS Service Terms and applying automatically to the account.
Google Analytics
Google Ireland Limited, Dublin, Ireland (EU), with Google LLC, United States.
- What it does: tells us which pages get used.
- What it sees: pages you viewed, approximate location from your IP, your device and browser, and a random identifier stored on your device.
- Where: United States — Google LLC. GA4 offers no EU data residency; Google Ireland Limited is the contracting entity, but the data itself is processed in the US.
- Leaving the EU: Google LLC is certified under the EU–US Data Privacy Framework, with Standard Contractual Clauses under Google's Ads Data Processing Terms as a fallback.
- Only with your consent. Nothing loads until you allow it, and turning it off in Cookie settings stops it.
- Settings we apply: IP addresses are not stored (GA4 does not store them), Google Signals is off, ad personalisation is off in every region, sharing your data with Google's own products and services is off, and data is kept 14 months.
- Art. 28 basis: the Google Ads Data Processing Terms, accepted 20 July 2026, with a named primary GDPR contact recorded against them.
Hosting
Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany.
- What it does: runs the site, the database and the object storage the report files sit in.
- What it sees: everything, in the sense that the data lives there.
- Where: Germany (EU) — Hetzner's Falkenstein/Nuremberg data centres.
- Leaving the EU: No — hosting and its logs stay in Germany. Hetzner's approved-subcontractor list names companies in the United States and Singapore, but those are tied to server locations we do not use; for a server in the EU the agreement confirms the data is processed only in the EU, and support for every location is provided from within it.
- Art. 28 basis: Hetzner Data Processing Agreement, version 1.2, concluded 9 August 2026 in the Hetzner customer account.
Not processors, and why
Tiingo
Our market-data provider. It supplies share prices for listed companies.
No personal data goes to Tiingo. We ask it about ticker symbols; it never learns who asked. It is named here because the data appears in reports, not because it is part of anyone's privacy.
U.S. Securities and Exchange Commission (EDGAR)
Where the filings come from. Public documents, fetched by us. No personal data goes to the SEC — apart from our own company contact address in the User-Agent header, which SEC's fair-access policy requires of everyone.
Google Sign-In
Distinct from Google Analytics, and legally different. When you choose to sign in with Google, Google is not our processor — it is an independent controller running its own service, and what it does with your Google account is governed by Google's own privacy policy.
What passes to us is your Google account identifier and email address, and nothing else. What passes to Google is the fact that you signed in to Deklarify.
The Article 28 contracts
A controller without an Article 28 contract for each processor fails the first question a regulator asks. Here is where each one comes from and when it was agreed, so that answering "show me your processor agreements" takes a minute rather than a week.
- AWS — GDPR Data Processing Addendum, incorporated into the AWS Service Terms and applying automatically to every account. Nothing to sign separately; the Standard Contractual Clauses ride along with it.
- Google Analytics — Google Ads Data Processing Terms, accepted 20 July 2026 on the Analytics account. A named primary GDPR contact for contractually-mandated notices is recorded against it.
- Hetzner — Data Processing Agreement, version 1.2, concluded 9 August 2026 in the Hetzner customer account. Under it, Hetzner secures the data centre and the infrastructure; on a cloud server everything above that — the operating system, the database, encryption at rest — is ours.
No payment processor appears above, because nothing is sold. When that changes, the processor goes on this list before it receives its first byte, and the documents get a fresh review first.