All compliance documents
- Version
- 1.0 · Effective 2026-08-11
- Owner
- privacy@depozza.eu
- Review cycle
- On change
- Mapped controls
- GDPR art. 28, 44–49 · ISO 27001 A.5.19–A.5.22
Current subprocessors
- Payments and payouts — Stripe. Processes payment and payout details; PCI-DSS certified. Depozza never stores card numbers.
- Application hosting, database and file storage — managed EU cloud infrastructure. Stores accounts, listings, bookings, messages and uploaded documents.
- Transactional and authentication email — email delivery provider. Processes recipient address and message content.
- Identity verification — verification provider. Processes identity documents and check results for hosts and renters who verify.
- Error monitoring — processes technical diagnostics; personal data is minimised in error payloads.
How suppliers are selected
- A data-processing agreement must be in place before any personal data is shared.
- EU hosting or an approved transfer mechanism (standard contractual clauses) is required.
- The supplier's own security posture and breach-notification commitments are reviewed before onboarding.
International transfers
Primary storage of personal data is in the European Union. Where a supplier processes data outside the EU, the transfer relies on standard contractual clauses or an adequacy decision.
Changes to this list
This page is updated when a subprocessor is added or removed. Business customers who want advance notice of changes can request it at privacy@depozza.eu.
Questions about this document
privacy@depozza.euThis document states Depozza SAS's own policy. It is not a certification, an audit report or a legal guarantee.