Subprocessors and supplier management

The third parties that process personal data on Depozza's behalf, what they do, and where the data sits.

All compliance documents
Version
1.0 · Effective 2026-08-11
Owner
privacy@depozza.eu
Review cycle
On change
Mapped controls
GDPR art. 28, 44–49 · ISO 27001 A.5.19–A.5.22

Current subprocessors

  • Payments and payouts — Stripe. Processes payment and payout details; PCI-DSS certified. Depozza never stores card numbers.
  • Application hosting, database and file storage — managed EU cloud infrastructure. Stores accounts, listings, bookings, messages and uploaded documents.
  • Transactional and authentication email — email delivery provider. Processes recipient address and message content.
  • Identity verification — verification provider. Processes identity documents and check results for hosts and renters who verify.
  • Error monitoring — processes technical diagnostics; personal data is minimised in error payloads.

How suppliers are selected

  • A data-processing agreement must be in place before any personal data is shared.
  • EU hosting or an approved transfer mechanism (standard contractual clauses) is required.
  • The supplier's own security posture and breach-notification commitments are reviewed before onboarding.

International transfers

Primary storage of personal data is in the European Union. Where a supplier processes data outside the EU, the transfer relies on standard contractual clauses or an adequacy decision.

Changes to this list

This page is updated when a subprocessor is added or removed. Business customers who want advance notice of changes can request it at privacy@depozza.eu.

Questions about this document

privacy@depozza.eu

This document states Depozza SAS's own policy. It is not a certification, an audit report or a legal guarantee.