Skip to main content
Skip to main content
deploybase
FeaturesPricingCompareDeploy
Sign In Start Deploying

Subprocessors

Last updated: August 27, 2026

Contents

  1. Overview
  2. Subprocessors
  3. What we run ourselves
  4. What we do not use
  5. Services you connect
  6. Changes to this list

1. Overview

A subprocessor is a third party we use that processes data on behalf of our customers. When you host a site with deploybase, a small number of other companies necessarily handle parts of that work: the servers your build runs on, the network that delivers your files, the service that sends your notification emails, the company that invoices you.

There are exactly 4. Every one of them is headquartered in the European Union, and the personal data we process for you stays in the EU. The two caveats worth knowing, public site files cached at global edge locations for delivery and the card payment rails inside our billing provider's own chain, are spelled out on this page rather than left for you to discover.

Each subprocessor is listed with its full legal entity and, where we have verified it, its registration number, so you can check these claims against the public registers yourself rather than taking our word for them.

This page is the canonical list referenced by our data processing agreement. Each subprocessor is bound by data processing terms meeting GDPR Article 28, with obligations no less protective than the ones we accept towards you.

2. Subprocessors

Scaleway #

Paris, France
Legal entity
Scaleway S.A.S.
Registration
R.C.S. Paris 433 115 904
Processing location
Paris, France (fr-par datacenter)
Reference
Scaleway privacy policy

What it does: Cloud infrastructure: servers, the build system, database, object storage, logs and metrics, secrets management.

Data processed: Everything we store to run the service: account data, your site files and build logs, form submissions, usage records, encrypted configuration secrets.

Bunny.net #

Ljubljana, Slovenia
Legal entity
BUNNYWAY, informacijske storitve d.o.o.
Processing location
Site files are stored in EU storage regions. Public static files are cached at global edge locations for delivery
Reference
Bunny.net GDPR overview

What it does: Content delivery network, site file storage and DNS for site domains.

Data processed: Deployed site content, CDN access logs, DNS zones for your custom domains.

Lettermint #

Zwolle, Netherlands
Legal entity
Lettermint B.V.
Registration
KVK 99337711
Processing location
EU. Lettermint's data processing agreement commits all email data processing to the EU
Reference
Lettermint data processing agreement

What it does: Transactional email delivery: build, billing and form notification emails.

Data processed: Recipient email addresses and notification content.

Creem #

Tallinn, Estonia
Legal entity
Armitage Labs OÜ
Registration
Estonian registry 16977866
Processing location
Tallinn, Estonia (EU)
Reference
Creem privacy policy

What it does: Billing and payments, as our merchant of record (the company you buy from).

Data processed: Billing name and address, VAT ID, payment method, invoices. Card details never touch deploybase systems.

As our merchant of record, Creem is the company you actually buy from: your invoice and card statement show Creem, and it handles VAT for you. It acts as an independent controller for payment processing, and its own provider chain includes services outside the EU: card payments can run on Stripe (US) payment infrastructure, covered by EU standard contractual clauses. The billing relationship, invoicing and VAT handling stay in the EU.

3. What we run ourselves

The reliable way to keep a subprocessor list short is to buy less software. Ours is short because we operate these parts of the platform on our own infrastructure, so no third party is involved in them at all.

Authentication
Zitadel, running on our own cluster in Paris. Your credentials never leave our infrastructure.
Database
Runs on our own cluster in Paris. No managed third-party database service holds your data.
Status page
status.deploybase.eu is self-hosted. No status page vendor sees your traffic.
CI and build system
Builds run in isolated jobs on our own cluster, never on a third-party build service.

4. What we do not use

Some categories of vendor turn up on almost every subprocessor list in this industry. These are absent from ours.

  • No US hyperscaler. No AWS, Google Cloud, Azure or Cloudflare anywhere in the stack.
  • No third-party error tracking service. Errors go to our own monitoring, hosted in Paris.
  • No external spam scoring or CAPTCHA API. Form spam filtering runs entirely on our own infrastructure.
  • No analytics SaaS and no advertising trackers, on your sites or in the dashboard. Our own analytics are self-hosted and cookie-free.

5. Services you connect

deploybase can connect to a Git provider you already use: GitHub, GitLab, Bitbucket, Codeberg. When you connect a repository, we receive the code you point us at and we act on your instruction to build and deploy it.

These are your own providers, under your own agreement with them, so they are not our subprocessors. You choose whether to connect one, which repositories to grant access to, and when to disconnect. You can also deploy without connecting any Git provider at all.

6. Changes to this list

We update this page, and the last-updated date at the top of it, before engaging a new subprocessor. We give at least 30 days notice before adding or replacing one, matching section 5 of our DPA. If you object to a new subprocessor, you may terminate the affected service by giving written notice within that window.

For questions about this list, or to raise an objection, email us at support@deploybase.eu.

deploybase

Static site hosting, built in the Netherlands.

support@deploybase.eu

Product

Features Forms Pricing Changelog Open Source For agents Brand kit

Use Cases

All Use Cases Presentations Portfolios

Frameworks

All Frameworks Astro Hugo SvelteKit

Compare

All Comparisons vs Netlify vs Netlify Forms vs Vercel vs GitHub Pages vs StaticHost

Legal

Security Sustainability Privacy Policy Terms of Service Cookie Policy DPA Subprocessors Status
© 2026 TwanIT KVK 71667415 · BTW-id NL002404374B49 Live · 694b73c · built 27 Aug 2026
Hosted in the EU