Last updated: 14 May 2026
ReadyCMS AB engages the third parties listed below to assist in providing the ReadyCMS platform. Each of them is contractually bound to data-protection obligations no less protective than those in our Data Processing Agreement (DPA) with you, and each acts only on our documented instructions.
We notify customers by email at least 30 days before adding a new sub-processor that processes customer personal data, or replacing an existing one. Customers may object on reasonable data-protection grounds within that window; see section 5 of the [DPA] for the consequences of an unresolved objection.
1. Sub-processors that process customer personal data
These sub-processors may have access to or process personal data that customers upload to or generate within the ReadyCMS platform.
| # | Name and legal entity | Jurisdiction (data center) | Service provided | Transfer mechanism for non-EEA storage |
|---|---|---|---|---|
| 1 | Hetzner Online GmbH — Industriestr. 25, 91710 Gunzenhausen, Germany |
Germany (Nuremberg, Helsinki, Falkenstein) — EEA | Primary hosting, dedicated servers, VPN, JetBackup off-site backup target (Hetzner Storage Box) | Not applicable (EEA) |
| 2 | Cloudflare, Inc. — 101 Townsend Street, San Francisco, CA 94107, USA |
United States, with a global edge cache | Content delivery network, WAF, DDoS mitigation, TLS termination | EU–US Data Privacy Framework (Cloudflare is certified) + 2021/914 SCCs Module 3 as additional safeguard |
| 3 | Stripe Payments Europe Ltd — 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland (with Stripe, Inc., USA, as its own sub-processor) | Ireland (primary); United States (Stripe, Inc.) | EU–US Data Privacy Framework (Stripe, Inc. is certified) + 2021/914 SCCs | |
| 4 | WHM/cPanel L.L.C. — 2550 N Loop W, Houston, TX 77092, USA | Self-hosted on Hetzner DE; product telemetry to the US | Server control panel software (account, mail, DNS, file management). Telemetry only — no customer personal data leaves the EEA. | 2021/914 SCCs Module 3 (telemetry only) |
| 5 | Tally NV | — Veemarkt 47, 9000 Ghent, Belgium | Belgium — EEA | Form builder used by our customer-success team for product surveys and waitlists | Not applicable (EEA) |
| 6 | Answerly, Inc. | United States | AI-assisted customer support widget | EU–US Data Privacy Framework (where certified) + 2021/914 SCCs Module 3 |
| 7 | OpenAI, L.L.C. — 3180 18th Street, San Francisco, CA 94110, USA | United States | Large-language-model inference for opt-in AI features in the platform | EU–US Data Privacy Framework (OpenAI is certified) + 2021/914 SCCs Module 3 + zero-retention API mode where available |
| 8 | Anthropic PBC — 548 Market Street, PMB 90375, San Francisco, CA 94104, USA | United States | Large-language-model inference for opt-in AI features in the platform | EU–US Data Privacy Framework (where certified) + 2021/914 SCCs Module 3 + zero-retention configuration where available |
How customer data flows to each sub-processor
- Hetzner receives all customer data at rest. Backups are written to a Hetzner Storage Box in Germany.
- Cloudflare processes data in transit only. Page bodies and form submissions transit Cloudflare's network; cached static assets do not contain personal data.
- Stripe receives billing-side personal data of the ReadyCMS customer (the merchant): contact name, company name, billing address, VAT, card token, and transaction history. Stripe does not receive end-customer (shopper) data unless the customer separately enables Stripe for their own ecommerce checkout, in which case the customer has a direct relationship with Stripe, and ReadyCMS is not a party to it.
- cPanel has access to server-level configuration on Hetzner hosts. Customer personal data resides in databases administered through cPanel, but is not exported to cPanel L.L.C.; telemetry data sent to cPanel L.L.C. is limited to licensing and software-version metadata.
- Tally is used only when a customer chooses to fill out a survey or waitlist. The data subjects are the survey respondents.
- Answerly processes support chat content from users who initiate a chat through our support widget. Customers can disable the widget for their tenant.
- OpenAI / Anthropic are invoked only when an AI feature is explicitly enabled and triggered. Prompts contain whatever the feature is operating on (for example, product descriptions or chat history snippets). API calls are made with zero-data-retention controls enabled where the provider supports them.
2. Infrastructure providers that do not process customer personal data
For completeness, the following parties form part of our supply chain but do **not** have access to customer personal data:
- Namesilo, LLC (USA) — domain registrar. Holds only domain-registrant data (which is ReadyCMS's own corporate data).
- Google LLC / Google Ireland Limited — Google Analytics, Google Search Console, Google Ads. Used only on our public marketing website at readycms.io. They are not deployed on customer-operated stores. The data flow is described in our [Cookie Policy].
- Meta Platforms Ireland Ltd. / Meta Platforms, Inc. — Meta Ads pixel and conversions API. Used only on our public marketing website. See the Cookie Policy.
- Syncthing — open-source software running on our own infrastructure for file replication between our servers. No third-party service is involved.
3. Notification of changes
Customers are notified of changes to this list by email to the address on file for the customer's primary contact and via an in-app banner that remains visible for the duration of the 30-day objection window.
To object to a proposed new sub-processor, email privacy@readycms.io within 30 days of the notification. We will work with you in good faith to address the objection; if it cannot be resolved, you may terminate the affected service as described in section 5 of the DPA.
To receive notifications in addition to the named primary contact, email privacy@readycms.io with the additional addresses.
4. Changes log
| Date | Change |
|---|---|
| 2026-05-14 | Initial publication. |