Skip to content
worldgovdata

Legal / Subprocessors

Subprocessors

Five third parties, named with their role, where they process and the transfer mechanism that covers them. The service itself runs on infrastructure in Germany, inside the European Union, which is why most of this page has nothing to justify.

List updated 2026-07-28 · Annex to the privacy policy and the DPA

01

What this page is

A subprocessor is a third party that processes data on our behalf so that we can run the service. We keep the number small on purpose: every one is a party that has to be trusted, contracted with, and told about here.

Everything below is bound by a written data processing agreement, may act only on our documented instructions, is subject to confidentiality obligations, and is required to apply appropriate technical and organisational measures. Where a transfer outside the European Economic Area is involved, the mechanism is named — no transfer happens on an unstated basis.

This list is authoritative. The privacy policy summarises it; the data processing addendum incorporates it by reference for customers who have one.

02

The list

Every subprocessor worldgovdata uses, with role, processing location and transfer mechanism.
ProviderRoleWhere it processesTransfer mechanism
netcup GmbHGermanyApplication and database hosting, storage, backups. Everything the service runs on.Germany — European UnionNone required. Processing stays inside the EEA.
Cloudflare, Inc.United StatesDNS, TLS termination, content delivery and denial-of-service protection in front of the site and the API.Global edge network; company incorporated in the United StatesEU Standard Contractual Clauses in Cloudflare's data processing addendum, plus the UK addendum.
PostHogUnited StatesCookieless product analytics — aggregate page-view counts, with no identifier and no profile.PostHog EU Cloud, hosted in the European UnionData is stored in the EU. Standard Contractual Clauses in PostHog's DPA cover any support access from outside the EEA.
ResendUnited StatesTransactional email delivery: verification, password reset, receipts, security notices.United StatesEU Standard Contractual Clauses in Resend's data processing agreement.
Razorpay Software Private LimitedIndiaPayment processing and payment-related compliance for credit purchases.IndiaEU Standard Contractual Clauses. Razorpay is also an independent controller for the payment and compliance data you give it directly — see clause 04.

“Standard Contractual Clauses” means the clauses adopted by the European Commission in Implementing Decision (EU) 2021/914, in the module appropriate to the relationship, together with the UK International Data Transfer Addendum where UK data is involved. You may ask us for a copy of the safeguards in place for any transfer at connect@worldgovdata.com.

03

What each one actually receives

A list of names is not much use without knowing what reaches whom. In each case the provider gets only what the function requires.

netcup GmbH — hosting

Everything, in the sense that the whole application and database run on their infrastructure: account records, hashed credentials, usage events, the credit ledger, orders. netcup does not access it in the ordinary course; they provide the machines and the network. This is the reason we chose an EU host — it means the default location of every record is inside the EEA, not a transfer to be justified.

Cloudflare — CDN, DNS and protection

Request metadata in transit: IP address, requested URL, user-agent, TLS details. It sits in front of the service, so it necessarily sees the connection. It does not receive account records or the database. Note that Cloudflare sees your real IP address even though we store only a hashed digest of it — that is a property of any network intermediary and we would rather state it than let the hashing claim imply more than it does.

PostHog — analytics

A page path and a timestamp, with no cookie, no persistent identifier and no user account attached. Autocapture, session recording and page-leave tracking are off. The events cannot be linked back to a person, by us or by them.

Resend — email

Your email address and the content of the message we are sending you — a verification link, a reset link, a receipt, a security notice. Nothing else. Where a deployment sends through our own SMTP server instead, no third party is involved in delivery at all.

Razorpay — payments

The order amount, currency, our receipt number and an order reference, plus whatever you type into their checkout. Your card number never touches our systems: it goes from your browser to them. What comes back to us is a payment identifier and a status.

04

The payment processor is also its own controller

This is the one relationship on the page that is not a straightforward processor arrangement, and it is worth being precise about.

For the instruction we give — take this amount, for this order — Razorpay acts as our processor. But for the card details, fraud checks and anti-money-laundering records it collects directly from you, it acts as an independent controller under its own obligations and its own privacy notice. We do not instruct it on that processing, we do not receive that data, and we cannot answer for it. Data protection requests about that data go to Razorpay; requests about anything we hold come to us.

05

Who is not on this list

Just as important as the list itself. We use no:

  • advertising networks, ad exchanges, retargeting pixels or conversion trackers;
  • data brokers, enrichment services or lead-generation providers;
  • customer-data platforms, marketing automation suites or CRM systems holding your account data;
  • third-party AI or machine-learning services processing customer data. Your account, usage and support correspondence are not used to train anyone’s model, ours included;
  • session-replay, heat-mapping or behavioural-analytics tools of any kind;
  • embedded social widgets, comment systems, externally hosted fonts or third-party video players.
06

How we choose, and how we bind them

Before a provider is added, it has to clear four things:

  • Necessity. There is a function we genuinely cannot run ourselves at reasonable cost or quality. Convenience is not a reason.
  • Minimisation. It receives the least data the function needs, and no more.
  • Contract. A written agreement with GDPR Article 28 terms, and, where it processes outside the EEA, a valid transfer mechanism in place before any data moves.
  • Location preference. An EEA option wins where one exists at comparable quality. That is how the host and the analytics region were chosen.
07

Changes to this list

When we add or replace a subprocessor we update this page and change the stamp at the top.

  • Notice. Customers with a data processing addendum in place are emailed at least 30 days before a new subprocessor starts processing their data.
  • Objection. Those customers may object on reasonable data protection grounds within that period. We will try to resolve it; if we cannot, either side may terminate the affected part of the service and we refund the unused credit balance.
  • Emergency replacement. If a provider fails or has to be replaced urgently for security reasons, we may act first and tell you immediately afterwards, with the reason.
  • Want to be told? Email connect@worldgovdata.com with “subscribe to subprocessor notices” and we will add you to the notification list, DPA or not.

To be notified before this list changes, or to ask for a copy of the transfer safeguards for any provider named here, email connect@worldgovdata.com.