Subprocessor list
Superseded by ADR-046 (2026-06-03). This document reflects the prior crypto-first posture, which is no longer GA scope. See ADR-046.
Scope (added 2026-08-10): Entries below premised on the superseded crypto rail — the Wise Europe USDC off-ramp and the wallet-address (on-chain identifier) screening category under Chainalysis — are preserved for the record and are not current practice. The Estonian Tax and Customs Board entry is premised on the prior Estonian OÜ posture: the operating entity is JuiceVendor Labs inc., a Delaware C corporation, which does not file Estonian withholding or INF1 declarations. The vendor registry is pending counsel re-baseline under the fiat model and the 2026-08-10 entity decision.
Article 28(3) GDPR
Status: v1.0 — 2026-05-29
Source of truth: server/compliance/gdpr/subprocessor-list.ts
Next review: every 90 days + on every new subprocessor onboarding
This document is the human-readable rendering of the machine-readable subprocessor registry. The TypeScript source is authoritative; CI rejects PRs that change vendor surface without also updating server/compliance/gdpr/subprocessor-list.ts and re-rendering this document.
JuiceVendor Labs inc. (operating the GoFundNode service) is the processor on behalf of tenants. The subprocessors below process personal data on behalf of GoFundNode under flow-down clauses substantively equivalent to our own controller agreements (Article 28(3) full set).
Flow-down clauses (applied to every subprocessor)
| Clause | Article | Status |
|---|---|---|
| Instruction-only processing | 28(3)(a) | required |
| Confidentiality commitment from staff | 28(3)(b) | required |
| Security measures (encryption in transit / at rest / access controls / audit logging) | 28(3)(c) + 32 | required |
| Sub-subprocessor prior consent | 28(2) + 28(4) | required |
| Data subject rights assistance | 28(3)(e) | required |
| Breach notification within 24h | 33(2) | required |
| Audit rights | 28(3)(h) | required |
| Return-or-delete at term | 28(3)(g) | required |
Subprocessors
Neon (managed Postgres)
- Legal entity: Neon Inc. (US)
- Category: managed_postgres
- Lawful purpose: Primary platform data store: tenants, submissions, leases, signature registry, credit ledger. EU-applicant data provisioned in eu-central region.
- Data categories: tenant identifiers, submission metadata, encrypted PII payloads (envelope ciphertext), audit events, credit ledger.
- Processing region: EU/EEA (eu-central region pinned for EU applicants)
- Domicile: US (legal entity)
- Transfer mechanism: Standard Contractual Clauses (Art 46(2)(c))
- DPA reference: NEON-DPA-2026-Q1, signed 2026-02-15
- Publicly listed: yes
- Notes: EU-applicant data is pinned to Neon's eu-central region. SCCs cover the legal-entity transfer to the US parent; data residency is enforced by region selection at provisioning.
Cloudflare R2 (object storage)
- Legal entity: Cloudflare, Inc. (US)
- Category: object_storage
- Lawful purpose: Encrypted artifact storage: vanguard screenshots, lease artifacts, operator export bundles. Cleartext never touches R2 — only three-layer-envelope ciphertext.
- Data categories: encrypted artifact ciphertext, envelope metadata (manifest_hash, lease_id, tenant_id).
- Processing region: EU/EEA
- Domicile: US
- Transfer mechanism: SCCs
- DPA reference: CF-R2-DPA-2026-Q1, signed 2026-01-30
- Publicly listed: yes
- Notes: Region bucket pinned to EU. All objects encrypted at REST by R2 + at application level by three-layer envelope.
Wise Europe SA/NV (regulated payouts)
- Legal entity: Wise Europe SA/NV (BE; registered EMI)
- Category: regulated_payouts
- Lawful purpose: Off-ramp from USDC settlement to operator fiat bank accounts for non-crypto-preferring operators. Required for AMLD5 obliged-entity payout compliance.
- Data categories: operator IBAN, operator legal name, operator tax residency, payout amount and reference.
- Processing region: EU/EEA
- Domicile: BE
- Transfer mechanism: eu_only (no transfer outside EU/EEA)
- DPA reference: WISE-DPA-2026-Q1, signed 2026-03-04
- Publicly listed: yes
- Notes: L3 workstream integrates this. EMI regulated by NBB (Belgian National Bank). No transfer outside EU/EEA.
Corrected by ADR-046 (2026-06-03): operator payouts are fiat via an embedded payout stack (Stripe Connect or equivalent), not USDC/Solana; customer payment is fiat; customer credits are consumptive single-issuer prepayment; there is no token, wallet, self-custody, or stored value. See docs/ADR/0046-fiat-resource-contribution-model.md.
Chainalysis (sanctions screening)
- Legal entity: Chainalysis Inc. (US)
- Category: sanctions_screening
- Lawful purpose: AMLD5 Article 13 sanctions/PEP/adverse-media screening for operator KYC and high-value flows. L2 workstream interfaces.
- Data categories: hashed subject identifier, wallet address (on-chain identifier), screening result (hit/no-hit/manual-review).
- Processing region: EU/EEA (Chainalysis EU endpoint)
- Domicile: US
- Transfer mechanism: SCCs
- DPA reference: CHAINALYSIS-DPA-2026-Q1, signed 2026-02-22
- Publicly listed: yes
- Notes: Chainalysis processes hashed identifiers only — raw PII does not leave GoFundNode. SCCs cover incidental EU→US transfer of hashed identifiers.
Corrected by ADR-046 (2026-06-03): operator payouts are fiat via an embedded payout stack (Stripe Connect or equivalent), not USDC/Solana; customer payment is fiat; customer credits are consumptive single-issuer prepayment; there is no token, wallet, self-custody, or stored value. The wallet-address (on-chain identifier) data category above is a crypto-rail artifact of the superseded posture, preserved for the record — it is not screened under the fiat model. See docs/ADR/0046-fiat-resource-contribution-model.md.
Sumsub (operator KYC)
- Legal entity: Sum and Substance Ltd. (UK)
- Category: operator_kyc
- Lawful purpose: AMLD5 Article 13 customer due diligence for operator onboarding: ID document verification, liveness check, sanctions screening overlay.
- Data categories: operator name, operator DOB, operator ID document image (encrypted in transit), liveness selfie (deleted after verification), verification result.
- Processing region: EU/EEA
- Domicile: GB
- Transfer mechanism: SCCs + UK adequacy decision (June 2021)
- DPA reference: SUMSUB-DPA-2026-Q1, signed 2026-01-12
- Publicly listed: yes
- Notes: UK adequacy decision in force; SCCs as belt-and-braces for any post-decision drift.
Twilio SendGrid (transactional email)
- Legal entity: Twilio Inc. (US)
- Category: transactional_email
- Lawful purpose: Transactional email: tenant onboarding, DSAR receipt confirmation, breach notifications, operator earnings statements.
- Data categories: email address, message body (DSAR notifications include subject identifier hash only — not raw PII).
- Processing region: EU/EEA
- Domicile: US
- Transfer mechanism: EU-US Data Privacy Framework (DPF)
- DPA reference: TWILIO-SENDGRID-DPA-2026-Q1, signed 2026-02-08
- Publicly listed: yes
- Notes: DPF-certified; SCCs available as fallback if DPF is invalidated.
Sentry (error monitoring)
- Legal entity: Functional Software, Inc. (d/b/a Sentry, US)
- Category: error_monitoring
- Lawful purpose: Error and performance monitoring. PII is redacted at ingest via pino redaction policy.
- Data categories: error stacks, request metadata (paths, status codes), redacted (PII-stripped) payload references.
- Processing region: EU/EEA (Sentry de1.sentry.io)
- Domicile: US
- Transfer mechanism: SCCs
- DPA reference: SENTRY-DPA-2026-Q1, signed 2026-03-21
- Publicly listed: yes
- Notes: Self-hosted on Sentry's EU region. pino redaction policy strips PII fields before transmission; redaction list maintained in
server/_core/logger.ts.
Estonian Tax and Customs Board (tax filing — data recipient)
- Legal entity: Eesti Maksu- ja Tolliamet (MTA)
- Category: tax_filing
- Lawful purpose: Statutory tax reporting for operator earnings: withholding and INF1 declarations.
- Data categories: operator legal name, operator tax residency, annual gross earnings, withholding tax amount.
- Processing region: EE
- Domicile: EE
- Transfer mechanism: eu_only
- DPA reference: MTA-RECIPIENT-2026-Q1, signed 2026-03-01
- Publicly listed: yes
- Notes: MTA is a data recipient under legal obligation (GDPR Art 6(1)(c)), not a subprocessor in the Art 28 sense. Listed for transparency. No flow-down clauses imposed by us; the legal obligation is statutory.
Historical — superseded by the 2026-08-10 entity decision: the operating entity is JuiceVendor Labs inc., a Delaware C corporation, not an Estonian OÜ, and does not file Estonian withholding or INF1 declarations with the MTA. This entry reflects the prior posture and is preserved for the record; information-reporting obligations under the current entity are pending counsel determination (see
docs/legal/COUNSEL_QUESTIONS.md§12.8).
Sub-subprocessors
Subprocessors above are bound to obtain GoFundNode's prior consent before engaging sub-subprocessors. Current declared sub-subprocessors:
- Neon → AWS (infrastructure host). Neon's underlying compute and storage runs on AWS Frankfurt (eu-central-1) for our EU instance. AWS DPA + EU AWS Region.
- Cloudflare R2 → Cloudflare CDN. Same legal entity; no additional sub-subprocessor.
- Wise Europe → SWIFT for international wires. SWIFT operates as a data recipient under legal obligation for cross-border wire transfer, not as a sub-processor in the Article 28 sense.
If any subprocessor proposes a new sub-subprocessor, the DPO reviews within 14 days and either consents or objects in writing.
Public list and notification
This document is published at https://gofundnode.com/legal/subprocessors as required by Article 28(2) transparency obligations. New subprocessor additions trigger a 30-day controller notification window (apply.fun's DPO is on the change-notice list).
For questions or objections: dpo@gofundnode.com