Sub-Processor Register

Effective Date: April 1, 2026 Last Updated: April 1, 2026


1. Overview

nproxy engages the following sub-processors to deliver the service. Each sub-processor is contractually bound to process personal data only for the purposes described below. Changes to the sub-processor list will be communicated to customers in advance per the Data Processing Agreement.


2. Sub-Processor Register

Cloudflare, Inc.

FieldValue
CompanyCloudflare, Inc.
HeadquartersSan Francisco, California, USA
PurposeAll infrastructure hosting and compute for the nproxy platform
Services usedWorkers (compute), D1 (SQLite database), KV (key-value cache), R2 (object storage), Durable Objects (stateful coordination), Queues (message pipeline), Analytics Engine (metrics)
Data processedAll personal data described in the Privacy Policy: user accounts, sessions (IP, user agent), OAuth tokens, organization configurations, API token hashes, audit events, internal packages, billing references, SCIM provisioning data
DPA statusCloudflare DPA available at cloudflare.com/privacy-policy/ (incorporated by reference in Cloudflare's Terms of Service)
CertificationsSOC 2 Type II, ISO 27001, PCI DSS Level 1, HIPAA (with BAA on Enterprise plan), C5, FedRAMP
Transfer mechanismEU-US Data Privacy Framework, Standard Contractual Clauses (SCCs)
Data locationGlobal (Cloudflare operates data centers in 300+ cities worldwide; Workers execute at the nearest edge location to the request origin)

Stripe, Inc.

FieldValue
CompanyStripe, Inc.
HeadquartersSan Francisco, California, USA
PurposePayment processing and subscription billing
Services usedStripe Checkout (redirect-based payment collection), Stripe Webhooks (subscription lifecycle events), Stripe API (subscription management)
Data processedStripe customer ID and Stripe subscription ID (generated by Stripe and stored as references in nproxy). Payment card data is collected and processed entirely by Stripe; nproxy never receives, transmits, or stores card data.
DPA statusStripe DPA available at stripe.com/privacy (incorporated by reference in Stripe's Terms of Service)
CertificationsSOC 2 Type II, PCI DSS Level 1, ISO 27001
Transfer mechanismEU-US Data Privacy Framework, Standard Contractual Clauses (SCCs)

GitHub, Inc. (Microsoft)

FieldValue
CompanyGitHub, Inc. (subsidiary of Microsoft Corporation)
HeadquartersSan Francisco, California, USA
PurposeOAuth authentication provider
Services usedGitHub OAuth App (authentication)
Data processedOAuth authentication: GitHub account ID, OAuth access token, OAuth refresh token
DPA statusGitHub DPA available at docs.github.com/en/site-policy/privacy-policies (incorporated by reference in GitHub's Terms of Service)
CertificationsSOC 2 Type II, ISO 27001
Transfer mechanismEU-US Data Privacy Framework, Standard Contractual Clauses (SCCs)

Resend, Inc. (Planned)

FieldValue
CompanyResend, Inc.
HeadquartersSan Francisco, California, USA
PurposeTransactional email delivery (account verification, password reset, security notifications)
Services usedResend Email API (planned integration)
Data processedEmail address, email subject, email content (transactional messages only)
DPA statusResend DPA available at resend.com/legal/dpa
CertificationsSOC 2 Type II
Transfer mechanismStandard Contractual Clauses (SCCs)
NoteThis sub-processor is listed in advance of integration. Customers will be notified when the integration goes live.

Socket, Inc. (socket.dev)

FieldValue
CompanySocket, Inc.
HeadquartersSan Francisco, California, USA
PurposePackage security intelligence — analyzing packages for malware, suspicious behavior, and security scoring
Services usedsocket.dev API (batch PURL endpoint for package analysis)
Data processedPackage names and versions only. No personal data is transmitted to socket.dev.
DPA statusNot required — no personal data is shared with socket.dev
CertificationsN/A
Transfer mechanismNot applicable (no personal data transfer)

OSV.dev (Google)

FieldValue
CompanyGoogle LLC (OSV.dev is a Google-operated open-source vulnerability database)
HeadquartersMountain View, California, USA
PurposeVulnerability advisory data — querying known CVEs and security advisories for packages
Services usedOSV.dev API (batch query endpoint)
Data processedPackage names only. No personal data is transmitted to OSV.dev.
DPA statusNot required — no personal data is shared with OSV.dev
CertificationsN/A (OSV.dev is a free, open-source service operated by Google)
Transfer mechanismNot applicable (no personal data transfer)

3. Sub-Processor Summary Table

Sub-ProcessorPurposePersonal DataDPAKey Certifications
CloudflareAll infrastructureAll personal dataYes (Cloudflare DPA)SOC 2, ISO 27001, PCI DSS L1, HIPAA
StripeBillingStripe customer/subscription IDsYes (Stripe DPA)SOC 2, PCI DSS L1, ISO 27001
GitHubOAuth + source hostingOAuth tokens, GitHub account IDYes (GitHub DPA)SOC 2, ISO 27001
Resend (planned)Transactional emailEmail addressesYes (Resend DPA)SOC 2
socket.devPackage analysisPackage names only (no PII)N/AN/A
OSV.dev (Google)Vulnerability advisoriesPackage names only (no PII)N/AN/A

4. Sub-Processor Change Notification

Per GDPR Article 28(2), nproxy will notify customers of any intended changes to sub-processors (additions or replacements) with reasonable advance notice, allowing customers the opportunity to object. Notification will be provided via:

  • Email to organization owners (when transactional email is available)
  • Dashboard notification banner
  • Update to this document

Customers who object to a sub-processor change may terminate their subscription in accordance with the Terms of Service.


5. Document Control

VersionDateChanges
1.0April 1, 2026Initial sub-processor register