Trust

What an agency needs before putting a client's site on someone else's infrastructure: who touches the data, where it lives, and what we will sign.

Accurate as of 2026-08-25

What this page is

A DACH agency answering a supplier questionnaire, or working through NIS2, needs a subprocessor list and a signable agreement as separate documents — not a paragraph inside a privacy policy. This is that page. It says what is true today, including where something does not exist yet.

Subprocessors

Everyone who processes personal data on our behalf. If a provider is not on this list, it receives nothing.

ProviderPurposeLocationStatus
Hetzner Online GmbH
All workloads run here, under a data processing agreement.
Hosting and infrastructureEU — GermanyIn use
Google Ireland Limited
Support and general correspondence. Not used for bulk sending.
Business email (Google Workspace)EU — IrelandIn use
Mindbaz SAS (Sweego)
Delivers subscription confirmations and system notifications.
Email and SMS deliveryEU — FranceIn use
Stripe Payments Europe
Registration and payment are closed; no payment data has been processed.
Card paymentsEU — IrelandNot in use yet
KBOSS.hu Kft.
Starts with the first invoice, which has not happened.
Electronic invoicingEU — HungaryNot in use yet
AbuseIPDB
Manual escalation only: an operator investigating a specific incident looks up an IP address — an IP only, never an email address, and never automatically.
IP reputation lookup, on manual escalation onlyUnited StatesIn use

One US recipient, on manual escalation only

Every provider in the serving path is in the EU. The one US entry above receives an IP address, and only when an operator investigating a specific incident looks one up — never automatically, never for the general visitor population, never an email address. Its Art. 46 transfer mechanism is not yet confirmed, and this page would rather say so than leave the row looking settled.

Where the data is

100% EU infrastructure. No US subprocessor in the serving path — the single US recipient is the manual lookup described above, never an automatic one. Analytics are first-party and self-hosted, so there is no third-party tracker to disclose in your own privacy notice either.

What we will sign

A data processing agreement (AVV / DPA) is available on request from the address below — ask and you get a copy to review. The Article 28 processor terms are published together with the Terms of Service, which go live with account registration.

Being exact about a document nobody has signed yet: there is no self-service download here, because there is no counter-signed template to download. Write to us and we will send one.

Security, stated as what is on

Claims here are limited to what is enforced today. Where something is built but not switched on, it is not on this page.

Tenant isolation

Every tenant runs in its own Kubernetes namespace — own pods, own database. No shared runtime between customers.

WAF by default

Tivadar Sentinel sits in front of every site as standard, not as a paid add-on.

Encryption

TLS in transit; encryption at rest on the underlying storage.

Backups

Scheduled backups per site — the database and wp-content, so themes, plugins and uploads come back with it — with restore from the dashboard.

What is not here

Stated so nobody has to discover it in a questionnaire: there is no third-party security certification (ISO 27001, SOC 2) and no independent penetration test report. Neither exists yet, and saying so is cheaper than being asked.

Ask us something

Security or data-protection questions, an AVV request, or a supplier questionnaire that needs filling in: privacy@tivadar-cms.cloud

Talk to an engineer