What this page is
A DACH agency answering a supplier questionnaire, or working through NIS2, needs a subprocessor list and a signable agreement as separate documents — not a paragraph inside a privacy policy. This is that page. It says what is true today, including where something does not exist yet.
Subprocessors
Everyone who processes personal data on our behalf. If a provider is not on this list, it receives nothing.
| Provider | Purpose | Location | Status |
|---|---|---|---|
Hetzner Online GmbH All workloads run here, under a data processing agreement. | Hosting and infrastructure | EU — Germany | In use |
Google Ireland Limited Support and general correspondence. Not used for bulk sending. | Business email (Google Workspace) | EU — Ireland | In use |
Mindbaz SAS (Sweego) Delivers subscription confirmations and system notifications. | Email and SMS delivery | EU — France | In use |
Stripe Payments Europe Registration and payment are closed; no payment data has been processed. | Card payments | EU — Ireland | Not in use yet |
KBOSS.hu Kft. Starts with the first invoice, which has not happened. | Electronic invoicing | EU — Hungary | Not in use yet |
AbuseIPDB Manual escalation only: an operator investigating a specific incident looks up an IP address — an IP only, never an email address, and never automatically. | IP reputation lookup, on manual escalation only | United States | In use |
One US recipient, on manual escalation only
Every provider in the serving path is in the EU. The one US entry above receives an IP address, and only when an operator investigating a specific incident looks one up — never automatically, never for the general visitor population, never an email address. Its Art. 46 transfer mechanism is not yet confirmed, and this page would rather say so than leave the row looking settled.
Where the data is
100% EU infrastructure. No US subprocessor in the serving path — the single US recipient is the manual lookup described above, never an automatic one. Analytics are first-party and self-hosted, so there is no third-party tracker to disclose in your own privacy notice either.
What we will sign
A data processing agreement (AVV / DPA) is available on request from the address below — ask and you get a copy to review. The Article 28 processor terms are published together with the Terms of Service, which go live with account registration.
Being exact about a document nobody has signed yet: there is no self-service download here, because there is no counter-signed template to download. Write to us and we will send one.
Security, stated as what is on
Claims here are limited to what is enforced today. Where something is built but not switched on, it is not on this page.
Tenant isolation
Every tenant runs in its own Kubernetes namespace — own pods, own database. No shared runtime between customers.
WAF by default
Tivadar Sentinel sits in front of every site as standard, not as a paid add-on.
Encryption
TLS in transit; encryption at rest on the underlying storage.
Backups
Scheduled backups per site — the database and wp-content, so themes, plugins and uploads come back with it — with restore from the dashboard.
What is not here
Stated so nobody has to discover it in a questionnaire: there is no third-party security certification (ISO 27001, SOC 2) and no independent penetration test report. Neither exists yet, and saying so is cheaper than being asked.
Ask us something
Security or data-protection questions, an AVV request, or a supplier questionnaire that needs filling in: privacy@tivadar-cms.cloud
Talk to an engineer