Regtrue uses the following third-party service providers to process data on behalf of our customers. All sub-processors have signed Data Processing Agreements (DPAs) and meet our security requirements.
We update this list at least 30 days before adding new sub-processors. Subscribe to notifications by emailing support@regtrue.com.
| Sub-processor | Purpose | Location | DPA |
|---|---|---|---|
| Web hosting and edge network | EU (Frankfurt) — pinned region | Signed | |
| Database, authentication, storage | EU (Frankfurt) | Signed | |
| Redis caching and rate limiting | EU (Frankfurt) | Signed | |
| JavaScript library CDN (cdnjs.cloudflare.com) | Global edge (EU PoPs preferred) | Signed | |
| Durable background jobs and event orchestration | USA (EU SCCs) | Signed | |
| AI text generation and analysis | USA (EU SCCs) | Signed | |
| AI text generation and OCR | EU | Signed | |
| AI text generation (backup / failover) | USA (EU SCCs) | Signed | |
| Payment processing and subscription billing | EU (Ireland) + USA (EU SCCs) | Signed | |
| Transactional email delivery | USA (EU SCCs) | Signed | |
| Error tracking and monitoring | EU | Signed | |
Google LLC (Tag Manager / Analytics)Consent-gated | Web analytics tag orchestration | USA (EU SCCs) — IP anonymisation enabled | Signed |
Microsoft Corporation (Clarity)Consent-gated | Session replay for UX analysis | USA (EU SCCs) | Signed |
Our AI providers (OpenAI, Google Gemini, Anthropic) process data only for real-time inference:
For sub-processors located outside the EEA (marked as "USA"), we ensure GDPR-compliant transfers through:
If you have questions about our sub-processors or need documentation for your compliance needs: