Legal

次级处理方

还有谁接触平台数据、为了什么、在哪里。类别列在此处;具体名单可按需索取。

Last updated - 2026年8月27日

01

我们如何使用处理方

Running a database platform means engaging other companies for infrastructure and for a handful of business functions. Each one is engaged under a written agreement with the same data-protection obligations we owe you, receives only the data its function requires, and is prohibited from using it for its own purposes.

Nothing below has access to the contents of your database cells. Cell storage and its backup archive stay inside the infrastructure categories, in the European Union.

02

已使用的类别

Listed by the function performed rather than by vendor name, with the data categories that reach each one.

  • 计算与存储基础设施European Union

    Bare-metal servers and attached storage running the database cells, the control plane, and the routing layer. Processes everything stored in a cell, as encrypted-at-rest volumes it does not read.

    数据类别: Database content, platform metadata, operational logs

  • 边缘分发与 DNSGlobal edge, EU origin

    Serves the marketing and documentation sites and terminates TLS for the public web surfaces. Sees request metadata only, never database traffic.

    数据类别: IP address, user agent, requested URL

  • 对象存储European Union

    Holds the continuous backup archive and long-term platform artifacts. Contents are written by the platform and are not readable by the provider in plaintext form.

    数据类别: Backup archives, write-ahead log segments, exports

  • 身份与认证European Union / United States

    Handles sign-in, sessions, multi-factor authentication, and organization membership. We never receive or store passwords.

    数据类别: Name, email address, profile image, authentication metadata

  • 支付与开票European Union / United States

    Acts as merchant of record: takes payment, applies the correct tax, and issues invoices. Card details never reach our systems.

    数据类别: Billing name and email, address for tax, payment and invoice records

  • 事务性邮件European Union / United States

    Delivers account, incident, billing, and support messages. Marketing sends go only to people who asked for them.

    数据类别: Email address, message content

03

具名清单

We publish categories rather than vendor names on the open web, and give the current named list - company, role, processing location, and transfer mechanism - to customers and to anyone running a vendor assessment, on request. Write to us with the subject line "Subprocessor notifications" and you will have it the same working day.

We are aware this is stricter than the common practice of publishing the list outright. If your procurement process requires a public list, tell us: that is a reason to change the policy, and we would rather change it than lose the assessment.

04

变更通知

Ask to be added to the subprocessor change list and you will be told before a new subprocessor is engaged or an existing one is replaced, with at least 30 days' notice where the change is planned rather than forced by an incident.

The notice names the incoming processor, what it will process, where, and on what transfer mechanism.

05

对变更提出异议

If you have a reasonable, data-protection-based objection to a new subprocessor, raise it during the notice period. We will try to offer an alternative; where we cannot, you may terminate the affected service without penalty and export your data - see Data portability and exit.

06

跨境传输

Infrastructure processors operate in the European Union. Identity, payments, and email processors are established in or supported from the United States; those transfers rely on an adequacy decision where one applies, and otherwise on Standard Contractual Clauses with the supplementary measures identified in a transfer risk assessment.