Back to Security

Security Document

Sub-processor List

The third-party services that process data on our behalf to deliver Simple Commenter, where they operate, and what they handle.

Ander Digital OÜ Document Version: 1.0 Effective Date: March 5, 2026 Last Reviewed: March 5, 2026 Owner: Aleksander Kaaberma, CEO / Information Security Officer


1. Purpose

This document lists all third-party service providers (sub-processors) used by Ander Digital OÜ in the delivery of the Simple Commenter SaaS platform. It includes details on the data each provider processes, their geographic location, and their security certifications.

2. Sub-Processors with Data Access

ProviderPurposeData ProcessedLocationCertificationsDPA
MongoDB Atlas (MongoDB, Inc.)Database hostingUser accounts, domains, comments, configuration, email logsEU regionSOC 2 Type II, ISO 27001, HIPAA, GDPRYes
Hetzner Online GmbHObject storage (S3-compatible)Uploaded files, screenshots, attachmentsEU (Germany)ISO 27001, GDPRYes
Vercel Inc.Application hosting, CDN, serverless functionsApplication code, API request/response data, function logsGlobal CDN, EU data processingSOC 2 Type II, GDPRYes
Upstash Inc.Redis cacheComment cache data, rate limiting counters, session tokensEU regionSOC 2 Type II, GDPRYes
Stripe Inc.Payment processingCustomer IDs, subscription status, payment metadata (no card data stored by us)US/EUPCI DSS Level 1, SOC 2 Type II, ISO 27001, GDPRYes
Twilio SendGridEmail deliveryRecipient email addresses, email content (notifications, magic links)USSOC 2 Type II, ISO 27001, GDPRYes
GitHub Inc.Source code hosting, CI/CDSource code, deployment triggersUSSOC 2 Type II, ISO 27001, GDPRYes
Better Stack Inc.Log management and monitoringApplication logs, API request logs, serverless function logsEU (Nuremberg, Germany)SOC 2 Type II, GDPRYes

3. Third-Party Integrations (Customer-Initiated)

These integrations are optionally configured by customers and process data only when enabled:

ProviderPurposeData Shared (when enabled)LocationNotes
Slack Technologies (Salesforce)Comment notificationsComment text, user name, status, priority, screenshot URLsUSOAuth-based; customer configures channel
Trello (Atlassian)Task tracking syncComment text, attachments, status, repliesUS/AUTwo-way sync; customer provides API token
Custom WebhooksOutbound notificationsComment data, status updates, repliesCustomer-definedCustomer configures endpoint and auth

4. Domain Registrar and DNS

ProviderPurposeData ProcessedLocation
Domain registrarDNS hostingDNS records only (no customer data)Varies

5. Review Process

  • This list is reviewed quarterly and updated when providers change.
  • New sub-processors are evaluated for security certifications and GDPR compliance before onboarding.
  • Customers are notified of material changes to this list.
  • DPAs are verified and renewed as needed.

6. Data Flow Summary

User Browser
    |
    | (HTTPS/TLS 1.2+)
    v
Vercel (Application Hosting, EU CDN)
    |
    |---> MongoDB Atlas (EU) -- User data, comments, config
    |---> Hetzner S3 (EU) -- File uploads, screenshots, attachments
    |---> Upstash Redis (EU) -- Cache, rate limits
    |---> SendGrid (US) -- Email notifications
    |---> Stripe (US/EU) -- Payment processing
    |---> Better Stack (EU) -- Log management
    |
    |---> [Optional, customer-initiated]
          |---> Slack -- Comment notifications
          |---> Trello -- Task sync
          |---> Webhooks -- Custom endpoints

Approval: Aleksander Kaaberma, CEO / Information Security Officer Date: March 5, 2026