Legal

Subprocessors

Last updated 2026-08-16

The list is short on purpose. Because age checks carry no identity data, very little personal data exists to hand to anyone. These are the external services that process personal data on our behalf:

Provider Location What it processes
Hetzner Online GmbH Germany (servers in Helsinki, Finland) Hosting of the entire service, including databases and backups. All customer and account data lives here, inside the EU. Our DPA with Hetzner is concluded (2026-08-13); the executed copy and the TUV Rheinland audit report of their data centres are confidential and available on request. Their DPA template (PDF) · Their security measures (PDF)
Resend, Inc. EU (Ireland region); provider incorporated in the United States Transactional email (account invitations) only, and only when email sending is enabled. Processes recipient email addresses, in Resend's EU region, so this data does not leave the EU either. The provider is a US company, so their EU-US Data Privacy Framework certification and the EU standard contractual clauses in their DPA remain in place to cover any residual access from the parent. Their DPA · Their subprocessors

Run by us, not subprocessors

Website analytics (Umami) and error monitoring run on our own infrastructure in the EU. They involve no third party.

Changes

Before adding or replacing a subprocessor we update this page and email customers at least 14 days in advance, so there is time to object. Questions to hello@tessio.eu.