Sub-processors
Version 1.1.0 — as of 25 April 2026
This is a courtesy English translation. The legally binding version is the German Sub-processors list; in the event of any discrepancy, the German version prevails.
This list names all sub-processors (Art. 28 GDPR) to which Kikidori transmits personal data or with which Kikidori data is stored.
In brief: Single-vendor stack. All processing takes place at netcup GmbH (Karlsruhe, DE). No transfers to third countries take place. Glitchtip is self-hosted and is not a separate sub-processor.
1. Active sub-processors
1.1 netcup GmbH — VPS hosting
| Provider | netcup GmbH |
|---|---|
| Registered office | Daimlerstraße 25, 76185 Karlsruhe, Germany |
| Purpose | VPS hosting (compute, storage, network) for the entire Kikidori application |
| Data categories | all categories listed in the privacy policy (section 4) |
| DPA | Standard DPA (Data Processing Agreement under Art. 28 GDPR) with netcup |
| Third country | no (EU/DE) |
| Sub-processors | netcup-owned infrastructure; no further sub-processors |
| Safeguards | ISO 27001 certified, Tier-3 data center, physical access control |
| Website | https://www.netcup.de |
| Added | since 2026-04 (production launch) |
1.2 netcup GmbH — transactional email (SMTP)
| Provider | netcup GmbH (same legal entity as 1.1) |
|---|---|
| Registered office | Daimlerstraße 25, 76185 Karlsruhe, Germany |
| Purpose | sending transactional emails (confirmations, password reset, notifications) |
| Data categories | email address, subject, message content |
| DPA | included in the hosting DPA (1.1) |
| Third country | no (EU/DE) |
| Sub-processors | none |
| Safeguards | TLS transmission; SPF/DKIM configured for auth emails |
| Added | since 2026-04 |
1.3 netcup GmbH — domain registrar + DNS
| Provider | netcup GmbH (same legal entity as 1.1) |
|---|---|
| Registered office | Daimlerstraße 25, 76185 Karlsruhe, Germany |
| Purpose | domain registration and authoritative DNS for kikidori.com and kikidori.de |
| Data categories | technical DNS records; domain owner data in accordance with ICANN/Denic requirements |
| DPA | included in the hosting DPA (1.1) |
| Third country | no (EU/DE) |
| Sub-processors | ICANN/Denic centralized registry functions are required by regulation, not independent processing operations |
| Added | since 2026-04 |
2. Self-operated components (not sub-processors)
2.1 Glitchtip — error tracking
Glitchtip runs as a self-hosted instance on the netcup infrastructure (1.1). No data is transmitted to third parties. Not a separate sub-processor within the meaning of Art. 28 GDPR. Data remains within the netcup DPA umbrella.
2.2 Self-hosted Supabase stack
The entire Supabase stack runs as a self-hosted open-source installation on netcup infrastructure. There are no connections to Supabase Cloud or other cloud services (AWS, GCP, Azure, Vercel, Cloudflare). Supabase Inc. is not a sub-processor.
3. Not used
We deliberately do not use any of the following categories of service providers:
- Advertising networks / behavioral advertising platforms
- Third-party analytics SDKs (Google Analytics, Mixpanel, Amplitude or similar)
- Social media pixels (Facebook, TikTok, LinkedIn)
- External font CDNs (Google Fonts or similar)
- External chatbots or AI services with third-country transfer
4. Planned / in preparation
4.1 Premium payment provider — still open
With the Premium launch, a payment provider will be integrated. Options currently under evaluation:
- Stripe (USA, SCC required, third-country relevance)
- Paddle (UK/IE, reseller model)
- Mollie (Netherlands, EU-only)
- SEPA direct mandate (national, no additional sub-processor)
Before being added, this list will be updated, a DPA concluded, and, if there is third-country relevance, a transfer risk assessment (TIA) carried out. The privacy policy will be adapted with a lead time of 14 days.
5. Change workflow
When a sub-processor is added or changed:
- At least 14 days before it takes effect, we inform registered caregivers by email.
- Caregivers can object to the change by deleting the account before the effective date.
- Update of this document with a version bump (semver).
- Update of the privacy policy (section 8.2) with the same version bump.
6. History
| Version | Date | Change |
|---|---|---|
| 1.0.0 | 2026-04-16 | Initial creation; netcup as hosting provider, individual areas marked as "under review" |
| 1.1.0 | 2026-04-25 | Full single-vendor consolidation documented: netcup for hosting + SMTP + DNS; Glitchtip noted as self-hosted; Premium payment provider options listed |
7. Contact
Questions about this list: datenschutz@kikidori.com