Subprocessors
Providers and service categories that may process Customer Personal Data for Grydor.
Grydor uses subprocessors only to operate, secure, support, and bill the service. The production Order Form identifies the selected service region and any provider that varies by deployment.
Named platform providers
| Provider | Purpose | Data involved | Location |
|---|---|---|---|
| Cloudflare, Inc. | DNS, DDoS protection, WAF, edge delivery, short-lived device wake routing, and object storage when selected | Network metadata, encrypted traffic, device routing identifiers, and stored artifacts when R2 is selected | Global edge; storage region stated in the Order Form |
| Stripe, Inc. | Subscription checkout, invoicing, tax calculation, payment status, and customer portal | Business contact, customer reference, plan, usage total, invoice, tax, and payment status | United States and other locations described by Stripe |
| Apple Inc. | Apple MDM push, Automated Device Enrollment, Apps and Books, and Apple software catalog services selected by the customer | Device push token, MDM topic, hardware identifier where required, app-license assignment, and catalog request | Apple-operated service locations |
| Microsoft Corporation | Windows Push Notification Services and Microsoft enrollment or identity integrations selected by the customer | WNS ChannelURI, package identity, device-management routing data, and identity claims for enabled integrations | Microsoft-operated service locations |
Deployment-specific providers
The production infrastructure host, transactional email provider, error-monitoring provider, support system, and customer-requested regional service are named in the Order Form before Customer Personal Data is accepted. A customer-configured SMTP, identity, directory, certificate, Syslog, or object-storage destination acts under the customer’s instructions and is not selected by Grydor as a general subprocessor.
Changes and objections
Grydor publishes material additions before use and provides at least 30 days’ notice when required by the DPA. Customers may object on reasonable data-protection grounds during the notice period. Provider removal or a purpose/location change is reflected in a new page version and effective date.
Contact
Questions about data location, provider terms, transfer safeguards, or a planned change may be sent to [email protected].