Sign in Get free forever Get started

Legal

Subprocessors

Third parties that process data on behalf of Clavitor. All are GDPR-compliant and contractually bound to data protection standards equivalent to our own.

Last updated: July 3, 2026

Resilience by design

Clavitor is built to keep serving you regardless of any single provider, region, or vendor failing. We deliberately spread trust across independent companies, jurisdictions, and ownership chains — and cut every dependency we can. Where a provider is load-bearing, it has a fail-over that shares nothing with it: no common owner, country, or network. The breadth of this list is the point — engineered redundancy, not vendor sprawl.

  • Central-I and Central-II share nothing — Leaseweb (Amsterdam, Dutch-owned) and ABLENET (Osaka, Japanese-owned) have no common provider, geography, or failure domain.
  • Outgoing email fails over — Google handles primary delivery of your six-digit verification codes, with Proton as an independent backup, so codes still reach you if one is down.
  • Your vault is replicated — stored encrypted at the POP nearest you, with backups to geographically distant POPs.
01
Infrastructure & hosting

Clavitor operates 22 Points of Presence (POPs) across six continents. Your vault data is stored encrypted at the POP nearest to you, with backups to geographically distant POPs for resilience. See the Looking Glass for the complete list of POPs with locations and latency.

ProviderPOPsScopeData typeCertifications
The Constant Company, LLC (Vultr)
319 Clematis Street, West Palm Beach, FL, USA
5New York, Mexico City, Amsterdam, Seoul, JohannesburgEncrypted vault dataSOC 2 Type II, ISO 27001, PCI DSS, GDPR
Akamai Technologies, Inc. (Linode)
145 Broadway, Cambridge, MA, USA
6Dallas, Toronto, São Paulo, Mumbai, Tokyo, SydneyEncrypted vault dataSOC 2 Type II, ISO 27001, PCI DSS, GDPR
UpCloud Ltd
Aleksanterinkatu 15 B, 00100 Helsinki, Finland
4Silicon Valley, London, Stockholm, SingaporeEncrypted vault dataISO 27001, PCI DSS, GDPR
Webrain OÜ (is*hosting)
Endla 4, 10142, Tallinn, Estonia
6Bogotá, Zürich, Istanbul, Hong Kong, Dubai, AlmatyEncrypted vault dataSOC 2 Type II, ISO 27001, PCI DSS, GDPR
SiteHUB Agency Ltd
Unit 6, Royal Pine Estate, Orchid Road, Lekki, Lagos, Nigeria
1LagosEncrypted vault dataTier III, SOC 2 Type I (Rack Centre, Lagos)
Leaseweb Netherlands B.V.
Luttenbergweg 8, 1101 EC Amsterdam, Netherlands
--Central-I (primary)Administrative operations, billing infrastructureISO 27001, PCI DSS, SOC 1, GDPR
K&K Corporation (ABLENET)
2-8-19 Ebisu-nishi, Naniwa-ku, Osaka 556-0003, Japan
--Central-II (fail-over)Administrative operations, billing infrastructure (fail-over)ISO 27001
Hivelocity, Inc.
Tampa, FL, USA
--Platform servicesPlatform operations — no vault dataSOC 2 Type II, PCI DSS, HIPAA, GDPR
Cloudflare, Inc.
101 Townsend Street, San Francisco, CA, USA
--Global DNS resolutionDomain resolution only — no vault dataSOC 2 Type II, ISO 27001, GDPR
02
Payment processing
ProviderFunctionData processedCertifications
Paddle.com Market Ltd
Judd House, 18-29 Mora Street, London, UK
Subscription billing, payment processingPayment method (tokenized), billing address, invoice dataPCI DSS Level 1, SOC 2 Type II, GDPR
03
Communications & services
ProviderFunctionData processedCertifications
Google LLC
1600 Amphitheatre Parkway, Mountain View, CA, USA
Transactional email — primary (six-digit verification codes, vault notifications)Email address, one-time verification codes, vault-related notificationsISO 27001, SOC 2 Type II, GDPR
Proton AG
Route de la Galaise 32, Plan-les-Ouates, Geneva, Switzerland
Transactional email — independent fail-overEmail address, one-time verification codes, vault-related notificationsGDPR, Swiss FADP
Cloudflare, Inc.
101 Townsend Street, San Francisco, CA, USA
DNS resolutionDomain queries only — no vault data ever touches CloudflareSOC 2 Type II, ISO 27001, GDPR
04
What we don't use

We deliberately avoid common subprocessors that compromise privacy:

  • No Google tracking or embeds: No Analytics, no Fonts, no reCAPTCHA, no Firebase — Google is used only for outbound transactional email, never tracking and never embedded in the product
  • No Meta/Facebook: No tracking pixels, no social plugins
  • No third-party CDNs: All assets served from our own POPs (Cloudflare is DNS-only, never proxy/CDN)
  • No marketing platforms: No Mailchimp, HubSpot, or similar
  • No cloud logging: Logs stay within our infrastructure
05
Updates

We notify all active subscribers 30 days before adding any new subprocessor. For critical security updates, shorter notice may apply with immediate notification.

Last updated: July 3, 2026