Legal

Subprocessors

1. About this page

This page lists the third parties — our subprocessors — that process personal data on our behalf to help us deliver the Services to you. We publish it in the interests of transparency and to meet our obligations under Article 28 of the General Data Protection Regulation (GDPR); it is the current, dated list referred to in our Data Processing Agreement (DPA), and it replaces any older “available on request” approach.

A subprocessor is an organisation that we engage to process personal data contained in your Content or Customer Data, or personal data we hold about you as our Customer, in the course of providing the Services. We engage each of them on data-protection terms, and we remain responsible to you for what they do with your data. We should be precise about what those terms are, because they are not the same in every case. Most of the providers below are engaged on the data processing agreement that each of them publishes — we link them all at the end of section 2 — rather than on terms we negotiated individually, and we do not imply otherwise. Where a provider publishes no Article 28 processing agreement at all, the row says so instead of leaving you to assume one exists. And three organisations appear in the table that are not our processors; they are marked as such and explained under it.

The hosting of Customer Data for the Services, and our encrypted backups, take place within the European Union / European Economic Area (EU/EEA). Some processing necessary to deliver and protect the Services takes place outside the EEA or at a global edge — content delivery, TLS termination and edge request logging; our helpdesk, Help Centre and support email; transactional email; and domain registration. Those recipients are identified in the table below, with the transfer mechanism relied on for each. Managed Email is different again (see section 3): those mailboxes live in your own Microsoft 365 or Google Workspace tenant, in the region you choose with that provider, and are not on Maxinodes infrastructure.

Last updated: August 31, 2026. We keep this list current and re-date it whenever it changes (see section 4), and section 5 records what has changed and when.

2. Our subprocessors

Until now this table described each subprocessor by category and function rather than by name. We have changed that, and this version names every one of them. Naming the organisation is the only way you can check where it is established, read its own data-protection terms and its own list of sub-processors, and decide whether you object to it — and the right to object, which our Data Processing Agreement gives you, is worth nothing against a party you cannot identify. Where a commercial term is genuinely confidential we withhold the term, not the identity.

Each row gives the provider and where it is established, what it does for us, where the processing actually takes place, which parts of the Services it touches, the transfer mechanism relied on where the recipient is outside the EEA, and the date it came into use. Where we can evidence which company in a group holds the contract, we name that company; where we cannot, we name the service and the group behind it and say so, because we would rather be vague than publish a registered company name we have not verified. Where a row applies only to certain Services or options — for example only to Managed Services, only where you register a domain through us, or only where you pay an invoice by card or in cryptocurrency — the “Applies to” column says so. Three rows describe organisations that are not our processors at all; they are marked as such and explained under the table.

One distinction runs through the whole table and is worth having in mind before you read it: the websites and data we host for you stay in the EEA — your site is served straight from our servers in the Netherlands and does not pass through the edge network at all — whereas your support correspondence, and the request metadata logged at our edge, do leave it. Each row says which side of that line it falls on.

Subprocessor Purpose of processing Location of processing Applies to Transfer mechanism
Worldstream — our dedicated server, network and data centre
Established in the Netherlands (EU/EEA). The group trades through more than one Dutch company, and we have not verified which of them holds our contract, so we name the provider rather than a registered company name we cannot evidence
In use since July 16, 2026
Supplies the dedicated server, the network capacity and the physical data-centre facility on which all of our systems run, including the servers that hold your Content and Customer Data. It has physical custody of the disks; it has no administrative or logical access to what is on them, and its own published policy states that it plays no active role in relation to the services its customers run. Netherlands (EU) — its own data centres at Naaldwijk. All Services (Self-Managed Services and Managed Services) and the Client Area. None required — the processing takes place in the EEA.
Microsoft — the Azure Front Door service
Microsoft Corporation, the group parent, is established in the United States
In use since August 4, 2026
Content delivery and security at Microsoft’s network edge for the hostnames we publish: it terminates the encrypted connection, caches our public marketing pages, and screens incoming requests against a blocklist and a rate limit. It processes your IP address, your browser user-agent string, the address you requested and the technical details of the connection, and writes them to access and security logs. It sets no cookies. Global anycast edge. Each request is handled at whichever Microsoft edge location is nearest to the visitor, which may be outside the EEA; Microsoft excludes this service from its EU Data Boundary for exactly that reason. Our copy of the resulting logs is stored in Microsoft’s West Europe region (Netherlands) and kept for 30 days. The Maxinodes website, the Client Area at my.maxinodes.com and our statistics dashboard at stats.maxinodes.com. Not the websites we host for you — those are served straight from our servers in the Netherlands and do not pass through this edge network at all. Only our public marketing pages are cached; Client Area responses are never cached. Standard Contractual Clauses, under Microsoft’s Products and Services Data Protection Addendum. Microsoft Corporation is additionally certified under the EU–US Data Privacy Framework.
BunnyWay d.o.o.
Established in Slovenia (EU/EEA)
In use since July 26, 2026
Operates the authoritative DNS for your domain’s zone behind our nameservers ns1.maxinodes.com and ns2.maxinodes.com, and powers the record editor in your Client Area. It holds the contents of your zone — your hostnames and your A, AAAA, MX and TXT records, including SPF, DKIM and DMARC entries, which reveal your domain and the other providers you use — the zone created when your order is provisioned, and DNS query metadata. Those queries reach it from recursive resolvers, not from identifiable visitors. Slovenia and the wider EU; the provider states that it is established in Slovenia and processes most data within the European Union. DNS answers are served from a global anycast network, so a query arriving from a resolver outside the EEA is answered outside the EEA. All hosting orders — DNS for the domains you point at us. None required of us — our contract is with an EEA establishment. The provider’s own onward arrangements are covered by its data processing agreement and its published sub-processor list.
Microsoft — the Azure DNS service
A Microsoft service, as with the edge row above; Microsoft Corporation, the group parent, is established in the United States
In use since August 4, 2026
Not a processor of Customer Data
Answers DNS queries for the domains Maxinodes itself operates, such as maxinodes.com. This is not your domain’s DNS — customer zones are with BunnyWay d.o.o. in the row above and did not move. The zone files hold hostnames and IP addresses; on Microsoft’s own published position this service handles no customer personal data, and we have not switched on query logging. Global anycast Microsoft DNS. Our own corporate domains only. It plays no part in your domains or your hosting. No customer personal data is processed here. Any Microsoft transfer is in any event covered by the Standard Contractual Clauses in Microsoft’s data protection addendum.
Backblaze, Inc.
Established in the United States
In use since July 26, 2026 (current EU storage region)
Stores our off-site backup copies. Backups are encrypted on our own servers before they are uploaded, with a key we keep ourselves and never give to the provider, so it holds ciphertext it has no means to read: no file, database record, message or password reaches it in a readable form. What it can see is the backup metadata — archive and snapshot names, timestamps, sizes and the network address our backup server connects from — together with our own account and billing details. Amsterdam, Netherlands (EU/EEA) — our storage sits in the provider’s EU Central region, which is also where it holds the account data for it. Administrative control of the service nevertheless rests with a United States company. All Services — backups of the infrastructure on which the Services run. Not reachable by customers. Standard Contractual Clauses, under the provider’s data processing agreement for EEA and EU residents. It is separately certified under the EU–US Data Privacy Framework, but the contract we rely on is the Clauses.
MicrosoftMicrosoft 365 (Exchange Online), in our own tenant
Microsoft Corporation, the group parent, is established in the United States
In use since June 14, 2026
Hosts our own mailbox and the distribution groups behind support@, privacy@ and abuse@maxinodes.com. Mail you send to any of those addresses arrives here first and is then forwarded to our helpdesk in the row below, so everything in the message passes through — your address, what you wrote, and anything you attached. European Union / EFTA. Microsoft commits to store and process this within the EU and EFTA under its EU Data Boundary. That commitment has documented exceptions: its global security operations, some support cases escalated to engineers, limited directory data, and network routing that can occasionally take traffic outside the boundary. All Services — every email sent to one of our published addresses, including support requests, data-protection requests and abuse reports. For the documented exceptions above: Standard Contractual Clauses, under Microsoft’s Products and Services Data Protection Addendum. Microsoft Corporation is additionally certified under the EU–US Data Privacy Framework.
Zendesk, Inc.
A Delaware corporation established in the United States
In use since August 6, 2026
Runs our helpdesk. It handles support tickets and their full history, live chat and messaging, our Help Centre at support.maxinodes.com, every enquiry sent through the contact form on our website, and all mail forwarded to it from support@, privacy@ and abuse@maxinodes.com — which means data-protection requests together with any identity evidence sent with them, and abuse and copyright correspondence about people who are not our customers. It processes your name, your email address, what you write, and any files you attach. It engages its own sub-processors, several of which are in the United States. United States (place of establishment). Service Data for our account is currently held in the provider’s Europe (Ireland) region, but we have not obtained a contractual commitment to that region and the provider reserves the right to move account data between regions without notice. Personal data reaches the United States in any event, through the provider’s own operations and its named United States sub-processors. All Services (support and communications). Also anyone who writes to us without being a customer. The safeguards are those in Zendesk’s published data processing agreement: Binding Corporate Rules approved by the Irish Data Protection Commission, and the European Commission’s Standard Contractual Clauses. Zendesk, Inc. is additionally certified under the EU–US Data Privacy Framework. Our account is on Zendesk’s published online terms; we have not negotiated separate terms with it.
NOWPayments — the hosted cryptocurrency checkout
Operated under the merchant terms published at nowpayments.io, which name a company established in Saint Vincent and the Grenadines. Those terms and that provider’s own privacy policy name different entities, so we cannot tell you with certainty which company you are dealing with, and we will not publish a registered name we have not verified
In use since July 27, 2026
Not our processor — see the note below
Takes payment of Client Area invoices in cryptocurrency, on its own hosted checkout page. We send it only the amount, the currency and the invoice number — no name, no email address, no postal address and no account identifier. Everything else it collects, it collects from you directly on its own page and under its own privacy policy: your IP address, your device and browser details, cookies, and your wallet and transaction data. It does that on its own account rather than on our instructions, which is why we do not describe it as our processor. Not disclosed by the provider. Only where you choose to pay an invoice in cryptocurrency. None. Saint Vincent and the Grenadines is not covered by an EU adequacy decision; the provider offers no Standard Contractual Clauses and no Article 28 processing agreement; and its terms state that by accepting them you consent to your personal data being processed and exported outside the jurisdiction you are in. We would rather tell you that plainly before you start a payment than imply a safeguard that does not exist.
Whop — the hosted card and local-payment checkout
Its terms of service name Whop Inc., established in the United States. Its seller terms name no company at all, and a second, undated set of terms that no page on its site links to names three further companies, one of them in the EU. No Whop page states which of them a European seller contracts with, and none publishes a registration number, so we name the company its live terms name and tell you that the position is unsettled
In use since August 27, 2026
Not our processor — see the note below
Takes payment of Client Area invoices by card, Apple Pay, Google Pay, PayPal, iDEAL, Bancontact and SEPA Direct Debit, on its own hosted checkout page. We send it only the amount, the currency and the invoice number. Your card details never reach us. What you type on its page — your email address, your billing address and your card — you give to Whop directly, under its own privacy policy, and it also collects your IP address, device and browser details and cookies, creates a Whop account for you, and emails you its own order confirmation. It then returns to us, and we keep in our billing records, your name, email address, billing address, telephone number where you gave one, the brand and last four digits of your card, and the fraud-risk score it assigned. Whop also uses what it collects for its own advertising and states that it may share or sell identifiers and usage data to ad networks, analytics providers and social networks. United States, and its own onward providers worldwide. It offers no EU data-residency option. Only where you choose to pay an invoice by card or another method on the Whop checkout. None that runs to you. The United States is not covered by an EU adequacy decision; Whop is not certified under the EU–US Data Privacy Framework; and it offers us neither Standard Contractual Clauses nor an Article 28 processing agreement. The one commitment it does make is in its own privacy policy and is owed to you rather than to us: for its own onward transfers of EEA personal data it undertakes to use clauses approved by the European Commission “or another measure”. It publishes no sub-processor list, and names no EU Article 27 representative and no data protection officer. Its seller terms mention a “Seller Data Sharing Addendum” once, in a sentence that links to nothing and that we have never been shown. We would rather tell you that plainly before you start a payment than imply a safeguard that does not exist.
Postmark — the transactional email service of the ActiveCampaign group
Established in the United States
In use since June 3, 2026
Sends the automated account emails from our billing system — invoices, order confirmations and password resets. It processes your name, your email address, the invoice or order reference, and the contents of the message. United States. The provider offers no EU data-residency option. Transactional email from the Client Area. Not support email, not marketing email, and not the mailboxes we administer. Standard Contractual Clauses under Postmark’s data processing agreement, together with certification under the EU–US Data Privacy Framework held by ActiveCampaign, the group it belongs to, whose certification names Postmark as a covered service.
Key-Systems GmbH, trading as CentralNic Reseller
Established in Germany (EU/EEA)
In use since June 17, 2026
Our domain registrar channel: it registers, transfers and renews the domains you order through us, and holds the registrant, administrative, technical and billing contact records for them — name, organisation, postal address, email address and telephone number — along with the domain names themselves, registrant-verification correspondence, WHOIS and RDAP disclosure, and abuse correspondence. Germany (EU) — the provider states that it processes personal data in its data centres in Germany. Registrant data is then passed on to the registry that runs your domain extension, to a data-escrow agent and, for generic extensions, to ICANN. Some of those recipients are outside the EEA. Only where you register, transfer or renew a domain through us, and the domain tools in your Client Area. None required for the provider itself, which is established in the EEA. The onward disclosures to registries, escrow agents and ICANN are made under ICANN and registry rules that apply to every domain registration whoever you buy it from; they are not made under our contract, and we cannot apply our own safeguards to them.
UptimeRobot s. r. o.
Established in Slovakia (EU/EEA)
In use since July 21, 2026
Probes our public hostnames from outside our own network, so that we hear about an outage from something other than the thing that is down, and hosts the public Status Page. Most of what it holds is not personal data — addresses, response codes and response times. It also holds our own account and billing details, the email addresses and telephone numbers of the people we alert, and the email address of anyone who subscribes to Status Page updates, including people who are not customers. Slovakia (EU). The provider’s data processing agreement names the European Union as the primary location of processing and the United States as a secondary one, and its own sub-processors include United States providers for email, SMS and error logging. Our operational monitoring and the Status Page. It does not process the Customer Data we host. Standard Contractual Clauses under the provider’s data processing agreement, with the UK Addendum and a Swiss variant. The provider does not claim certification under the EU–US Data Privacy Framework, and we do not rely on one.
MaxMind, Inc.
Established in the United States (51 Pleasant Street #1020, Malden, Massachusetts)
In use since August 28, 2026
Screens orders placed in the Client Area for fraud, using its minFraud Insights service. When you place an order we send it your IP address, your email address, the billing name, address and country you entered and your telephone number where you gave one, together with the amount and currency of the order; it returns a risk score and the reasons behind it, which we keep with the order record. No card details are sent, because none reach us — you enter those on the payment provider’s own page, never on ours. Unlike the two payment providers below, MaxMind does this on our instructions and for our purposes, which is what makes it our subprocessor and them not. United States. Every order placed through the Client Area. It does not process the Customer Data we host, and it is not involved after an order is accepted. Standard Contractual Clauses, under the provider’s published data processing addendum. It is separately self-certified under the EU–US Data Privacy Framework, but the contract we rely on is the Clauses.

Not every subprocessor processes personal data for every Customer. Which of them are involved depends on the Services you order and the options you choose — the registrar only matters if you buy a domain through us, and the payment provider only to the extent that you pay us through the Client Area.

Three rows are in the table although they are not our processors. We have included them because leaving them out would give you a less complete picture, not a more accurate one. Microsoft Azure DNS answers queries for our own corporate domains and holds no Customer Data; it is there so you can see that it is a different thing from the DNS we run for you. NOWPayments and Whop each collect payment data from you directly on their own checkout pages, for their own purposes and under their own policies, which makes each of them an independent controller rather than someone acting on our instructions; they are there because your data reaches them when you pay us. Whop’s own terms describe it as a “payment processor” and as the merchant of record. That is the language of the card networks and of tax law, and we mention it so you are not misled by it: it does not mean Whop is a processor in the data-protection sense, and we do not claim it acts on our instructions.

One further point of accuracy, about our data centre. Worldstream supplies the hardware, the network and the building. Administrative control of the servers is ours alone, and it has no logical access to what is stored on them. It does not publish an Article 28 processing agreement, and we do not claim one for it; we list it because it has physical custody of the disks your data sits on, and you are entitled to know who that is.

Each provider publishes its own data-protection terms, and several publish their own list of sub-processors, so you can follow the chain further than this page can take it:

Meta — a joint controller, not a subprocessor

If — and only if — you opt in to the Marketing category in our cookie banner, we load the Meta pixel and send Meta the advertising-measurement data described in our Privacy Policy and Cookie Policy. Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland, does not appear in the table above, and that is deliberate: it is not our subprocessor. For that data we and Meta are joint controllers under Article 26 GDPR. We set that out here because Article 26(2) requires the essence of the arrangement to be made available to you, and a subprocessor table is the wrong place to describe a relationship that is not subprocessing.

The arrangement is narrower than it sounds. The joint controllership covers only the collection of that measurement data on our website and its transmission to Meta. What Meta does with it afterwards is Meta’s own processing, for Meta’s own purposes, under Meta’s own terms; it forms no part of the joint arrangement, we have no control over it, and we do not describe it here, because it is not ours to describe. Meta’s own onward transfers are likewise Meta’s to account for.

Because we are joint controllers, Article 26(3) lets you exercise your data-protection rights against either of us. Write to privacy@maxinodes.com and we will deal with what is ours and pass on what is not; you may also go to Meta directly. The simplest control of all is the Cookie settings button at the top of our Cookie Policy: decline the Marketing category and nothing is collected or sent at all — nothing else on this site depends on it.

3. A note on Managed Email

When you purchase Managed Email, Microsoft or Google acts as your service provider in respect of those mailboxes, which sit in your own tenant. This is different in kind from everything in the table above, which is why it is described here rather than as a row: you accept Microsoft’s or Google’s own customer agreement for that tenant, and our role is that of agent and administrator — we arrange and pay for the subscription in your name and we hold an ordinary administrator account on your tenant so that we can administer it for you. We do not act as a controller or a processor of the mail inside those mailboxes. What we hold is the order and licence-assignment record in your Client Area.

As a result, the personal data processed within those mailboxes is governed by Microsoft’s or Google’s own terms, data-processing agreements and subprocessor lists, and that processing is outside the scope of our SLA and of our commitment to host Customer Data and store encrypted backups within the EU/EEA. Any international transfer of your mailbox data is made by Microsoft or Google under their own transfer mechanisms, not by us. You should review your chosen provider’s own documentation for the full list of subprocessors and processing locations that apply to your tenant.

4. Changes to this list

We add, replace and remove subprocessors as our Services evolve. Every change is recorded in section 5, with the date it actually took effect.

Where we intend to add or replace a subprocessor that processes personal data on our behalf, we will tell you at least 30 days before the change takes effect where that is practicable, and otherwise as soon as reasonably practicable afterwards. We will give that notice by email and through the Client Area, and we will publish an updated, re-dated version of this page. Those are two different things, and the previous version of this section treated them as one: it said notice would be given “by posting an updated, re-dated version of this page”, which cannot work, because the page can only be updated once the change is known. This page is the record of a change. The email and the Client Area notice are the notice of it. If we ever have to replace a provider at short notice to keep the Services running or to deal with a security problem, we will make the change first and tell you immediately afterwards, with the reason.

If you reasonably object to a new subprocessor on legitimate data-protection grounds, tell us — within the notice period, or within 30 days of our notice where the change has already taken effect — and we will work with you in good faith to address your concern, as set out in our Data Processing Agreement. The DPA also explains the rights and remedies available to you, including termination, if a reasonable objection cannot be resolved.

Three of the changes in section 5 went live before any notice was given, which is not what this section promised. We would rather say so here than let you find out by comparing dates. Those changes are treated as notified on the date this version was published, and the objection process above is open to you from that date on the same terms as if the notice had been given in advance.

To be notified of changes to this list, make sure the contact details in your Client Area are up to date. The version in force at any time is the one published at this URL, identified by the version label and “Last updated” date at the top of the page.

5. Change history

The changes below took effect on the dates shown. This page was rewritten on August 7, 2026 to reflect all of them and to name each provider individually rather than by category. Where a change would attract the notice described in section 4, the notice period runs from the date this version was published, and the objection process in section 4 and in clause 7 of our Data Processing Agreement is available to you from that date.

Took effect Change
July 26, 2026 Authoritative DNS for customer domains moved to BunnyWay d.o.o. (Slovenia, EU), operating behind our own ns1.maxinodes.com and ns2.maxinodes.com nameservers. A DNS zone is now created automatically for each hosting order, with a self-service record editor in the Client Area.
August 4, 2026 Our own websites and the Client Area were placed behind Microsoft Azure Front Door, which terminates TLS, caches our public marketing pages and screens incoming requests at Microsoft’s global edge. Authoritative DNS for the maxinodes domains themselves moved to Azure DNS. Customer websites were not affected: they are still served directly from our servers in the Netherlands and do not pass through that edge.
August 6, 2026 Support moved from the helpdesk we ran on our own infrastructure to Zendesk, Inc. (United States). This covers support tickets, live chat, the Help Centre at support.maxinodes.com, contact-form enquiries, and inbound mail to support@, privacy@ and abuse@maxinodes.com.
August 7, 2026 This page rewritten to Version 2.0: every subprocessor is now named, with its legal entity, country of establishment, purpose, location of processing, the Services it applies to and, for recipients outside the EEA, the transfer mechanism relied on.
August 27, 2026 Card and local payment methods went live through Whop, alongside the existing cryptocurrency option: card, Apple Pay, Google Pay, PayPal, iDEAL, Bancontact, SEPA Direct Debit and EU bank transfer. Whop was added to the table above as an independent controller rather than a subprocessor, for the reason given under it. Neither payment provider stores a payment method, so nothing is charged automatically and every renewal invoice is still paid by hand.
August 28, 2026 Order fraud screening began through MaxMind, Inc. (United States), which became necessary once payments could be reversed. It is a subprocessor and is listed as one above. This change went live before this page recorded it; under section 4 it is treated as notified on the date this version was published.
August 31, 2026 Resold Email renamed to Managed Email, and section 3 restated. The Microsoft 365 or Google Workspace subscription is taken out in the customer’s own name; we arrange it, pay for it on the customer’s behalf and recover what we paid, and we hold an ordinary administrator account on the tenant rather than delegated administrative access. No subprocessor was added or removed, and the mailboxes were always in the customer’s own tenant.

Contact

Questions about our subprocessors: privacy@maxinodes.com.

By post: Maxinodes Ltd, 1 Ballycoolin Road, Dublin 15, Ireland.

Mail sent to that address reaches our own Microsoft 365 tenant in the EU and is then forwarded into our helpdesk platform, operated by Zendesk, Inc., a Delaware corporation established in the United States. Your message, anything attached to it and our correspondence about it are stored there. Our account data is currently held in its Europe (Ireland) region, but we have no contractual commitment to that region, and the provider and its named United States sub-processors can reach that data from the United States — so it is processed outside the EEA. If you would rather your message did not pass through a third-party helpdesk — for example because it includes identity documents, or because it names someone else — write to us by post at the address above, or email billing@maxinodes.com, which reaches us directly.