Subprocessors and platform recipients
Providers and platform recipients with their contracting entities and transfer safeguards. Effective 1 September 2026.
Infrastructure subprocessors
OVHcloud — used for infrastructure hosting, PostgreSQL, private object storage, backups, and content delivery. Status: used for production hosting, database, and private media storage. Contracting entity: OVH GmbH, Saarbrücken, Germany (OVHcloud group). Data region: European Union data centres. DPA: data processing agreement incorporated in the OVHcloud service contract. Transfer safeguards: processing inside the EU; any OVHcloud support access from outside the EU is covered by OVHcloud's Standard Contractual Clauses.
Zoho/ZeptoMail — used for transactional account, security, invitation, support, billing, and publishing email. Status: used for transactional email. Contracting entity: Zoho Corporation B.V., Utrecht, Netherlands (EU data centre). Data region: European Union. DPA: data processing addendum incorporated in the Zoho service terms. Transfer safeguards: EU data centre; remote support access is governed by Zoho's Standard Contractual Clauses.
Stripe — used for checkout, subscriptions, invoicing, fraud prevention, and payment recovery. Status: used for checkout, subscriptions, and invoicing. Contracting entity: Stripe Payments Europe, Limited, Dublin, Ireland. Data region: European Union with Stripe group processing in the United States under the EU-US Data Privacy Framework. DPA: Stripe Data Processing Agreement incorporated in the Stripe Services Agreement. Transfer safeguards: EU-US Data Privacy Framework certification of Stripe, Inc. and Standard Contractual Clauses.
User-selected social-platform recipients
Meta Platforms Ireland Limited (Instagram) — status: used when you connect an Instagram professional account. Receiving entity: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland; Meta Platforms, Inc. (United States) under the EU-US Data Privacy Framework. Transfer safeguards: EU-US Data Privacy Framework and Meta's Standard Contractual Clauses.
TikTok Technology Limited (TikTok) — status: used when you connect a TikTok account. Receiving entity: TikTok Technology Limited, Dublin, Ireland and TikTok Information Technologies UK Limited, London; group companies outside the EEA may access data under TikTok's transfer safeguards. Transfer safeguards: European Commission Standard Contractual Clauses in TikTok's data processing terms plus TikTok's documented supplementary measures. Transfer assessment: Selfpost relies on the Standard Contractual Clauses and supplementary measures above; information about the transfer assessment is available from the privacy contact.
Google Ireland Limited (YouTube) — status: used when you connect a YouTube channel. Receiving entity: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Google LLC (United States) under the EU-US Data Privacy Framework. Transfer safeguards: EU-US Data Privacy Framework and Google's Standard Contractual Clauses.
When enabled, these destinations receive content only after a user connects an account or instructs publication or analytics. Data can include platform identity, permissions, media, captions, settings, disclosure and audience choices, post identifiers, processing status, and analytics. They generally act under the user's separate platform relationship rather than as ordinary hosting subprocessors.
Changes and objections
Business customers covered by the DPA receive reasonable advance notice of a new subprocessor by email or durable account notice and may object on reasonable data-protection grounds within 14 days. Emergency replacements required for security or availability may be notified as soon as reasonably possible.
Questions, current entity or region details, and safeguard requests can be sent to [email protected].