1. Current register
This is the register referenced by our Data Processing Agreement. It lists the providers that may process Customer Personal Data on our instructions, and the role each performs. The Privacy Policy describes the same inventory from the perspective of an individual whose information we handle.
A provider appears here because it is part of operating the service, not because every customer’s data reaches it. Which providers actually handle a given customer’s data depends on the features that customer uses.
- Cloudflare, Inc.
- Role: Subprocessor. Processing: Global delivery and storage of published pages and assets, request routing and security, and — where configured — Cloudflare Email Service for operational and lead email. Turnstile protects account and privacy-request initiation forms; customer landing-page forms remain CAPTCHA-free. Location: Global edge network; the serving location depends on where the visitor is, and email processing location is determined by Cloudflare.
- DigitalOcean, LLC
- Role: Subprocessor. Processing: Hosts the application servers that receive, validate and deliver form submissions, and the database holding those submissions during their retention window. Location: European Union.
- OpenAI
- Role: Subprocessor. Processing: Requested image generation and automated content checks on page content. It does not receive form submissions. Location: United States and other countries in which the provider operates.
- Sentry
- Role: Subprocessor. Processing: Error and performance monitoring for our own systems, with console session replay disabled in our configuration. Location: United States and other countries in which the provider operates.
- Role: Identity provider for optional account sign-in. Processing: Basic profile information for the person signing in. This is account data rather than Customer Personal Data, and is used only where a customer chooses Google sign-in. Location: United States and other countries in which the provider operates.
- Dodo Payments
- Role: Merchant of record. For its own merchant-of-record purposes — payment processing, fraud prevention, tax and invoicing, and its own record-keeping — it acts as an independent controller rather than solely on our instructions, and its own terms govern its relationship with the purchaser. Processing: Purchaser and transaction details for a payment. It does not receive page content or leads. Location: Determined by the provider and its own payment partners.
2. Selected but not yet in use
Naming a provider here is not a statement that it holds data today.
Payment processing is not enabled. Dodo Payments becomes a recipient when an enabled payment workflow is first used, and no purchase, trial or charge exists before that.
An additional image-generation provider is under evaluation for a second image tier. It has not been reviewed for handling customer information, and it will not process any before it is added to this register with the notice described in section 5.
3. Recipients you choose
Where you tell us to deliver a lead — a mailbox, a webhook endpoint, a CRM, or an agent you connect — that recipient is normally yours, not a subprocessor we appointed, even though we send the data there on your instruction. We will identify the destination and the transit providers involved, but assessing the recipient, its terms, and any resulting international transfer is your responsibility as the controller.
The same applies to an AI assistant you connect over MCP. It acts with the permissions you grant it, and its own provider’s terms govern what it does with what it retrieves.
4. What a page’s own policy lists
A published page carries its own privacy notice for its visitors, and that notice deliberately lists fewer providers than this register: only those in the path a form submission actually travels, plus the destination you configured for that page. A provider that never receives a submission — image generation, for example — is left out, because telling a visitor their data goes somewhere it does not is a worse error than omitting it.
That per-page list is produced from our maintained registry rather than written from memory, so it reflects what the service actually runs at the time it is generated. This register remains the complete picture for you as our customer.
5. Adding or replacing a provider
Under the DPA, we give at least 30 days’ advance notice to the account contact before adding or replacing a subprocessor that will handle that customer’s Customer Personal Data. You may raise a reasoned data-protection objection during that period, and we will look for a reasonable solution; if none is available, the affected processing will not start for you, and either party may end the affected service with a refund of unused prepaid fees for it.
An urgent legal or security need may require stopping an existing provider sooner. That does not remove any applicable notice or objection right.
This page is versioned with the rest of the legal package. The version date shown above is when the package was last revised, not necessarily when an individual entry changed.
6. Operator and contact
Aleksandr Shelestov PR JustOneDevJurija Gagarina 231, Novi Beograd, 11070 Belgrade, Serbia
PIB (tax identification number): 113504102
Registered with Serbian Business Registers Agency (APR), Register of Entrepreneurs
Business registration number (matični broj): 66872807
- General: [email protected]
- Support and billing: [email protected]
- Privacy requests: [email protected]
- Legal notices: [email protected]
- Content reports: [email protected]