Sub-processors

Version v1.1 · Last updated: 18 July 2026

This page lists the sub-processors flintery uses to process your clients’ data on your behalf (Art. 28 GDPR). Services that only concern your own account, payment or usage data are listed in the privacy policy.

Only the German original version is binding. This English version is provided for information only.

Processes contract data

These services process contract data (the end-client and project data you enter). They are part of the DPA (Annex 2).

ServiceLocationPurposeThird countrySafeguards
Hetzner Online GmbHNürnberg, DEApplication hosting, PostgreSQL database, Redis, backups, audit-proof archive PDFsNoISO 27001; processing within Germany
Cloudflare, Inc. (US) / Cloudflare London, LLC (UK)US / UKCDN, WAF, DDoS protection, TLS termination, reverse proxy — pass-through of traffic “in transit”YesUK adequacy decision; EU-US Data Privacy Framework (US entity); Standard Contractual Clauses (SCCs)

Other services

Services that only concern your own account, payment or usage data (such as payment processing, email delivery or analytics) are not part of the data processing agreement. They are fully listed in the privacy policy.

Go to the privacy policy

Changes to sub-processors

When adding or replacing a sub-processor, we notify you in advance with a lead time of 7 days via your registered contact email. You may object to the change within 14 days of receipt for important data protection reasons (channel: legal@flintery.com); this period continues to run after the change takes effect. If you do not object within the period, the change is deemed approved. In urgent security or outage cases we may switch immediately and will inform you without undue delay afterwards. If you activate an optional feature after being informed about the service it uses, this constitutes a separate authorisation; the notice periods do not apply in that case.

Change history

A traceable history of all changes to this list.

VersionDateChange
v1.118 Jul 2026List focused on the sub-processors relevant to the DPA. Services that only concern account, payment or usage data (controller sphere) are fully listed in the privacy policy. No change to the sub-processors in use.
v129 Jun 2026Initial publication of the sub-processor list.