This page lists the categories of sub-processors lead.box engages to provide the Service. Infrastructure providers are named below; category-critical intelligence providers are described by function and region and are named to customers on request (confidential). This protects the integrity of our supply chain while giving you the information required by GDPR Art. 28 and related contractual data-protection obligations: category, purpose, location, data categories and the contractual safeguards in place. The full list forms Annex I of our Data Processing Agreement.
| Provider | Function | Location | Data Categories | Legal Safeguard |
|---|---|---|---|---|
Stripe Payment Processing | Processing of subscription payments and invoicing | Ireland (EU) / United States | Name, billing address, email, payment method | GDPR Art. 28 DPA, EU SCCs, PCI-DSS Level 1 |
Resend Transactional Email | Delivery of transactional emails (account, lead alerts, billing) | European Union / United States (parent) | Recipient email, name, message content | GDPR Art. 28 DPA, EU data residency, EU SCCs |
Heroku (Salesforce) Application Runtime | Hosting of internal background jobs and processing pipelines | European Union (eu region) | Processing logs, transient job payloads | GDPR Art. 28 DPA, EU SCCs |
Cloudflare Edge Network & DDoS Protection | CDN, WAF and traffic routing for the tracking endpoint | Global edge with EU-preferred routing | IP addresses, request metadata | GDPR Art. 28 DPA, EU SCCs |
Supabase Database & Authentication | Managed PostgreSQL, authentication and file storage | EU (Frankfurt, eu-central-1) | Account, tracking and lead data | GDPR Art. 28 DPA, EU-only data residency |
GDPR-Compliant IP & Company Intelligence | Resolution of public company IP ranges into firmographic information | European Union / EEA | Anonymised IP, company metadata (name, domain, industry, size) | GDPR Art. 28 DPA, EU/EEA processing — specific provider and sub-sub-processor list named to customers on request under a confidentiality undertaking |
1. Notification of changes
We notify customers of intended additions or replacements of sub-processors at least 30 days in advance, giving you a reasonable opportunity to object on data-protection grounds. Active customers receive notifications via email; this page is the canonical source.
2. Safeguards in place
- Written sub-processor agreements meeting GDPR Art. 28 requirements
- EU Standard Contractual Clauses for any transfers outside the EEA / UK
- EU-preferred data residency wherever technically feasible
- Contractual restriction to processing on documented instructions only
- Regular review of each sub-processor's security posture and certifications
3. Customer audit
Customers with a signed DPA may request additional information about specific sub-processors, including copies of audit reports where available, by contacting info@lead.box.