Reditus Sub-processors
Last updated: 5 August 2026.
This page lists the vendors Reditus B.V. (Kapelweg 12, 3951 AC Maarn, Netherlands, KvK 77814487) engages, as referenced in clause 9 and Annex C of our Data Processing Agreement. Table 1 are sub-processors of customer personal data; Table 2 are vendors Reditus uses as a controller in its own right. We give at least 30 days' notice before a new sub-processor begins processing customer personal data, and customers may object as described in the DPA. To receive change notifications by email, write to privacy@getreditus.live with the subject "Sub-processor notifications".
Table 1: Approved Sub-processors of Customer Personal Data
Maintained at https://www.getreditus.live/sub-processors. Entries marked (newly disclosed) are existing engagements named here for the first time, not new appointments, so the clause 9.2 notice period is not triggered by their appearance in this list.
| Name (legal entity) | Purpose | Location | Transfer mechanism | |---|---|---|---| | Hetzner Online GmbH | Hosting of the application, API and supporting infrastructure | Nuremberg, Germany | None (EEA) | | Supabase Pte. Ltd | Primary application database only. Supabase does not provide file storage or authentication for the Services. | Frankfurt, Germany (Singapore contracting entity) | SCCs, Module Three (no Singapore adequacy decision; data rests in the EU) | | Amazon Web Services, as sub-sub-processor beneath Supabase (newly disclosed) | Underlying cloud infrastructure on which the Supabase EU project runs. AWS is not a direct Reditus vendor; see Note 4. | | Inherited through the Supabase contract and the SCCs referenced in the Supabase row | | Cloudflare, Inc. | DNS, CDN, WAF, TLS termination and edge compute; object storage (Cloudflare R2) holding files uploaded through the Services; and hosting and serving of the Reditus tracking script | Global edge network; TLS terminates at the point of presence nearest the visitor | SCCs, Module Three; EU-US Data Privacy Framework self-certification as a supplementary fact | | Stripe Payments Europe, Limited | Payment processing and, where the Customer connects its Stripe account, reading transaction data to attribute commissions | European Economic Area | None (EEA) at the top level | | PayPal (Europe) S.à r.l. et Cie, S.C.A. | Affiliate commission payouts, the default payout rail. Reditus stores the affiliate's PayPal email address and uses it to pay commissions; there is no automated PayPal API integration in the Services. Commissions are paid on three rails in all: PayPal, direct bank transfer to the affiliate's IBAN, and Wise. The direct transfer leg runs through Reditus's own bank account, so it is not a Sub-processor disclosure; the other two rails are the two rows here. | European Economic Area | None (EEA) | | Wise Europe SA | Affiliate commission payouts on the Wise rail, one of the three rails described in the PayPal row. Payouts here are initiated operationally rather than through an API integration in the Services. Affiliate IBANs are stored in the affiliate record and encrypted at application level. | European Economic Area | None (EEA) | | Twilio Inc., trading as Twilio SendGrid | Transactional email sent by the Services, and synchronisation of contact records for Reditus's marketing email | United States | SCCs, Module Three | | Functional Software, Inc., doing business as Sentry | Frontend error tracking and diagnostics for the authenticated application, including session replay configured to mask all text and block all media. There is no Sentry agent in the backend. | United States (Sentry US region) | SCCs, Module Three; EU-US Data Privacy Framework self-certification as a supplementary fact | | PostHog, Inc. | Product and website analytics. Identified profiles carry the user's email address, full name, account MRR and plan. Session replay is not enabled in the application's PostHog configuration. | Frankfurt, Germany, at rest, through an EU ingestion endpoint; United States contracting entity, and the analysis interface is served from a United States host | SCCs, Module Three (data rests in the EU; US contracting entity) | | Honeybadger Industries LLC | Backend error tracking only. Its log-ingestion product is disabled, application logs are written to standard output rather than shipped to Honeybadger, and error reports carry no user-context tagging. | United States | SCCs, Module Three | | Plane Software, Inc. | Issue tracking, where Reditus creates its tickets. A ticket can contain the identity and contact details of the person who raised it, together with whatever they included in their report, and nothing beyond that. | United States (Delaware entity, hosted cloud service running on Amazon Web Services) | SCCs, Module Three | | HubSpot (newly disclosed) | Two roles in which HubSpot receives Customer Personal Data. (a) In-product support chat: the chat widget is mounted on every page of the authenticated application and identifies the visitor with a signed token, so it receives the email address of every logged-in user. (b) CRM synchronisation: affiliate and advocate records (name and email address) are synchronised from the Services into Reditus's own HubSpot CRM. HubSpot's third role, the integration a Customer connects to its own HubSpot account, is a different legal relationship and is covered by Note 1, not by this row. | See Note 6 | See Note 6 | | Calendly (newly disclosed) | Server-side resolution of a booking invitee's name and email address for attribution. Where the Customer connects its own Calendly account, Note 1 also applies to that leg. | See Note 6 | See Note 6 | | User.com (newly disclosed) | Notification and messaging service receiving referral, lead and advocate email addresses, names and countries from the Services | See Note 6 | See Note 6 | | Slack (newly disclosed) | Internal Reditus notifications generated by the Services, roughly thirty message types including affiliate creation and commission payment events, which carry affiliate identifying data into Reditus's internal Slack workspace | See Note 6 | See Note 6 | | LinkedIn (newly disclosed) | The OAuth connection an affiliate makes to their own LinkedIn account, from which the Services read and store the affiliate's profile data in a dedicated store. Listed here on the conservative view: as Note 7 explains, the direction of travel makes this an affiliate-authorised read grant rather than an onward disclosure by Reditus, but the connection is implemented in the Services and the profile data it returns is retained, so Reditus discloses it as a Table 1 entry rather than argue itself out of the listing. LinkedIn's separate role in Reditus's own marketing is covered by Note 2. | See Note 6 | See Note 6 | | Paragon (newly disclosed) | Embedded integration platform running in the authenticated frontend, through which Customer integrations are configured and data is brokered | See Note 6 | See Note 6 | | n8n Cloud (newly disclosed) | Automation platform brokering the AI lead-discovery and affiliate-matching pipeline described at clause 10.2. It receives the Customer's search and ideal-customer-profile criteria, calls the model and the enrichment vendors, and returns scored matches; the inbound webhook stores the full unfiltered response body. Listed here on the conservative view of the role split. | See Note 6 | See Note 6 | | Google Tag Manager, operated by Google (newly disclosed) | Tag container loaded in the authenticated application in production (container GTM-PSMWBCS). A tag container can load further third-party tags, so the set of scripts it introduces is a configuration choice rather than a fixed list. | See Note 6 | See Note 6 |
Table 2: Vendors for which Reditus is the controller
These are not Sub-processors of Customer Personal Data and are not covered by the clause 9 notice and objection procedure. They are set out here because they are live, and because a vendor placed in this table has to be disclosed in the Reditus privacy notice instead. Note 5 records the placement decisions and what the privacy notice has to pick up. This table and section 8.1(b) of the Reditus privacy notice are the same list, rendered from one source; where the two ever differ, the published sub-processor page at https://www.getreditus.live/sub-processors is canonical.
| Name (legal entity) | Purpose | Personal data involved | Location | |---|---|---|---| | CORDNET OU (registry code 14748498), Kaluri tee 4-32, Viimsi vald, trading as Featurebase | The chat and product feedback widget on the getreditus.live marketing site, processing in the Netherlands, Germany and Ireland. The in-product chat on the authenticated application is HubSpot Conversations (Table 1). | Marketing-site visitors and prospects who open a chat or post feedback | Estonia (entity of establishment) | | POSITIVE GROUP SALES SOLUTIONS SAS, trading as NoCRM.io | Reditus's internal sales CRM. The entry sits in this table rather than Table 1 because it carries Reditus's own account-relationship data, not affiliate or referred-lead data held for a Customer. | Reditus's own prospects and its own customer account contacts, synchronised automatically from the Services | Hem, France | | Hunter Web Services, Inc. | Work-email discovery and verification for candidate affiliates in the recruitment pipeline. The call is made inside n8n and the enriched personal data is stored in Reditus's own systems. | Candidate name, email address and LinkedIn profile | Delaware, United States | | Google, for the Gemini API | The model called inside the n8n pipeline to score, rank and explain candidate matches | Candidate contact records: name, email address, job title, LinkedIn handle | See Note 6 | | DataForSEO OU (company number 14502291), Vesivarava tn 50-201, Tallinn | Public web and search data about candidate sites and companies, and search and AI-answer data for the public tools on the Reditus marketing site | None in the recruitment pipeline: site and company data only. The public tool passes the free-text category a visitor types in | Estonia, with operations at 63 Profesora Otamanovskoho Street, Kharkiv, Ukraine. Ukraine has no EU adequacy decision, so the Standard Contractual Clauses are required and the Estonian registration alone is not sufficient | | Supabase Pte. Ltd, second project (newly disclosed) | A second, separate database project holding the AI recruitment pipeline's data, including scraped, non-registered candidate profiles. Distinct from the production application database in Table 1. | Candidate contact records: name, email address, job title, LinkedIn handle, plus company data | See Note 6 | | Google Ireland Limited, for the browser Google Analytics 4 tag | Reditus's own product analytics on the authenticated application interface. Does not run on the marketing site. | Online identifiers, page addresses and IP address, with IP dropped at the EU collection endpoint | Ireland (entity). Collected in the EU and then forwarded to Google servers in the United States, which is not EU residency | | Google Analytics 4, operated by Google, server-side (newly disclosed) | Reditus's own analytics: the Reditus backend sends a server-side event when a Customer installs the tracking script. Distinct from the browser tag above and from the Google Analytics 4 property an affiliate may connect to their own account. | | See Note 6 | | Google Cloud EMEA Limited | Google Workspace: staff email, documents, spreadsheets and calendar | Business contact data of anyone Reditus corresponds with | Ireland, with Google LLC (United States) as a listed sub-processor for data centre operations | | Dealfront Finland Oy, trading as Leadfeeder Finland, with Dealfront Group GmbH (Karlsruhe, Germany) as parent | IP-based company identification of visitors to Reditus's own web properties | Visitor IP address, the reverse lookup of the IP owner, and page addresses | Finland, with a German parent. Dealfront's own chain reaches United States recipients under the Clauses | | Sanity (contracting entity to be established: Sanity US Inc. or Sanity AS) | Content management for the Reditus marketing site | Author profiles and named case-study contacts | United States or Norway. Content stored on Google Cloud in Belgium | | Mintlify, Inc. | Hosting of docs.getreditus.live | Documentation visitor telemetry | United States | | SaaSflow OU, trading as Guideflow | Interactive product demo embeds on the Reditus marketing pages | Visitor identifiers set by the demo player, approximate location from IP address | Estonia | | Better Stack, Inc. | Uptime and availability monitoring, and the public status page at status.getreditus.live | Name, email address and IP address of status-page visitors and subscribers | United States. The status page itself is served from Hetzner in Germany | | Deluxe Custom Apps LLC, trading as GlockApps | Receipt of email authentication (DMARC) reports for the Reditus domains | Email authentication metadata, including sending IP addresses, and, where forensic reporting is enabled, recipient email addresses | United States | | Sprinto (contracting entity to be established: Sprinto Inc. or Sprinto Technology Private Limited) | Compliance automation and the Reditus trust centre | Published compliance content, plus the email address of anyone requesting a document through the trust centre | United States or India | | Open Exchange Rates | Currency conversion rates for commission and payout amounts | None | See Note 6 | | GitLab | Source control and continuous integration | None from production; the repositories hold no production personal data, though the pipeline holds deployment secrets | See Note 6 |
Notes:
1. Integrations the Customer connects are not Reditus Sub-processors. Where the Customer connects its own HubSpot, User.com, Slack, Calendly, Google Analytics, YouTube or LinkedIn account, or its own systems via the Reditus API and webhooks, that vendor is the Customer's processor: Reditus sends the data to the Customer's own account with a vendor the Customer chose. Several vendors appear both here and in Table 1, and the distinction is which account the data lands in. HubSpot is the clearest case: the Customer-connected OAuth integration pushes data into the Customer's HubSpot portal and is governed by this Note, while the in-product support chat and Reditus's own CRM synchronisation push data into Reditus's HubSpot portal and are governed by Table 1.
2. Reditus's own marketing. Google Ads and LinkedIn advertising run on Reditus's own web properties for Reditus's own marketing, as independent controllers, and are disclosed in the Reditus privacy notice, not here. LinkedIn is not marketing-only: it also appears in Table 1 for the affiliate OAuth connection, from which the Services read and store an affiliate's LinkedIn profile data.
3. Purely internal tooling. Vendors that process no personal data connected with the Services and hold no production data, such as internal workspace and documentation tools, are maintained in Reditus's internal vendor register rather than in this Annex. The three borderline cases the audit raised, Better Stack, Open Exchange Rates and GitLab, have been placed in Table 2 as a deliberate call rather than left to a general note.
4. Amazon Web Services and Cloudflare R2. The Reditus application uses the aws-sdk-s3 and fog-aws libraries, but these speak the S3 protocol to Cloudflare R2, not to Amazon Web Services. AWS appears in this Annex only underneath other vendors, as the cloud beneath the Supabase EU project and as the cloud on which Plane's hosted service runs, never as a direct Reditus vendor.
5. For the privacy notice. The following entries sit in Table 2 rather than Table 1, which means the Reditus privacy notice, not this Annex, is where they must be disclosed to data subjects: Featurebase (marketing-site chat and feedback), NoCRM.io, Hunter Web Services, Inc., Google (Gemini API), DataForSEO OU, the second Supabase project holding scraped candidate profiles, the browser and server-side Google Analytics 4 properties, Google Workspace, Dealfront / Leadfeeder, Sanity, Mintlify, Guideflow, Better Stack, GlockApps, Sprinto, Open Exchange Rates and GitLab. Every one of them now has a named row in privacy notice section 8.1(b); the audit's point about Better Stack, Open Exchange Rates and GitLab was that the call had to be conscious and written down, and naming them in both places is how that is discharged. The second Supabase project and the Gemini pipeline also bear on the Article 14 notice for non-registered candidates.
6. Still to be established.
7. Two placement calls, recorded rather than assumed. LinkedIn sits in Table 1 even though the affiliate OAuth connection runs in the opposite direction from an ordinary onward disclosure: the affiliate authorises Reditus to read their own profile, so LinkedIn is the source rather than the recipient, which is the reasoning section 8.4 of the privacy notice applies to YouTube and Google Analytics. Reditus lists it in Table 1 anyway, because the connection is implemented in the Services, the returned profile data is stored against the affiliate record, and a listing that is arguably too generous costs a Customer nothing while an omission costs it an Article 28 finding. Google Tag Manager sits in Table 1 for a different reason: the container loads on authenticated pages used by the Customer's affiliates, and because a tag container can introduce further tags without any change to the Reditus application, the honest classification is the one that gives the Customer the clause 9 notice and objection right over it. Version 1.0 carried Google Tag Manager only in the controller-side table; that has been corrected here and in the privacy notice together.
*End of the Reditus Data Processing Agreement, version 1.3 (concise edition), effective 5 August 2026. This concise edition is the edition published at https://www.getreditus.live/dpa and the only edition Reditus offers for signature. Reditus B.V., Kapelweg 12, 3951 AC Maarn, Netherlands, KvK 77814487, VAT NL861156420B01.*
Questions about this list: privacy@getreditus.live. Our security overview is at /security, and our Data Processing Agreement is at /dpa.