Jotholm Subprocessors
This list names every third party that may process personal data on Jotholm's behalf, its purpose, the data it touches, and its location. The Stripe contracting entity uses a dual-entity SCC arrangement (see the table below).
Last updated: 21 June 2026
Effective: 21 June 2026
1. Active subprocessors
| # | Subprocessor | Purpose | Personal data processed | Location | DPA / transfer mechanism |
|---|---|---|---|---|---|
| 1 | Stripe | Payment processing, subscription billing & customer portal | Account email; account/workspace identifiers (as metadata); payment/card data collected and held directly by Stripe, not by us | Stripe, Inc. (US) and/or Stripe Payments Europe, Ltd. (Ireland), dual-entity arrangement | Stripe standard DPA + SCCs, incorporated by reference into the Stripe Services Agreement; transfer mechanism: Stripe, Inc. (US) and/or Stripe Payments Europe, Ltd. (Ireland), with Stripe's standard SCCs in place. |
| 2 | Resend | Sending verification, magic sign-in, and account-notice emails | Recipient email address; email content (sign-in/verification links, notices) | United States | Resend standard DPA (incorporating SCCs). |
| 3 | Self-hosted hosting / infrastructure (on-premises, self-hosted) | Running the application servers and storing workspace databases and uploaded images | All personal data at rest (account, board content, sessions, billing identifiers) | Self-hosted on-premises in Sweden (EU/EEA), privately-operated cluster, not a public cloud | On-premises, within the EEA (Sweden): no third-party hosting processor. |
| 4 | Backup / cold-archive storage (off-box backup storage) | Storing operational backups (hourly snapshots, ~8-week max) and cold-archive tarballs | Same as #3 (backup copies) | Access-controlled storage, encrypted at rest; the primary backup store is an on-premises NAS in Sweden (EU/EEA) | Primary store on-premises, within the EEA (Sweden). |
2. Identity provider (special case)
| Provider | Role | Data flow | Notes |
|---|---|---|---|
| Google (Sign in with Google / OIDC) | Identity provider, only for users who choose Google sign-in | We send Google nothing about other users; for a user who signs in with Google we receive their verified email, name, and Google subject id | Independent (separate) controller for the authentication, not a Jotholm subprocessor. The user authenticates directly with Google under Google's own terms/privacy policy; Jotholm only receives back verified identity (email, name, subject id) and sends Google no data about other users. No controller-to-processor transfer by Jotholm; Google's own EU–US Data Privacy Framework / SCC safeguards govern its US processing. Listed for transparency. |
3. Notes
- No advertising, analytics, CDN, crash-reporting, or feature-flag third parties are present (no Sentry/PostHog/Segment or similar SDKs). Product analytics are internal and contain no personal data (closed-enum event counts only).
- Supporting infrastructure that does not process personal data (listed for transparency, not subprocessors of personal data): a DNS provider (domain-name resolution only) and Let's Encrypt (TLS certificate issuance). These receive no user personal data. Purely internal development and build tooling that never touches user data is out of scope for this list.
- This list must be kept current: adding any new subprocessor requires updating this document and (where consent or notice obligations apply) notifying users in advance.
Effective 21 June 2026. Questions: privacy@jotholm.io.