Data Processing (DPA)

DE

Zuletzt aktualisiert: 20 August 2026

Overview

Under Art. 28 GDPR we sign a data-processing addendum with every third party that processes personal data on our behalf. Below is the full list of sub-processors.

Sub-processors

Cloudflare, Inc.
Purpose: Hosting, CDN, Workers runtime, TLS, DDoS protection
Location: US / EU edge
Safeguard: SCCs + supplementary technical measures
Supabase, Inc. (via Lovable Cloud)
Purpose: Auth, PostgreSQL database, storage (image uploads)
Location: EU (Frankfurt)
Safeguard: EU region, SCCs for supplementary processing
Stripe Payments Europe, Ltd.
Purpose: Payment processing, fraud prevention, subscription management, refunds
Location: EU (Dublin) / US
Safeguard: SCCs, PCI-DSS Level 1
Google LLC (via Lovable AI Gateway)
Purpose: Gemini models for drop enrichment (metadata, summaries)
Location: EU / US
Safeguard: SCCs, no model training per vendor terms
Google FCM / Apple APNs / Mozilla Autopush
Purpose: Delivery of encrypted web push messages
Location: Global
Safeguard: Only technical endpoint URLs & encrypted payloads

Controller & contact

Controller under Art. 4(7) GDPR is Maurice-Benjamin Huschke. Questions about data processing: datenschutz@cherry-drop.io.

Changes to sub-processors

Changes (addition or replacement of a sub-processor) are announced on this page. Where legally required, affected controllers are also informed in advance and granted a right of objection.