Legal & Governance
Sub-processors
Last updated: 10 August 2026
To deliver the DESKREG platform, Leckware (“we”, “us”) engages third-party service providers (“sub-processors”) to process certain customer personal data.
Under Article 28 of the EU General Data Protection Regulation (GDPR), each sub-processor undergoes a technical and legal review to ensure appropriate security measures and data protection safeguards are maintained.
1. List of Approved Sub-processors
The following third-party entities are currently authorised to process data on behalf of DESKREG customers:
| Vendor | Legal Entity | Purpose | Location | Transfer Safeguard |
|---|---|---|---|---|
| Hetzner | Hetzner Online GmbH | Primary EU cloud infrastructure, application server hosting, and database storage. | Germany (EU) | EU Infrastructure / GDPR Article 28 DPA |
| Stripe | Stripe Payments Europe, Ltd. | Subscription billing management, payment processing, and VAT invoicing. | Ireland (EU) / Global | EU-US Data Privacy Framework (DPF) / Standard Contractual Clauses (SCCs) |
| Cloudflare | Cloudflare, Inc. | DNS resolution, Web Application Firewall (WAF), edge caching, and DDoS mitigation. | Global Edge / EU Data Centers | EU-US Data Privacy Framework (DPF) / Standard Contractual Clauses (SCCs) |
| Google Ireland Limited | Single Sign-On (SSO) identity authentication (OAuth) for Google accounts. | Ireland (EU) | EU Infrastructure / GDPR Article 28 DPA | |
| Microsoft | Microsoft Ireland Operations Ltd. | Single Sign-On (SSO) identity authentication (OAuth) for Microsoft Azure / 365 accounts. | Ireland (EU) | EU Infrastructure / GDPR Article 28 DPA |
2. Due Diligence and Security
We evaluate the privacy posture and technical security measures of every sub-processor before onboarding. Each vendor is bound by a data processing agreement that enforces strict confidentiality, access controls, incident notification obligations, and data handling standard limits.
3. Changes and Notification
As our product architecture evolves, we may update our list of sub-processors. Where required under our Terms and Conditions and Data Processing Agreement (DPA), we will notify account administrators of material sub-processor additions or updates at least 14 days prior to authorising new processing activities.
Customers may object to the engagement of a new sub-processor on reasonable data protection grounds by contacting us within the notification period.
4. Contact & Sub-processor Updates
For inquiries regarding our sub-processors or to subscribe to sub-processor change notifications, please email [email protected].