Sub-processors & International Transfers

Version v1.0 · Last updated 11 July 2026

This register lists every third party that may process personal data on Tidehawk’s behalf, what they process, where, and how international transfers are kept lawful. It is written to be reviewed as-is by an MSP’s auditor or data-protection officer before sign-up. It forms part of, and is incorporated by reference into, our Data Processing Agreement.

The short version an auditor needs

All customer data is stored and primarily processed in the United Kingdom / EU (London). No customer data is stored on servers outside the UK/EU. The only routine cross-border transmissions are (a) publiccertificate/domain look-up queries carrying a domain name only, and (b) billing data to our payment processor — each covered by the safeguards below. Our in-region discovery methods transmit data to no third party; CT look-ups are limited to the domain name (see §7).

1. Roles

For an MSP’s own account data, Tidehawk is the controller. For the end-client monitoring data an MSP loads into Tidehawk (client names, domains, certificates), the MSP is the controller and Tidehawk is the processor, acting only on the MSP’s documented instructions under the DPA.

2. Where your data lives (residency)

Where Tidehawk data is hosted, by layer, provider and region
LayerProviderRegionNotes
Application computeDigitalOcean App PlatformLON1 (London, UK)App + background worker
Primary databaseDigitalOcean Managed PostgreSQLLON1 (London, UK)All records at rest
Transactional emailAmazon Web Services (SES)eu-west-2 (London, UK)Alert & account email
Object storageWasabi (S3-compatible)eu-west-1 (London, UK)Reports, export & erasure files
Error monitoringSelf-hosted GlitchTipLON1 (London, UK)Our own infrastructure — not a sub-processor
DNSCloudflareGlobal (DNS-only)Resolution only; no application PII

3. Core service sub-processors

Core service sub-processors, what they process and the transfer safeguard for each
Sub-processorFunctionData processedLocationTransfer safeguard
DigitalOcean, LLCHosting (compute + database)All customer data at rest & in useLON1, UKIn-region; DPA + SCCs for any incidental support access
Amazon Web ServicesTransactional email (SES)Recipient email + message contenteu-west-2, UKAWS DPA; EU-US DPF; SCCs / UK Addendum
Wasabi TechnologiesObject storageReport & export contentseu-west-1, UKWasabi DPA; data in-region
Stripe, Inc.Payments & billingBilling contact, card data (held by Stripe, never by us), plan metadataUS + globalStripe DPA; EU-US DPF; SCCs
Cloudflare, Inc.Authoritative DNS (DNS-only)DNS queries only — no application PIIGlobal anycastEU-US DPF; SCCs; DNS-only scope

Error monitoring runs on self-hosted GlitchTip within our own LON1 infrastructure and is therefore not a third-party sub-processor.

4. Certificate & domain discovery sources (look-up only)

These services are queried with a domain name to discover certificates and registration data. We do notstore any customer data on these providers — we send a query and store the results in our UK database. Certificate Transparency (CT) data is public by design; we query public indexes of public data. We may use one or more of the public CT sources below; the specific set is an implementation detail and may change without materially affecting this disclosure.

Public certificate-transparency and registration data sources queried during discovery
SourceOperatorFunctionData sentLocationSafeguard
CertspotterSSLMate, Inc.Public CT-log certificate discoveryDomain name (query)USPublic CT data; DPA/SCCs (confirm)
CensysCensys, Inc.Public CT-log certificate discoveryDomain name (query)USPublic data; DPA/SCCs (confirm)
crt.shSectigo Ltd.Public CT-log certificate discoveryDomain name (query)UK/USPublic CT data; public service
RDAP / WHOISRegistry / registrar operatorsDomain registration & expiry look-upDomain name (query)Global (per-TLD)Public registry data
Direct TLS scanTidehawk (in-region)Reads the certificate served by the hostHost connectionLON1, UKNo third party — zero cross-border transfer

Data minimisation

Discovery queries carry the domain name only— never MSP identity, end-client identity, or account data.

5. Customer-directed integrations (optional)

When an MSP connects a PSA, alerts and tickets flow to that MSP’s own systemat the MSP’s explicit direction. These are enabled per-MSP and are disclosed for completeness: HaloPSA (Halo Service Solutions), ConnectWise, Autotask (Datto/Kaseya), NinjaOne, and Syncro (Servably). Only the alert/ticket content the MSP configures is sent.

6. International transfers — how they're lawful

Storage: none outside the UK/EU. Transmission:GDPR treats sending personal data abroad as a transfer even where we don’t store it there. Where a transfer can occur (public look-up queries, or billing data to Stripe) we rely, in order:

  1. Adequacy — UK↔EU mutual adequacy covers UK-based processing for EU data subjects.
  2. UK–US / EU–US Data Privacy Framework — where the US recipient is DPF-certified.
  3. Standard Contractual Clauses + UK International Data Transfer Addendum — as a fallback.
  4. Data minimisation — look-up queries carry the domain name only, and the data is public.

7. Certificate-transparency look-ups and in-region discovery

Certificate discovery combines an in-region active TLS scan (our own UK workers; no third party) with look-ups to the public Certificate Transparency sources listed above. Those look-ups transmit the domain name only— no MSP identity, end-client identity or account data. The set of CT sources is configured at the platform level and any change is notified under §8. A per-workspace option to restrict discovery to in-region methods only is on our roadmap; it is not currently available and should not be relied upon until it is announced here.

8. Changes to this list

We maintain this register as our current, complete list of sub-processors. We will give at least 30 days’ advance notice before adding or replacing a sub-processor, so controllers may object. Material changes are versioned with our DPA. Questions or objections: hello@tidehawk.co.

9. Detailed documentation (under NDA)

This register discloses everything required to assess Tidehawk as a processor: who processes your data, what they process, where, and the transfer safeguards. A more granular register and our security, data-flow, and architecture documentation are available to customers and prospective customers under a mutual non-disclosure agreement— ask your account contact or email hello@tidehawk.co and we’ll share it as part of your security review.

Pre-launch note

The Data Privacy Framework / SCC status of each US recipient is being confirmed with the respective vendor and our data-protection counsel prior to launch; entries marked “confirm” will be finalised before this page is relied upon commercially.