Sub-processors & International Transfers
Version v1.0 · Last updated 11 July 2026
This register lists every third party that may process personal data on Tidehawk’s behalf, what they process, where, and how international transfers are kept lawful. It is written to be reviewed as-is by an MSP’s auditor or data-protection officer before sign-up. It forms part of, and is incorporated by reference into, our Data Processing Agreement.
The short version an auditor needs
All customer data is stored and primarily processed in the United Kingdom / EU (London). No customer data is stored on servers outside the UK/EU. The only routine cross-border transmissions are (a) publiccertificate/domain look-up queries carrying a domain name only, and (b) billing data to our payment processor — each covered by the safeguards below. Our in-region discovery methods transmit data to no third party; CT look-ups are limited to the domain name (see §7).
1. Roles
For an MSP’s own account data, Tidehawk is the controller. For the end-client monitoring data an MSP loads into Tidehawk (client names, domains, certificates), the MSP is the controller and Tidehawk is the processor, acting only on the MSP’s documented instructions under the DPA.
2. Where your data lives (residency)
| Layer | Provider | Region | Notes |
|---|---|---|---|
| Application compute | DigitalOcean App Platform | LON1 (London, UK) | App + background worker |
| Primary database | DigitalOcean Managed PostgreSQL | LON1 (London, UK) | All records at rest |
| Transactional email | Amazon Web Services (SES) | eu-west-2 (London, UK) | Alert & account email |
| Object storage | Wasabi (S3-compatible) | eu-west-1 (London, UK) | Reports, export & erasure files |
| Error monitoring | Self-hosted GlitchTip | LON1 (London, UK) | Our own infrastructure — not a sub-processor |
| DNS | Cloudflare | Global (DNS-only) | Resolution only; no application PII |
3. Core service sub-processors
| Sub-processor | Function | Data processed | Location | Transfer safeguard |
|---|---|---|---|---|
| DigitalOcean, LLC | Hosting (compute + database) | All customer data at rest & in use | LON1, UK | In-region; DPA + SCCs for any incidental support access |
| Amazon Web Services | Transactional email (SES) | Recipient email + message content | eu-west-2, UK | AWS DPA; EU-US DPF; SCCs / UK Addendum |
| Wasabi Technologies | Object storage | Report & export contents | eu-west-1, UK | Wasabi DPA; data in-region |
| Stripe, Inc. | Payments & billing | Billing contact, card data (held by Stripe, never by us), plan metadata | US + global | Stripe DPA; EU-US DPF; SCCs |
| Cloudflare, Inc. | Authoritative DNS (DNS-only) | DNS queries only — no application PII | Global anycast | EU-US DPF; SCCs; DNS-only scope |
Error monitoring runs on self-hosted GlitchTip within our own LON1 infrastructure and is therefore not a third-party sub-processor.
4. Certificate & domain discovery sources (look-up only)
These services are queried with a domain name to discover certificates and registration data. We do notstore any customer data on these providers — we send a query and store the results in our UK database. Certificate Transparency (CT) data is public by design; we query public indexes of public data. We may use one or more of the public CT sources below; the specific set is an implementation detail and may change without materially affecting this disclosure.
| Source | Operator | Function | Data sent | Location | Safeguard |
|---|---|---|---|---|---|
| Certspotter | SSLMate, Inc. | Public CT-log certificate discovery | Domain name (query) | US | Public CT data; DPA/SCCs (confirm) |
| Censys | Censys, Inc. | Public CT-log certificate discovery | Domain name (query) | US | Public data; DPA/SCCs (confirm) |
| crt.sh | Sectigo Ltd. | Public CT-log certificate discovery | Domain name (query) | UK/US | Public CT data; public service |
| RDAP / WHOIS | Registry / registrar operators | Domain registration & expiry look-up | Domain name (query) | Global (per-TLD) | Public registry data |
| Direct TLS scan | Tidehawk (in-region) | Reads the certificate served by the host | Host connection | LON1, UK | No third party — zero cross-border transfer |
Data minimisation
Discovery queries carry the domain name only— never MSP identity, end-client identity, or account data.
5. Customer-directed integrations (optional)
When an MSP connects a PSA, alerts and tickets flow to that MSP’s own systemat the MSP’s explicit direction. These are enabled per-MSP and are disclosed for completeness: HaloPSA (Halo Service Solutions), ConnectWise, Autotask (Datto/Kaseya), NinjaOne, and Syncro (Servably). Only the alert/ticket content the MSP configures is sent.
6. International transfers — how they're lawful
Storage: none outside the UK/EU. Transmission:GDPR treats sending personal data abroad as a transfer even where we don’t store it there. Where a transfer can occur (public look-up queries, or billing data to Stripe) we rely, in order:
- Adequacy — UK↔EU mutual adequacy covers UK-based processing for EU data subjects.
- UK–US / EU–US Data Privacy Framework — where the US recipient is DPF-certified.
- Standard Contractual Clauses + UK International Data Transfer Addendum — as a fallback.
- Data minimisation — look-up queries carry the domain name only, and the data is public.
7. Certificate-transparency look-ups and in-region discovery
Certificate discovery combines an in-region active TLS scan (our own UK workers; no third party) with look-ups to the public Certificate Transparency sources listed above. Those look-ups transmit the domain name only— no MSP identity, end-client identity or account data. The set of CT sources is configured at the platform level and any change is notified under §8. A per-workspace option to restrict discovery to in-region methods only is on our roadmap; it is not currently available and should not be relied upon until it is announced here.
8. Changes to this list
We maintain this register as our current, complete list of sub-processors. We will give at least 30 days’ advance notice before adding or replacing a sub-processor, so controllers may object. Material changes are versioned with our DPA. Questions or objections: hello@tidehawk.co.
9. Detailed documentation (under NDA)
This register discloses everything required to assess Tidehawk as a processor: who processes your data, what they process, where, and the transfer safeguards. A more granular register and our security, data-flow, and architecture documentation are available to customers and prospective customers under a mutual non-disclosure agreement— ask your account contact or email hello@tidehawk.co and we’ll share it as part of your security review.
Pre-launch note
The Data Privacy Framework / SCC status of each US recipient is being confirmed with the respective vendor and our data-protection counsel prior to launch; entries marked “confirm” will be finalised before this page is relied upon commercially.