Our Subprocessors
Third-party services that help us deliver Stish, all vetted for GDPR compliance
Last updated: February 2026
4 Subprocessors
Carefully Selected
Primary Hosting
EU (Frankfurt)
All Vetted
For GDPR
SCCs in Place
Where Required
Current Subprocessors
These are the third-party services that process personal data on our behalf to provide the Stish platform. We carefully vet each subprocessor for security, privacy practices, and GDPR compliance.
Data Processed
All platform data, files, and backups
Location
Frankfurt, Germany (EU)
Safeguards
EU Data Processing Addendum, SOC 2, ISO 27001
Data Processed
Payment card details, billing information
Location
EU & US (EU SCCs)
Safeguards
PCI DSS Level 1, EU SCCs, SOC 2
Data Processed
Campaign text, AI assistant queries
Location
US (EU SCCs)
Safeguards
SOC 2, EU Standard Contractual Clauses
Change Notifications
We will notify customers of any changes to our subprocessors list via email at least 14 days before the change takes effect, giving you the opportunity to object if the change affects your data processing requirements.
If you have questions about our subprocessors or wish to object to a change, please contact us.