HexVault
  • HexGuard AI
  • Pricing
  • Security
  • IAM
  • Extension
  • Blog
  • Download
Sign In Start Free Trial
  • HexGuard AI
  • Pricing
  • Security
  • IAM
  • Extension
  • Extension Security
  • Enterprise
  • Blog
  • Download
  • About
  • Contact
  • Trust Centre
  • FAQ
Sign In Start Free Trial
Legal — GDPR Article 28

Sub-Processor List

Last updated: April 2026 · Version 1.0 · HexVault Ltd, England & Wales

Your rights regarding sub-processors

Under GDPR Article 28(2), we are required to inform you of any sub-processors we use and allow you to object to new sub-processors. To subscribe to sub-processor change notifications, email [email protected] with subject "Sub-processor notification request". We provide 30 days notice of additions or changes.

Current sub-processors

Stripe
Payment processing and subscription billing
DPA in place
Data shared
Email address, billing address, Stripe customer ID and subscription ID
Country
United States
Transfer mechanism
UK IDTA / EU Standard Contractual Clauses
Added
January 2026
Postmark (ActiveCampaign)
Transactional email — password reset, email verification, security alerts
DPA in place
Data shared
Email address, email content (transactional only — no marketing)
Country
United States
Transfer mechanism
UK IDTA / EU Standard Contractual Clauses
Added
January 2026
Cloudflare
DDoS protection, CDN, DNS, Cloudflare Tunnel (origin access)
DPA in place
Data shared
IP addresses, request metadata (headers, URL paths). No vault data decryptable at this layer.
Country
United States (global edge network)
Transfer mechanism
UK IDTA / EU Standard Contractual Clauses
Added
January 2026
Have I Been Pwned (HIBP)
Password breach monitoring — k-anonymity model
No personal data
Data shared
5-character SHA-1 hash prefix only. This is insufficient to identify any specific password. No personal data is transferred.
Country
United States
Transfer mechanism
No personal data — GDPR transfer rules do not apply
Added
January 2026
Sentry
Application error monitoring — disabled for all vault operations
DPA in place
Data shared
Error stack traces and application metadata only. Vault operations are explicitly excluded from Sentry instrumentation.
Country
United States
Transfer mechanism
UK IDTA / EU Standard Contractual Clauses
Added
January 2026
No advertising sub-processors: HexVault does not use advertising networks, analytics platforms, social media tracking, or any other sub-processor that processes data for purposes beyond service delivery. This list is exhaustive.

Change history

April 2026Version 1.0 published. Initial sub-processor list.

Customers subscribed to change notifications will receive 30 days advance notice of any additions or material changes to this list. To subscribe, email [email protected].

Contact

Questions about sub-processors or data transfers: [email protected]

For a Data Processing Agreement: hexvault.co.uk/trust

HexVault

Zero-knowledge credential infrastructure for individuals, teams, and enterprises.

Product

Personal Team Enterprise Extension Download Security Changelog

Company

About Blog Careers Contact Press Status

Legal

Privacy Policy Terms of Service Cookie Policy Sub-processors Trust Centre FAQ
© 2026 HexVault Ltd · Registered in England & Wales hexvault.co.uk — Built in the UK · Patent Pending