Subprocessors
Last updated: [TBD] · This is a working draft pending legal review.
This page lists the third-party service providers ("subprocessors") that Coded B.V. ("Coded", "we", "us") engages to help operate the Coded commerce platform (the "Platform") and to process personal data on our behalf. We publish this list so that merchants, the people who use their Organizations and projects, and their own customers can see who is involved in delivering the Platform and where data is handled.
We maintain this list as part of our privacy-by-design commitment and as the general-authorization mechanism described in our Data Processing Agreement (DPA) and Privacy Policy. We do not sell personal data and we do not share personal data for cross-context behavioural advertising. Engaging a subprocessor never changes that.
Coded B.V. is a private limited company registered in the Netherlands (a subsidiary of Coded Holding B.V.) and operates internationally; merchants and their customers may be located anywhere in the world. The subprocessors below are selected and contracted to support that global operation.
What a subprocessor is
When you use the Platform, Coded acts as a data processor for the personal data that a merchant controls (for example, the personal data of a merchant's own shop customers), and as a data controller for the limited personal data Coded needs to run its own business (for example, merchant account and billing data). A "subprocessor" is a third party we engage to process personal data on our behalf in order to deliver the Platform — for example, our database host, our payment processors, our email-sending provider, and our error-monitoring tool.
Each subprocessor is bound by a written contract that requires it to process personal data only on documented instructions, to apply appropriate technical and organizational security measures, to assist with data-subject requests and security obligations, and to delete or return personal data at the end of the engagement. Where personal data leaves a jurisdiction that restricts international transfers, we rely on an approved transfer mechanism (such as the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful mechanism appropriate to the route).
We separate two roles a vendor can play:
- Subprocessor — processes personal data on Coded's behalf as part of delivering the Platform. These are the entities listed below.
- Independent processor / separate controller — a party that determines its own purposes for certain data and acts under its own terms. Our payment processors operate partly in this capacity for payment and anti-fraud purposes (see the note under the table).
Infrastructure subprocessors
Where Coded controls the choice of hosting, the Platform's primary application data is hosted in the European Union (Frankfurt, Germany). We treat EU hosting as a feature of the Platform, not a limitation on who we serve — merchants worldwide can use the Platform while their core records are kept in the EU.
The following subprocessors are engaged by Coded. — confirm each entity's exact legal name, the precise processing location/region we are provisioned in, and the current transfer mechanism before this page is published.
| # | Subprocessor | Purpose | Processing location | Notes |
|---|---|---|---|---|
| 1 | Supabase | Managed PostgreSQL database, authentication, and application data storage | European Union (Frankfurt, Germany) | Primary store for Platform application data |
| 2 | Stripe | Payment processing for merchant transactions and Coded subscription billing | Global (regional processing per cardholder/merchant) | Acts in part as an independent processor/controller for payments — see note below. Coded charges 0% platform fee; only Stripe's own processing costs apply |
| 3 | Mollie | Payment processing for European local payment methods (e.g. iDEAL, Bancontact) | European Union (Netherlands) | Acts in part as an independent processor/controller for payments — see note below. Coded charges 0% platform fee; only Mollie's own processing costs apply |
| 4 | Cloudflare | Edge security (WAF, DDoS mitigation, bot management), content delivery, and asset storage | Global edge network | Network-layer traffic and security processing |
| 5 | Amazon Web Services — SES | Transactional and platform email delivery | European Union (eu-central-1, Frankfurt) | Email sending and inbound email handling |
| 6 | Upstash | Managed Redis for queues, caching, and rate limiting | European Union (Frankfurt) | Confirm provisioned region |
| 7 | Sentry | Application error monitoring and performance diagnostics | European Union (EU data region) | Configured to receive diagnostic and stack-trace data; personal data is minimized via redaction |
| 8 | Vercel | Hosting and delivery of Coded's web frontends (marketing site, merchant dashboard, storefronts, payment pages) | Global edge network | Serverless hosting and CDN for frontend applications |
| 9 | Fly.io | Hosting of the Coded backend API | European Union (Frankfurt primary; Amsterdam replica) | Application server hosting |
Note on payment processors
Stripe and Mollie process payment data to carry out transactions, to meet their own legal, regulatory, and anti-fraud obligations, and to operate their own networks. For those purposes they act as independent controllers (or independent processors) under their own terms, rather than purely as Coded's subprocessors. Coded does not store full payment card numbers; payment pages are isolated to reduce the scope of payment data Coded handles. Coded charges no platform fee on merchant payment transactions — merchants pay only the pass-through processing cost charged by the relevant payment processor.
Note on diagnostics
We minimize the personal data sent to our monitoring and diagnostics subprocessor. Logs are configured to redact known personal-data fields, and our error monitoring is intended to receive technical diagnostics (such as stack traces) rather than user content. We do not use these subprocessors to profile individuals or to build advertising audiences.
Certifications and security
We describe our security measures honestly. We rely on the technical and organizational measures of the subprocessors above and on our own controls (including EU data residency for primary application data, network-edge protections, encryption in transit, least-privilege database access, and audit logging of administrative actions). We do not claim any certification that Coded does not actually hold. Where a subprocessor maintains its own certifications or attestations, those belong to that subprocessor and can be verified through its published documentation; they are not represented here as Coded's own.
Notification of changes
We may add, remove, or replace a subprocessor as the Platform evolves. When we do, we follow this process:
- Advance posting. We update this page to reflect a new or replacement subprocessor, with the "Last updated" date, before that subprocessor begins processing personal data on our behalf, or as soon as reasonably practicable where an emergency change is required to keep the Platform secure or available.
- Notice mechanism. Merchants and other customers may subscribe to receive notice of changes to this list. Subscription options will be published here (for example, an email subscription and/or an RSS feed). — confirm which notification channels we will offer at launch.
- Notice period and objection. For a change that increases risk to personal data, we aim to give at least 30 days' advance notice before the new subprocessor begins processing, unless a shorter period is required for security, legal, or continuity reasons. — confirm the notice period to commit to contractually.
- Right to object. A merchant who has a DPA with Coded may object to a new subprocessor on reasonable, documented data-protection grounds within the notice period. We will work in good faith to address the objection (for example, by offering an alternative or an additional safeguard). If we cannot reasonably resolve the objection, the merchant may, as its sole remedy, terminate the affected service in accordance with the DPA and the applicable agreement. Continued use of the Platform after a change takes effect constitutes acceptance of the updated list, to the extent permitted by applicable law.
This notification process is the "general written authorization" mechanism referenced in our DPA: by entering into the DPA, a merchant authorizes Coded to engage the subprocessors on this list and any future subprocessors added through this process, subject to the objection right above.
How this list relates to your own obligations
If you are a merchant acting as a data controller for your own customers' personal data, you remain responsible for your own privacy disclosures. This page is intended to help you meet your transparency duties — you may reference it (or this URL) in your own privacy notice and incorporate the relevant entries into your own subprocessor records. Coded provides this list to support, not replace, your assessment of the data chain.
Governing law
This page and the engagement of subprocessors are governed by the laws of the Netherlands, and disputes are subject to the exclusive jurisdiction of the courts of Amsterdam, the Netherlands — except that mandatory consumer-protection and data-protection laws of the jurisdiction where a user or data subject is located may also apply and are not displaced by this provision.
Contact
Questions about this list, our subprocessors, or our data-processing practices can be sent to:
- Privacy and data protection: privacy@coded.eu
- Security matters: security@coded.co
- Legal and contractual matters: legal@coded.eu
Coded B.V. De Taling 15, 2761 SL Zevenhuizen, The Netherlands KVK (Netherlands Chamber of Commerce): 42027097 VAT: NL869368795B01 Effective date: 11 June 2026
<!-- OPEN ITEMS FOR COUNSEL: - Verify the exact legal entity name, contracting entity, and provisioned processing region for EVERY subprocessor in the table (all marked ): Supabase, Stripe, Mollie, Cloudflare, AWS SES, Upstash, Sentry, Vercel, Fly.io. Confirm Upstash and Fly.io regions specifically. - Confirm which subprocessors require an executed DPA + signed SCCs/UK IDTA on file, and link each subprocessor's own DPA/privacy page once confirmed. - Confirm the controller/processor characterization of Stripe and Mollie (independent controller vs subprocessor) per their current terms — this drives the transfer-mechanism analysis. - Confirm the international data-transfer mechanism per route (EU SCCs, UK IDTA, Swiss addendum, or other), given the company operates globally and Vercel/Cloudflare/Stripe use global edge/processing. - Decide and commit to a concrete change-notification mechanism and notice period (currently drafted as ~30 days, marked ) and align with the DPA's general-authorization and objection clauses. - Confirm the objection-and-termination remedy aligns with the master agreement / subscription terms. - Confirm whether any additional subprocessors (analytics, support tooling, secrets management) must be disclosed; cookieless analytics posture suggests none, but verify the full vendor inventory. - Verify whether US state-law (CCPA/CPRA) "service provider" / "contractor" contractual flow-downs are reflected in each subprocessor contract for the universal-rights framing. - Replace 42027097, NL869368795B01, De Taling 15, 2761 SL Zevenhuizen, The Netherlands, 11 June 2026 and confirm contact domain (coded.eu (legal/privacy) · coded.co (ops)). -->