1. Scope and status
This list identifies providers that admorris GmbH may use to process Customer Personal Data on behalf of a HYPRCART Customer. A listed conditional provider only receives Customer Personal Data only if the corresponding function is enabled.
Corporate affiliates, support locations and downstream infrastructure may change in accordance with provider contracts. The DPA's notice and objection process applies to new subprocessors.
2. Authorised subprocessors
| Provider | Purpose | Processing location | Transfer safeguards / status |
|---|---|---|---|
| Cloudflare, Inc. Provider DPA | Edge delivery, Workers compute, security, DNS/networking, object/key-value storage, queues and platform runtime | Global network; EU and other locations according to routing and service configuration | Cloudflare DPA; SCCs and applicable adequacy mechanisms |
| Neon, Inc. Security information | Managed PostgreSQL database and backups | Primary production region: AWS eu-central-1 (Frankfurt); limited global support access may apply | Provider DPA; SCCs and applicable adequacy mechanisms |
| Amazon Web Services EMEA SARL and affiliates Data protection | Email delivery through Amazon SES and underlying cloud infrastructure used by contracted providers | HYPRCART email region: eu-central-1; AWS support/global infrastructure as contracted | AWS GDPR DPA; SCCs and applicable adequacy mechanisms |
| Typesense, Inc. Provider DPA | Hosted product search and indexing | EU search cluster; limited global support access may apply | Provider DPA and SCCs where required |
| Stripe Payments Europe, Limited and Stripe affiliates Provider DPA | HYPRCART subscription billing and Customer-enabled merchant payment/Connect functions | EEA, United States and global provider infrastructure | Conditional on use. Stripe may be processor for some technical processing and independent controller for regulated payment activities; SCCs/adequacy mechanisms apply as described by Stripe |
3. Customer-selected services and independent recipients
The following are not treated as HYPRCART subprocessors to the extent described:
- Customer-installed apps and custom integrations: selected and instructed by the Customer; their providers act under the Customer's terms.
- External identity providers: selected by the user or Customer and subject to their own controller terms, although HYPRCART receives the authentication result.
- Payment networks, acquiring banks and regulated payment services: may act as independent controllers for legal, fraud and payment obligations.
- Public authorities: independent recipients for verification or legal compliance.
- A Customer's buyers, staff and business partners: recipients determined by the Customer through normal commerce operations.
4. Changes and objections
We provide at least 30 days' advance notice before a new subprocessor begins processing Customer Personal Data, except where urgent replacement is needed to avoid a security, legal or service-continuity risk. In that case we notify the Customer as soon as reasonably possible.
A Customer may object within 15 days on reasonable, documented data-protection grounds by emailing legal@hyprcart.com. The resolution and affected-service termination rights are in Section 5 of the DPA.
5. Contact
Questions about a provider, processing region or transfer mechanism may be sent to legal@hyprcart.com. Customer-specific vendor details may require authentication and confidentiality.