Skip to content

Sub-processors

The complete, named list of sub-processors — with legal entity, purpose and region — lives at /subprocessors. It is the canonical source of truth and the page that gets updated whenever a sub-processor changes.

Why this list lives outside /docs

Our public-facing privacy and DPA copy describes sub-processors by category (e.g. "our managed Postgres provider, EU region") rather than by named vendor. This reduces the reconnaissance surface for opportunistic attackers — naming every vendor inline across multiple legal pages turns those pages into a free attack map.

GDPR Articles 13/14 and 28 require disclosure of the categories of recipients and the existence of sub-processors, not the specific commercial product on every page. The single canonical page at /subprocessors satisfies that obligation in full while keeping the rest of the surface clean.

Subscribing to changes

To be notified by email when /subprocessors is updated, or to object to a sub-processor on reasonable grounds, write to support@qr-branding.com. Material changes are announced at least 30 days before they take effect.