Sub-processors
The complete, named list of sub-processors — with legal entity, purpose and region — lives at /subprocessors. It is the canonical source of truth and the page that gets updated whenever a sub-processor changes.
Why this list lives outside /docs
Our public-facing privacy and DPA copy describes sub-processors by category (e.g. "our managed Postgres provider, EU region") rather than by named vendor. This reduces the reconnaissance surface for opportunistic attackers — naming every vendor inline across multiple legal pages turns those pages into a free attack map.
GDPR Articles 13/14 and 28 require disclosure of the categories of recipients and the existence of sub-processors, not the specific commercial product on every page. The single canonical page at /subprocessors satisfies that obligation in full while keeping the rest of the surface clean.
Subscribing to changes
To be notified by email when /subprocessors is updated, or to object to a sub-processor on reasonable grounds, write to support@qr-branding.com. Material changes are announced at least 30 days before they take effect.