# Subprocessor and Third-Party Provider List

> Version: 2026-08-01
> Issued: 28 July 2026
> Effective: 1 August 2026
> English is the authoritative version.

This list applies to **Hendrik**, the Service provided by Magnolia Squared (**Provider**), a Dutch
sole proprietorship owned by Wessel Hendrik Pannebakker, KVK 90466659, at Batavengaarde 4,
2408 TA Alphen aan den Rijn, the Netherlands. The vendors below are **Third-Party Providers** as
defined in the Terms; they are never references to Provider.

**Live** means the vendor currently receives the stated data. **Authorized** means Customer has
given general written authorization under the DPA for the vendor to receive the stated Customer
Personal Data when the relevant Service function is used. A vendor may be both Live and Authorized.
**Not enabled** means the stated processing is not active and is not authorized for Customer
Personal Data under this version.

Provider does **not** promise EU-only processing or data residency. Where a contracted plan offers
an EU region for the relevant workload, Provider prefers it. Control planes, support, and
subprocessors may process in other disclosed countries.

## 1. Subprocessors authorized for Customer Personal Data

The notices and objection procedure in Section 4 apply only to this section.

| Vendor and contracting entity     | Service and purpose                                                                                                                                  | Personal-data categories                                                                                                                                    | Status and primary location                                                                                                                                            | Transfer mechanism and contract                                                                                                                                                                                                                                                                                                                                                                                                                |
| --------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Hetzner Online GmbH**           | Nuremberg production compute and network for the trust core, Postgres, ClickHouse, ingestion, workers, on-host monitoring, logs, traces, and metrics | Customer Data processed by the Service; encrypted credentials; operational and security data                                                                | **Live and Authorized.** Nuremberg, Germany (`nbg1`); the executed DPA states that data for an EU server location and technical/customer support remain within the EU. | An Article 28 DPA v1.2 was electronically concluded for Magnolia Squared on 28 July 2026, including TOMs and the approved-subcontractor appendix. The additional proprietor account/contact address is not Provider's public or legal-notice address. The executed account document is available to Customers on request, subject to security redaction. [Hetzner data-protection information](https://www.hetzner.com/legal/privacy-policy/). |
| **Cloudflare, Inc.**              | DNS, CDN/edge security, Tunnel, Access, Workers, Durable Objects, AI Gateway routing, and encrypted R2 backups                                       | Requests and network metadata; account/session identifiers; interactive Agent state; selected prompts and outputs routed to AI providers; encrypted backups | **Live and Authorized.** Global edge; EU-jurisdiction Durable Objects where configured.                                                                                | Cloudflare's Customer DPA v6.4 is incorporated into its Self-Serve Subscription Agreement and includes EU SCC, UK and Swiss transfer terms, and supplementary measures. [Download the archived standard Cloudflare DPA](/legal/vendor-contracts/cloudflare-customer-dpa-v6.4.pdf) or [view Cloudflare's current DPA](https://www.cloudflare.com/cloudflare-customer-dpa/).                                                                     |
| **Anthropic, PBC**                | Interactive AI inference                                                                                                                             | Customer prompts, selected evidence and instructions, generated output, and technical request metadata                                                      | **Live and Authorized for customer admission.** United States and disclosed subprocessor locations.                                                                    | Anthropic's [Commercial DPA](https://www.anthropic.com/legal/data-processing-addendum) is incorporated into its Commercial Terms and includes EU SCC Modules Two and Three and the UK Addendum for applicable transfers. Anthropic does not use commercial inputs or outputs for general-model training by default; its published retention exceptions apply.                                                                                  |
| **Plus Five Five, Inc. (Resend)** | Transactional email delivery                                                                                                                         | Recipient name/work email, message content and metadata, delivery and security events                                                                       | **Live and Authorized for customer admission.** United States and disclosed subprocessor locations.                                                                    | The Resend DPA is incorporated into the service agreement and includes the EU SCCs and UK Addendum for applicable transfers. [Download Resend's signed standard DPA](/legal/vendor-contracts/resend-dpa-2025-12-31.pdf) or [view Resend's current DPA](https://resend.com/legal/dpa).                                                                                                                                                          |

OpenAI is not enabled as a fallback and is not authorized to receive Customer Personal Data under
this version. First enablement requires a list update, contract and transfer evidence, release
reconciliation, and the Section 4 notice.

## 2. Other Third-Party Providers and recipients

These Third-Party Providers handle Provider controller data or act in independent or mixed roles.
They are not Subprocessors for Customer Personal Data on the payload scope below. Provider must
reclassify a row into Section 1 before expanding its payload to data processed on a Customer's
instructions.

| Vendor                                                               | Role, status, data, location, and contract                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| -------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **PostHog, Inc.**                                                    | **Live.** Provider uses a PostHog Cloud EU project in Frankfurt for product/acquisition analytics, feature flags, content-free AI metadata, sanitized errors, and internal session replay. Replay is used for reliability, security, troubleshooting, support quality, and response quality assurance—not product improvement. Ordinary inputs and private regions are fully masked; interface text and Agent prompts/responses may remain readable only after deterministic redaction. Separately selected redacted Agent responses may be reviewed outside replay for the limited improvement purpose in the Privacy Policy and Terms. Replay is not exposed to or operated for Customer and is retained for up to 30 days; other analytics for up to 84 months. Global support/subprocessor access may occur. A countersigned PostHog DPA, including EU SCC, UK Addendum, and Swiss transfer terms, was executed and archived on 27 July 2026. The executed document contains restricted account/signature evidence and is available to Customers on request subject to redaction. [PostHog DPA information](https://posthog.com/dpa). |
| **Axiom, Inc.**                                                      | **Live.** Provider uses Axiom for allowlisted, redacted operational telemetry without prompts, secrets, raw bodies, or customer business content. Sanitized logs and sampled traces are processed in US East 1 (AWS) and retained for up to 30 days. Axiom's [DPA](https://axiom.co/docs/legal/data-processing) is incorporated into its Terms of Service and includes the EU SCCs and UK transfer terms for applicable transfers.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| **Stripe Payments Europe, Limited and applicable Stripe affiliates** | **Live.** Billing and payment provider in processor, independent-controller, or mixed roles, including fraud, compliance, and payment-network functions. Billing contact, subscription, invoice, tax, payment-method, charge, and fraud data may be processed in the United States and globally. Stripe's [DPA](https://stripe.com/legal/dpa) forms part of its Services Agreement; its [Data Transfers Addendum](https://stripe.com/gb/legal/dta) provides the applicable transfer terms. A customer-connected Stripe commerce account is separately customer-selected.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| **Cal.com, Inc.**                                                    | **Live.** Demo scheduling for Provider's sales relationship. Name, work contact, scheduling data, and qualification answers are processed in the United States and disclosed subprocessor locations. A production DPA containing EU SCC transfer terms was executed and archived on 27 July 2026. The executed document is available to Customers on request subject to account/security redaction. [Cal.com security and DPA information](https://cal.com/security).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| **Better Stack, Inc.**                                               | **Live.** Operational uptime, heartbeats, incident handling, and publication at `https://status.withhendrik.com`; no Customer business content is intended. Endpoint availability, timestamps, incident/status metadata, and accountable contacts may be processed with US/global support and subprocessor access. Provider relies on the SCC fallback incorporated into the [Better Stack DPA](https://betterstack.com/dpa), not on an unverified certification claim.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| **GitHub, Inc.**                                                     | **Live.** Source control, qualification, Actions, security scanning, and issue coordination. Developer identities, repository metadata, CI logs, and issue content may be processed in the United States and globally. Customer exports, credentials, provider payloads, prompts, and Customer Personal Data must not be committed. GitHub describes SCC and adequacy mechanisms in its [Data Protection Agreement](https://github.com/customer-terms/github-data-protection-agreement) and [General Privacy Statement](https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| **Professional advisers and authorities**                            | Lawyers, accountants, auditors, transaction advisers, courts, regulators, and law enforcement receive only data necessary for the engagement, claim, transaction, or binding request, subject to professional, contractual, or legal safeguards.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |

## 3. Public vendor contract references

The links above let Customers inspect or download public standard vendor terms. They do not replace
the executed agreement applicable to Provider's account, and a public standard document does not
prove a release-specific region, product, retention, or security setting. Executed account
documents that contain signature, network, account, or security evidence are not published openly;
Provider will make relevant portions available to a Customer on reasonable request, subject to
confidentiality, redaction, and third-party restrictions.

## 4. Customer-selected source and destination platforms

Meta, Google, Shopify, customer-connected Stripe accounts, and other connectors selected and
controlled by Customer are sources or recipients of Customer Data and approved actions. They are not
Provider's Subprocessors merely because Customer connects them. Their own terms and privacy
practices apply, and Customer is responsible for its accounts, permissions, notices, lawful basis,
and platform-policy compliance.

## 5. Subprocessor changes and objections

Provider will normally notify the Customer account owner at least 30 days before a material new
Subprocessor in Section 1 begins processing Customer Personal Data, where practicable. An urgent
security, legal, or continuity change may occur sooner, with notice as soon as practicable.

Materially changing an authorized Subprocessor's purpose, location, or transfer mechanism follows
this notice process. A status change in Section 2 is governed by the Privacy Policy and is not a
Subprocessor notice unless the payload change first requires reclassification into Section 1.

Customer may send a specific, documented data-protection objection within 15 days to
`privacy@withhendrik.com`. The parties will seek a commercially reasonable mitigation. If none
exists for a valid objection, Customer may terminate only the affected Service under the DPA.

## 6. Contact

- Privacy questions and Subprocessor objections: `privacy@withhendrik.com`
- Legal notices: `legal@withhendrik.com`
- Postal address: Magnolia Squared, Batavengaarde 4, 2408 TA Alphen aan den Rijn, the Netherlands
