Public list - Annex B of the DPA
Sub-processors
Up-to-date list of the third-party providers that Studio Cravero Consulting uses to deliver the DPO Workspace service. Each sub-processor is bound by a specific DPA under Art. 28(4) GDPR.
Last updated: 22 agosto 2026
Changes to the list: we will notify you by email of the addition or replacement of sub-processors with at least 30 days' notice. You have the right to object by terminating the contract without penalty.
| Provider | Service | Location and data region | Safeguards | DPA |
|---|---|---|---|---|
Google Ireland Limited Firebase / Google Cloud Platform | Hosting applicazione, autenticazione utenti, database Firestore, storage documentale, Cloud Functions | Dublino, Irlanda Data region: europe-west1 (Belgio) | DPA Google + SCC ove applicabile | Open |
Google Ireland Limited Google Cloud Document AI | Riconoscimento ottico del testo nei documenti caricati, per renderli ricercabili (piani Pro e Studio) | Dublino, Irlanda Data region: eu (endpoint europeo Document AI) | DPA Google; elaborazione sull'endpoint europeo; nessun uso dei contenuti per l'addestramento di modelli | Open |
Stripe Payments Europe Ltd Payment processing | Gestione abbonamenti, fatturazione, customer portal, gestione carte di credito | Dublino, Irlanda Data region: UE | DPA Stripe + certificazione PCI-DSS Level 1 | Open |
Sendinblue SAS (Brevo) Transactional email sending | Notifiche di sistema, conferme account, alert scadenze, comunicazioni utenti | Parigi, Francia Data region: UE | DPA Brevo | Open |
Cloudflare, Inc. DNS, CDN, DDoS protection | Risoluzione DNS del dominio dpoworkspace.eu, distribuzione asset statici, protezione da attacchi | San Francisco, USA Data region: Globale (multi-region) Outside the EU, with SCC | DPA Cloudflare + SCC 2021/914 + Transfer Impact Assessment (Schrems II) | Open |
Google Ireland Limited
Firebase / Google Cloud Platform
Role: Application hosting, user authentication, Firestore database, document storage, Cloud Functions
Location: Dublin, Ireland
Data region: europe-west1 (Belgio)
Safeguards: Google DPA + SCC where applicable
Google Ireland Limited
Google Cloud Document AI
Role: Optical character recognition on uploaded documents, to make them searchable (Pro and Studio plans)
Location: Dublin, Ireland
Data region: eu (European Document AI endpoint)
Safeguards: Google DPA; processing on the European endpoint; content not used to train models
Stripe Payments Europe Ltd
Payment processing
Role: Subscription management, billing, customer portal, credit card handling
Location: Dublino, Irlanda
Data region: UE
Safeguards: Stripe DPA + PCI-DSS Level 1 certification
Sendinblue SAS (Brevo)
Transactional email sending
Role: System notifications, account confirmations, deadline alerts, user communications
Location: Paris, France
Data region: UE
Safeguards: Brevo DPA
Cloudflare, Inc.
DNS, CDN, DDoS protection
Role: DNS resolution for dpoworkspace.eu, static asset delivery, attack protection
Location: San Francisco, USA
Data region: Global (multi-region)
Safeguards: Cloudflare DPA + SCC 2021/914 + Transfer Impact Assessment (Schrems II)
Transfer outside the EU with SCC
Safeguards for transfers outside the EU
For sub-processors that involve a transfer outside the EU — today only Cloudflare, for DNS and CDN — the safeguards in Chapter V GDPR apply:
- Standard Contractual Clauses (SCC) approved by EU Decision 2021/914;
- Transfer Impact Assessment (TIA) in line with the Schrems II ruling (CJEU C-311/18);
- Additional technical measures: end-to-end TLS 1.3 encryption, data limited to DNS metadata and static assets (no sensitive personal data passes through Cloudflare);
- TIA documentation is available on reasoned request.
For requests or objections: write to info@studiocravero.eu or certified email info.studiocravero@pec.it.