Public list - Annex B of the DPA

Sub-processors

Up-to-date list of the third-party providers that Studio Cravero Consulting uses to deliver the DPO Workspace service. Each sub-processor is bound by a specific DPA under Art. 28(4) GDPR.

Last updated: 22 agosto 2026

Changes to the list: we will notify you by email of the addition or replacement of sub-processors with at least 30 days' notice. You have the right to object by terminating the contract without penalty.
Google Ireland Limited
Firebase / Google Cloud Platform
Role: Application hosting, user authentication, Firestore database, document storage, Cloud Functions
Location: Dublin, Ireland
Data region: europe-west1 (Belgio)
Safeguards: Google DPA + SCC where applicable
Google Ireland Limited
Google Cloud Document AI
Role: Optical character recognition on uploaded documents, to make them searchable (Pro and Studio plans)
Location: Dublin, Ireland
Data region: eu (European Document AI endpoint)
Safeguards: Google DPA; processing on the European endpoint; content not used to train models
Stripe Payments Europe Ltd
Payment processing
Role: Subscription management, billing, customer portal, credit card handling
Location: Dublino, Irlanda
Data region: UE
Safeguards: Stripe DPA + PCI-DSS Level 1 certification
Sendinblue SAS (Brevo)
Transactional email sending
Role: System notifications, account confirmations, deadline alerts, user communications
Location: Paris, France
Data region: UE
Safeguards: Brevo DPA
Cloudflare, Inc.
DNS, CDN, DDoS protection
Role: DNS resolution for dpoworkspace.eu, static asset delivery, attack protection
Location: San Francisco, USA
Data region: Global (multi-region)
Safeguards: Cloudflare DPA + SCC 2021/914 + Transfer Impact Assessment (Schrems II)
Transfer outside the EU with SCC

Safeguards for transfers outside the EU

For sub-processors that involve a transfer outside the EU — today only Cloudflare, for DNS and CDN — the safeguards in Chapter V GDPR apply:

  • Standard Contractual Clauses (SCC) approved by EU Decision 2021/914;
  • Transfer Impact Assessment (TIA) in line with the Schrems II ruling (CJEU C-311/18);
  • Additional technical measures: end-to-end TLS 1.3 encryption, data limited to DNS metadata and static assets (no sensitive personal data passes through Cloudflare);
  • TIA documentation is available on reasoned request.
For requests or objections: write to info@studiocravero.eu or certified email info.studiocravero@pec.it.