This page lists the third-party Sub-processors that ReceiverX LLC, a Texas limited liability company ("ReceiverX"), engages to Process Personal Data on our customers' behalf in connection with the Service. It supplements our Privacy Policy and our Data Processing Addendum (DPA).
We require all Sub-processors to provide a level of data protection consistent with our DPA, including security, confidentiality, and breach-notification obligations.
Stay informed of changes
By default, we email all Tenant administrative and legal contacts of record (in addition to updating this page) when a new or replacement Sub-processor is added. Tenant contacts that wish to receive notices at additional addresses, or to opt a separate distribution list into notifications, may write to legal@receiver-x.com (subject: "Subscribe — sub-processor updates").
We will give at least 30 days' prior notice of any new or replacement Sub-processor by updating this page and notifying Tenant contacts as described above. Where security or continuity requires it (for example, a Sub-processor breach or insolvency), we may engage a replacement on shorter notice and will inform Customers as soon as reasonably practicable.
If a Tenant has a reasonable, documented data-protection objection, contact us within the notice window and we will work in good faith to provide an alternative; if we cannot, the Tenant may terminate the affected portion of the Service for material cause and receive a refund of prepaid, unused fees for the unused portion (see DPA §6.3).
Current Sub-processors
Scroll horizontally to see all columns →
| # | Sub-processor | Role / Service | Location of Processing | Cross-Border Transfer Mechanism |
|---|---|---|---|---|
| 1 | Railway Corp. | Application hosting and compute (web app, API, background workers) | United States | EU SCCs (Module 2/3) + UK Addendum |
| 2 | Neon Inc. | Managed PostgreSQL (Customer data, account, audit logs) | United States | EU SCCs + UK Addendum |
| 3 | Cloudflare, Inc. | DNS, CDN, and WAF/edge security; static site hosting (Pages — marketing site); file storage (R2) | United States; global edge | EU SCCs + UK Addendum |
| 4 | Resend (Resend, Inc.) | Transactional email delivery (verification, password reset, magic-link reports, security notices) | United States | EU SCCs + UK Addendum |
| 5 | Upstash Inc. | Rate limiting and ephemeral cache (Redis) | United States | EU SCCs + UK Addendum |
| 6 | Google LLC | Single sign-on (only if user signs in with Google) | United States; global | EU-US Data Privacy Framework where available; SCCs |
| 7 | Amazon Web Services, Inc. | AI image analysis (AWS Bedrock); ancillary AWS services as needed | United States | EU SCCs + UK Addendum |
| 8 | BunnyWay d.o.o. (bunny.net) | Video content delivery (embedded commodity training videos) | EU (Slovenia); global edge | EEA-based provider; SCCs for onward transfers |
Platform providers (independent controllers / data importers; not DPA Sub-processors for Tenant Customer Content)
The following platforms are not Sub-processors of Customer Content under our DPA. They are independent controllers / data importers that we list here for transparency. Their Processing of Personal Data in connection with the platform is governed by their own terms and privacy policies.
| Platform | Role | Location |
|---|---|---|
| Paddle (Paddle.com Inc. — U.S.; Paddle.com (Canada) Ltd. — Canada; Paddle.com Market Limited — all other countries) | Merchant of record, payment processing, and subscription billing for purchases made on our website; the purchase transaction is between you and Paddle. Acts as an independent business / controller for payments, invoicing, tax calculation and remittance, fraud-prevention, anti-money-laundering, and regulatory purposes; PCI-DSS compliant | United States; Canada; United Kingdom |
| Apple Inc. | Mobile app distribution; in-app purchase processing (where used) under Apple Media Services Terms | United States |
| Google LLC (Google Play) | Mobile app distribution; in-app purchase processing (where used) under Google Play terms | United States |
"Cross-Border Transfer Mechanism" describes the safeguard we rely on for transfers from the EEA, the UK, or Switzerland to the United States or other third countries. Where a Sub-processor self-certifies under the EU-US, UK Extension to the EU-US, or Swiss-US Data Privacy Framework, we may rely on that certification for the relevant transfer leg.
Affiliates
If we engage our own affiliates (entities under common control) as Sub-processors for support, sales, or security functions, they will be subject to the same data-protection obligations described above and will be added to the table above. (Billing and payment processing are handled outside processor scope under DPA §2.3.)
Questions
For DPA, sub-processor, or data-protection questions, contact privacy@receiver-x.com or legal@receiver-x.com.