Legal
Subprocessors
Last updated: 15 July 2026
vatnode engages the following subprocessors to provide the Service. We require all subprocessors to maintain at least the same level of data protection as required under GDPR.
Current subprocessors
| Subprocessor | Location | Purpose | Data shared | Safeguard |
|---|---|---|---|---|
Vultr Holdings LLC Vultr Holdings LLC | Frankfurt, Germany (EU) | Server infrastructure (database, API, and web hosting) | All personal data stored by vatnode (account data, API keys, check history, subscriptions) | None required — processor in EU/EEA |
Mollie Mollie B.V. | Amsterdam, Netherlands (EU) | Payment processing (card payments and recurring mandates) | Billing name and address, email, and the payment/mandate identifiers we store (Mollie customer, mandate, subscription and payment IDs) | None required — processor in EU/EEA; written DPA under GDPR Art. 28 |
Resend Resend, Inc. | USA | Transactional email — account notifications and onboarding survey forwarding | Email address, display name, onboarding survey answers (when submitted) | SCCs (Module 2) |
Cloudflare Cloudflare, Inc. | USA (global edge network; EU traffic served from EU data centres where available) | CDN, DNS, reverse proxy and DDoS/WAF protection — all inbound traffic to vatnode passes through it | Connection metadata processed in transit only (IP address, request URL, request headers, TLS metadata); no personal data stored at rest | SCCs (Module 2); Cloudflare Data Processing Addendum |
Sentry Functional Software, Inc. (d/b/a Sentry) | USA | Application error monitoring — captures backend exceptions and stack traces | Error events and stack traces with a pseudonymous account identifier; client IP addresses, credentials and the queried VAT number are stripped before events leave our servers | SCCs (Module 2) |
Google (analytics & ads — consent only) Google Ireland Limited / Google LLC | USA | Website analytics (Google Analytics 4) and ads measurement (Google Ads) — loaded only after you grant the matching cookie consent | Website usage events, cookie/device identifiers and truncated IP of consenting visitors only; not applied to Customer API data | SCCs (Module 2); processed only with your consent |
Microsoft (Clarity — consent only) Microsoft Ireland Operations Limited / Microsoft Corporation | USA | Product analytics (Microsoft Clarity session insights) — loaded only after you grant analytics consent | Anonymised session interactions and device identifiers of consenting visitors only; not applied to Customer API data | SCCs (Module 2); processed only with your consent |
Cloudflare fronts all vatnode traffic and processes connection metadata (including IP addresses) in transit only. Google and Microsoft are engaged solely for optional website analytics and ads measurement and receive data only from visitors who have granted the corresponding cookie consent; they do not process the personal data you submit to the vatnode API. Self-hosted, cookieless Umami analytics runs on our own EU infrastructure and is not a separate subprocessor.
Change notification
We will notify all active customers at least 14 days before adding or replacing a subprocessor. Notifications are sent to the email address on your account.
You may object to any such change by contacting [email protected] within 14 days of the notification. We will work with you in good faith to resolve the objection; if we cannot, you may terminate the affected service without penalty.
VIES and national registries
For VAT validation, vatnode transmits the queried VAT number (and, where configured, your requester VAT number) to the VIES service operated by the European Commission, and to national tax authority or company registry APIs of covered EU member states.
These entities act as independent data controllers, not subprocessors of vatnode. Transmission is within the EU.
Infrastructure tooling
We use self-hosted deployment and monitoring tools (Coolify, Docker, Redis, PostgreSQL) that run on our Vultr server in Frankfurt. These are software we operate directly and do not constitute separate subprocessors in the GDPR Art. 28 sense — data does not leave our infrastructure to reach them.
Contact
For questions about subprocessors: