This register details the authorized third-party subprocessors who process personal data on behalf of Consent Shield operators under strict Data Processing Addendum (DPA) mandates.
Before onboarding any infrastructure or analytics partner, Consent Shield executes a exhaustive compliance vetting protocol. We evaluate transfer mechanism security, cryptographic protection at rest, geographic routing isolation, and operational standard compliance (ISO 27001, SOC 2 Type II).
| Entity Name | Jurisdiction & Location | Processing Purpose | Data Elements Transferred |
|---|---|---|---|
| Amazon Web Services, Inc. | United States / EU Regions | Secure Cloud Hosting & Core Enclave Execution | Encrypted Telemetry Logs, IP Coordinates, Session Identifiers |
| Google Cloud Platform (GCP) | United States / EU Regions | Analytical Compute, BigQuery Storage & ML Processing | Aggregated Tracking Metrics, Risk Scores, System Logs |
| Cloudflare, Inc. | Global CDN / US & EU Points | DDoS Protection, Web Application Firewall & Edge Cache Routing | Network Headers, IP Address, TLS Cipher Metadata |
| Stripe, Inc. | United States | Payment Processing & Invoice Lifecycle Infrastructure | Credit Card Tokens, Corporate Address, Invoice Identifiers |
| Twilio, Inc. (SendGrid) | United States | System Notification SMTP & Authentication Routing | Operator Email Addresses, Dynamic OTP Tokens, Security Digests |
| Datadog, Inc. | United States / EU (Isolated) | Core Network Monitoring, Logs, & Application APM Metrics | System Latency Reports, Infrastructure Logs (Anonymized) |
Under our standard Operator Data Processing Addendum, EU sovereign customers can enforce strict regional localization configurations. When active, our model isolates AWS/GCP routing exclusively to Dublin (eu-west-1) and Frankfurt (eu-central-1) regions, with no secondary replication or transit permitted outside European Union borders.