Subprocessors
These providers process personal data on our behalf, under contract, only to deliver their part of the service. Customers are notified at least 30 days before a new subprocessor is added and may object under our Data Processing Agreement.
Hostinger
- Entity
- Hostinger International Ltd.
- Purpose
- Hosting of the platform (virtual private server, database, backups) and, for now, outgoing email
- Personal data
- All platform data, including account data and the visitor telemetry customers send us
- When
- Always
- Location
- VPS data-centre region as provisioned
- Transfer basis
- Within the provider's infrastructure; standard contractual terms of the provider
Anthropic
- Entity
- Anthropic, PBC
- Purpose
- AI analysis of suspicious files and findings, the console assistant, and code-fix explanations
- Personal data
- Excerpts of flagged files, finding details, summaries of the customer's console; the questions a user types
- When
- Only for companies whose owner switched AI analysis on (off by default), and for questions typed into the assistant
- Location
- United States
- Transfer basis
- Cross-border transfer (DPDP s.16; GDPR Art. 46 — provider DPA with SCCs). API inputs are not used to train models under the provider's commercial terms
Razorpay
- Entity
- Razorpay Software Private Limited
- Purpose
- Payment collection for invoices
- Personal data
- Billing contact name, email, phone, invoice amounts; card/UPI details are entered on Razorpay's page, never ours
- When
- When an invoice is paid online
- Location
- India
- Transfer basis
- None (India)
Team Cymru / RDAP registries
- Entity
- Team Cymru Inc.; regional Internet registries via rdap.org
- Purpose
- Looking up which network an IP address belongs to (attack attribution, CDN/origin detection)
- Personal data
- IP addresses seen in monitored traffic and security events
- When
- For addresses that appear in security events or traffic on agent-monitored sites
- Location
- United States / registries worldwide
- Transfer basis
- Cross-border; a single IP address per lookup, cached for days; no other data accompanies it
Services you connect
Sent on your instruction to providers you chose — your own providers, not ours:
- Slack, Microsoft Teams, Telegram, your own webhook — Alert text: site name, what happened, a link back to the console
- GitHub, Bitbucket — The access token you provide, used to clone the repositories you link for code audit
Lookups that carry no personal data
- Google Safe Browsing and DNS blocklists — your site's domain and server IP, to check blacklisting
- WPScan — names and versions of installed plugins/themes, to check for known vulnerabilities
- Have I Been Pwned — the first 5 characters of a password's SHA-1 hash (k-anonymity), never the password
Get notified
Company owners receive changes to this list by email. Anyone else can ask to be told at privacy@dxcslabs.com.