Subprocessors

OpenCredia engages the subprocessors below to host and operate production OpenCredia. This list covers vendors that process personal data on our behalf. For questions about this list or privacy, contact us at [email protected].

Last updated: September 1, 2026

1. About this list

A subprocessor is a third party engaged by OpenCredia to process personal data in order to provide the OpenCredia service.

OpenCredia distinguishes Account and operator data (sign-in, workspace membership, support) from issuer-supplied Recipient and credential data (recipient identifiers, credential records, and related artifacts that organizations choose to issue). Organizations control how they use issuer-supplied Recipient and credential data; OpenCredia processes that data to provide the service.

More than one subprocessor may touch Account data, Recipient or credential-related data, or both, depending on the role of the service. We do not claim that a single vendor alone handles Recipient data.

Hosting and processing locations below reflect confirmed configuration for OpenCredia production, or are described as configured for production when region placement can vary within a vendor's network. We do not claim EU-only residency or a single cloud region unless that is how production is configured and documented here.

We may update this list as infrastructure changes. Material additions will be reflected on this page.

2. Current subprocessors

The vendors below process personal data for OpenCredia production as described for each entry.

Netlify

Full legal name: Netlify, Inc.

Address: 101 2nd Street, San Francisco, CA 94105, United States

Hosting / processing location: As configured for OpenCredia production on Netlify's platform

Description of service: Application hosting and edge delivery for the OpenCredia web application and related serverless functions.

Purpose of processing: Host and deliver the OpenCredia application, serve public and authenticated pages, and run production application workloads.

Data processed: Account and operator request and session data as it flows through the hosted application. May also process Recipient and credential-related request data when those flows are handled by the OpenCredia application (for example issuance, claim, or verification requests).

More information: Netlify Privacy and Netlify Security.

Neon

Full legal name: Neon, LLC

Address: 2261 Market Street, Suite 22601, San Francisco, CA 94114, United States

Hosting / processing location: As configured for OpenCredia production on Neon

Description of service: Managed PostgreSQL database for OpenCredia application, account, organization, and credential data.

Purpose of processing: Store and retrieve application state needed to operate OpenCredia, including accounts, workspaces, credentials, and related records.

Data processed: Account and operator data, organization and issuer profile data, and issuer-supplied Recipient and credential data stored in the production database.

More information: Databricks Privacy Notice (covers Neon, LLC) and Neon Trust Center.

Cloudinary

Full legal name: Cloudinary Ltd.

Address: 6201 America Center Drive, Suite 220, San Jose, CA 95002, United States

Hosting / processing location: As configured for OpenCredia production on Cloudinary

Description of service: Media storage and delivery for public badge images, issuer logos, and similar visual assets.

Purpose of processing: Store, transform, and deliver media used on issuer profiles, credentials, and related public pages.

Data processed: Public media assets uploaded or referenced by organizations (badge art, logos, and similar). These assets may appear alongside credentials. OpenCredia does not use Cloudinary as the primary store for recipient names or email addresses, though issuer-chosen image content could include personal information if an organization embeds it.

More information: Cloudinary Privacy.

Resend

Full legal name: Plus Five Five, Inc. (doing business as Resend)

Address: 2261 Market Street #5039, San Francisco, CA 94114, United States

Hosting / processing location: As configured for OpenCredia production on Resend

Description of service: Transactional email delivery for operational and account-related messages.

Purpose of processing: Send magic links, invitations, security messages, and other transactional email required to operate OpenCredia.

Data processed: Account and operator email addresses and message content for transactional mail. May also process Recipient email addresses and related message content when OpenCredia sends credential-related transactional email (for example invitations or claim messages).

More information: Resend Privacy Policy.

Better Stack

Full legal name: Better Stack, Inc.

Address: 651 N Broad Street, Suite 206, Middletown, DE 19709, United States

Hosting / processing location: Log ingest for production is configured to Better Stack's EU (Falkenstein) ingest endpoint; status page hosting as configured for OpenCredia production. Public status page: https://status.opencredia.com

Description of service: Uptime status pages and operational logging for production observability.

Purpose of processing: Monitor service availability, publish status updates, and retain operational logs used to operate and troubleshoot OpenCredia.

Data processed: Operational telemetry and logs that may include Account or operator identifiers, request metadata, and similar service data. Not used as the primary store of Recipient credential databases.

More information: Better Stack Privacy.

Sentry

Full legal name: Functional Software, Inc. (doing business as Sentry)

Address: 45 Fremont Street, 8th Floor, San Francisco, CA 94105, United States

Hosting / processing location: As configured for OpenCredia production on Sentry

Description of service: Application error monitoring and performance diagnostics.

Purpose of processing: Detect, diagnose, and reduce application errors and performance issues in production.

Data processed: Error and performance event data that may include Account or operator context and limited request metadata. OpenCredia does not intend Sentry to be a store of Recipient credential databases; diagnostic payloads can still include incidental personal data present in an error event.

More information: Sentry Privacy Policy and Sentry Security.

Google

Full legal name: Google LLC

Hosting / processing location: As configured for OpenCredia production when Sign in with Google is enabled

Description of service: Sign in with Google authentication, only when that feature is enabled for the deployment.

Purpose of processing: Authenticate users who choose Google as a sign-in method for OpenCredia accounts.

Data processed: Account authentication data needed for Sign in with Google (such as Google account identifiers and profile fields returned for sign-in). Not used to store issuer-supplied Recipient credential databases.

More information: Google Privacy Policy.

Microsoft

Full legal name: Microsoft Corporation

Hosting / processing location: As configured for OpenCredia production when Sign in with Microsoft is enabled

Description of service: Sign in with Microsoft authentication via Microsoft Entra ID, only when that feature is enabled for the deployment.

Purpose of processing: Authenticate users who choose Microsoft as a sign-in method for OpenCredia accounts.

Data processed: Account authentication data needed for Sign in with Microsoft (such as Microsoft Entra account identifiers and profile fields returned for sign-in). Not used to store issuer-supplied Recipient credential databases.

More information: Microsoft Privacy Statement.

3. What is not listed

Customer organizations may connect their own SSO identity providers. Those IdPs process identity data under the customer's relationship with the IdP and are not OpenCredia subprocessors.

OpenCredia uses authentication software libraries in-process. Libraries that do not receive personal data as a separate hosted service are not listed here.

Source control, CI, and secrets-management tools used to build and operate OpenCredia are not listed when they are not used as production processors of Account or Recipient personal data for the live service.

4. Contact

For privacy or subprocessor questions, contact OpenCredia at [email protected]. See also our Privacy Policy.

Subprocessor questions: [email protected]