Please note: this document is a draft and remains subject to legal review and approval. In its present version it does not yet constitute a legally binding agreement.
Version of 2026-07-27. We update this document as soon as the underlying processing operations, systems or sub-processors change.
For a signed version, for questions regarding its content or for the conclusion of an individual data processing agreement, please contact hello@erseni.com.
The following overview lists all external service providers that we engage as sub-processors within the meaning of Art. 28 GDPR and with which personal data of the service is processed, that is content data, metadata or account data. Not listed are services that exclusively receive anonymous technical fault signals without any personal reference; personal details are removed before such signals are transmitted. None of the service providers listed obtains access to plaintext content.
We announce changes to the above list of sub-processors in advance. The controller may object to a change on important data protection grounds; the details are governed by the section on sub-processors in the data processing agreement.
The actual content is encrypted on the end device beforehand. Neither we nor the service providers listed hold the key required for decryption.
We operate the following systems ourselves, as Erseni Ltd. They are not sub-processors within the meaning of Art. 28 GDPR: there is neither an external contractual partner nor a separate data processing agreement to be concluded, and the right of objection described above does not apply to them. We list them here so that it is transparent which self-operated systems process data of the service and where they are located. These systems, too, obtain no access to plaintext content.
These systems run on the infrastructure of the hosting provider listed above and are covered by its entry to that extent.