No tracking. No cookie wall.·EU-hosted (Hetzner) · Cloudflare edge under SCCs
    Legal reference

    Vendor DPA directory — where to find each provider's Data Processing Agreement.

    A Data Processing Agreement (DPA) is the contract GDPR Article 28 requires whenever a company (the controller) has a vendor (the processor) handle personal data on its behalf. It sets out what the vendor may do with the data, the security measures it commits to, and the rules for using its own sub-processors.

    Building a processor roster means locating each vendor's own DPA on the vendor's own site. This page collects those links in one place, so you do not have to search each vendor's site individually.

    How a DPA becomes binding varies by vendor, and often by plan or product: some incorporate it into their standard terms, some require acceptance in your account, and some ask for a signature. The vendor's own page — linked below — states which applies. This page is informational, not legal advice: confirm the current terms directly with the vendor before relying on them.

    Directory

    29 vendor DPAs

    Search by vendor name. Every link goes straight to the vendor's own site — never a mirror or aggregator.

    VendorNotesLink
    VercelView DPA
    SupabaseView DPA
    ResendView DPA
    MicrosoftMicrosoft's own short link for the Products and Services Data Protection Addendum.View DPA
    AWSView DPA
    Google CloudView DPA
    GitHubStates it forms part of the GitHub Customer Agreement for GitHub's Online Services.View DPA
    StripeView DPA
    CloudflareView DPA
    OpenAIView DPA
    AnthropicView DPA
    SlackView DPA
    AtlassianView DPA
    NotionView DPA
    HubSpotView DPA
    ZoomView DPA
    DatadogView DPA
    SentryView DPA
    TwilioView DPA
    Okta / Auth0Okta's DPA; Auth0 (acquired by Okta in 2021) is covered by the same document family.View DPA
    MongoDB AtlasView DPA
    HetznerHetzner labels this PDF a sample; the operative DPA is concluded inside your Hetzner account.View DPA
    ScalewayContracts index page; the Data Processing Agreement is listed among the agreements there.View DPA
    Mailchimp (Intuit)View DPA
    FigmaView DPA
    SalesforceView DPA
    PagerDutyView DPA
    IntercomView DPA
    LinearView DPA
    FAQ

    Questions about vendor DPAs

    If your question is not here, email us — every message gets a human answer.

    Do I need to sign a DPA, or is it automatic?

    It varies by vendor, and often by plan or product. Some vendors incorporate the DPA into their standard terms, so accepting the terms is what makes it binding; others require acceptance inside your account, and some ask you to sign and return the document. The vendor's own DPA page states which applies — check it when you add the vendor to your processor roster. GDPR Article 28(9) allows the contract to be in electronic form, but a published DPA page binds the parties only once it is incorporated into or executed as part of your agreement with the vendor.

    What are SCCs and when do they apply?

    Standard Contractual Clauses (SCCs) are the European Commission's pre-approved contract terms, one of the Article 46 safeguards for transferring personal data outside the EU/EEA. They apply when a transfer goes to a country without an adequacy decision and no other safeguard covers it. Transfers to US organizations certified under the EU–US Data Privacy Framework instead rely on the Commission's adequacy decision under Article 45, which needs no SCCs. Many of the DPAs listed above incorporate SCCs by reference to cover their non-EEA processing.

    How do I track my processors?

    A processor roster lists every vendor that processes personal data on your behalf: what it processes, where, and under which contract. It is the vendor inventory that feeds your GDPR Article 30 record of processing activities — the statutory record itself has its own required fields (purposes, categories of data and data subjects, transfers, retention), so keep both. Build the roster from your own vendor list, add each vendor's DPA link and processing location, and review it whenever a vendor is added or removed.

    Where do subprocessor lists live?

    Most vendors publish a current sub-processor list, usually on the same page as the DPA or linked from it — check the DPA link in the table above for the vendor you need. Some provide the list through a customer portal or on request instead. Ansvar publishes its own sub-processor list openly, with each sub-processor's role, processing location, and transfer mechanism.

    Need the law behind these obligations?

    GDPR Article 28, the SCCs, and every regulation a processor roster touches are served through Ansvar's gateway with citations attached, straight into the AI client you already use.