1. Scope
This list covers all external service providers that process personal data on behalf of RoadReview GmbH (processing under Art. 28 GDPR). It supplements our privacy policy and is updated whenever something material changes — new sub-processor, change of hosting region, additional components. B2B customers with their own DPA receive the current list as a PDF upon request.
Some of the sub-processors listed below only apply to the RoadReview app, not to the marketing website. We list them here anyway, because the privacy statement of RoadReview GmbH is meant to be understood holistically. The Scope column makes the attribution transparent.
2. Current sub-processors
| Provider | Purpose | Location | DPA in place | GDPR mechanism | Scope |
|---|---|---|---|---|---|
| Railway Corp. (USA) | Website hosting and private contact enquiry storage | EU runtime/storage: Amsterdam; US provider | Railway DPA; applicable arrangements available from our privacy contact | See Railway DPA and standard contractual clauses | Website |
| Mailgun Technologies, Inc. (USA) | Sending transactional emails for the app (e.g. invitation, password reset) | EU region (Frankfurt) | Yes — Mailgun DPA | SCC + DPF | App |
| Google Ireland Ltd. (Maps Platform — Maps & StreetView) | Map and 3D StreetView rendering of trip routes and error locations in the app | Primarily EU/EEA; potentially global Google infrastructure | Yes — Google Cloud DPA (Maps Platform) | SCC + DPF (for any incidental US transfers) | App |
| Functional Software, Inc. dba Sentry (USA) | Error and crash reporting for the mobile app (stack traces, device metadata) | EU region (Frankfurt) — Sentry EU data residency | Yes — Sentry DPA | SCC + DPF | App |
| rapidmail (delivery adapter; disabled by default) | Newsletter registration and confirmation email after approval and complete configuration | Confirm against the actual provider agreement before activation | Activation requires verified processing arrangements; no signed agreement is asserted | Verify before activation; planning does not establish an active transfer | Website |
Legend: SCC = EU Standard Contractual Clauses (Art. 46 (2)(c) GDPR). DPF = EU-US Data Privacy Framework (Art. 45 GDPR, supplementing SCCs for US providers with self-certification). Scope indicates whether the sub-processor handles data of the website, the app, or both.
3. Own infrastructure (no sub-processors)
The following components run on our own infrastructure; they are not sub-processors within the meaning of Art. 28 GDPR and are therefore not listed in the table above:
- Rybbit (cookieless web analytics,
self-hosted at
rybbit.internal.thecodecave.de) — see Privacy § 4 and /en/cookies. - Cloud backend (NestJS on Kubernetes, PostgreSQL via Prisma) — operated on our own Kubernetes infrastructure within the EU.
- Fonts (Inter, Inter Tight, JetBrains Mono)
— served locally from
/fonts/; no connection to Google Fonts or any other CDN.
Note on Firebase Authentication: we are currently evaluating Firebase Auth (Google Ireland Ltd.) for student and instructor authentication in the app. Once Firebase Auth is in production use, we will add the corresponding entry to the table and update the „last updated" date.
4. Changes to this list
We update this list whenever something material changes in our roster of sub-processors. B2B customers with their own DPA are additionally informed in advance about planned new sub-processors; objection rights follow the rules of the respective DPA.
For DPA copies or questions on individual sub-processors please email aleks@roadreview.de. The latest version of this page is always available at roadreview.de/en/subprocessors.