RedPatron Rechtliches
Subprocessor List
The published production-provider approval and data-transfer status.
Effective date: 4 August 2026
Document version: 1.0
This page must contain the actual production providers before personal data is sent to them. A vendor name may be published only after contract, DPA, transfer mechanism, security review and data-flow verification are complete.
| Function | Provider | Legal entity/country | Data | Location/transfer safeguard | Status |
|---|---|---|---|---|---|
| Application hosting | NOT YET APPROVED | — | Account/application data | — | Production transfer blocked |
| Object/media storage and CDN | Cloudflare, Inc. / contracted Cloudflare entity | Contract-dependent | Media, asset metadata, IP/security data | Complete DPA and transfer assessment | Approval required |
| Video processing/streaming | NOT YET APPROVED | — | Video/audio and metadata | — | Production transfer blocked |
| Identity and age assurance | NOT YET APPROVED | — | Identity, age and verification evidence | — | Creator/fan verification blocked |
| Content moderation/CSAM safety | Cloudflare CSAM Scanning plus any approved moderation provider | Contract-dependent | Hashes/signals and limited media | Complete lawful-basis/DPA assessment | Approval required |
| Customer payments | Segpay or CCBill, not both implicitly | Contract-dependent | Customer/transaction/fraud data | Provider notice shown at checkout | Checkout blocked until selected/approved |
| Creator payouts | Paxum or provider-approved payout partner | Contract-dependent | Identity, beneficiary, payout and tax data | Provider notice in onboarding | Payout blocked until selected/approved |
| Email/SMS | NOT YET APPROVED | — | Contact and delivery data | — | Production messaging blocked |
| Support/ticketing | NOT YET APPROVED | — | Account, support and attachments | — | Production transfer blocked |
| Analytics | NOT YET APPROVED | — | Consent-dependent usage data | — | Non-essential scripts blocked |
Users are notified of material additions where required. Processor entries do not cover providers acting as independent controllers; those providers must be separately identified in the relevant flow and privacy notice.