Subprocessors
The canonical list of subprocessors and third-party vendors that process data for SSM.ro
To provide the service, SSM.ro uses a restricted set of trusted subprocessors and third-party vendors. All of them receive only the data necessary for their role, subject to data protection clauses.
Third Parties vs. AWS, depending on the model
- Dedicated Model (Enterprise): the client's data is processed entirely within the client's dedicated AWS infrastructure (email via AWS SES) — no third-party subprocessors for client data.
- Shared Model (SaaS): uses a restricted set of third-party subprocessors, notably Postmark for transactional email.
- GitHub is not a subprocessor — it holds only the source code and does not receive client data. Sentry and New Relic receive only technical telemetry, with no document content or personal data.
List of subprocessors
| Subprocessor | Role | Data processed | Guarantee / authentication |
|---|---|---|---|
| Heroku (Salesforce) | Hosting platform (application, Postgres, Redis) | Application and account data (encrypted at rest) | Managed provider; TLS; proprietary certifications |
| Amazon Web Services (AWS) | Document storage (S3); dedicated services (Enterprise) | Document content | SSE, Block Public Access; least-privilege IAM |
| Electronic Signature Provider | Qualified electronic signature (eIDAS QTSP) | Document hash (standard); signatory identification data only exceptionally (qualified certificate issuance); full document if the provider requires complete transmission | HTTPS + mTLS or API token |
| Postmark | Transactional email (Shared Model) | Email, notification/OTP content | HTTPS API, dedicated server token |
| Amazon SES (AWS) | Transactional email (Dedicated Model) | Email, notification/OTP content | HTTPS; AWS IAM-scoped credentials |
| New Relic | Observability / APM | Technical diagnostic telemetry (performance/error traces) + the associated account identifier; generally no personal data | TLS; per-account key |
| Sentry | Error monitoring | Runtime exception traces + the identifier of the account that generated the error; generally no personal data | TLS; per-project DSN |
| Plausible | Traffic analytics — only the ssm.ro marketing site | Aggregate traffic statistics; cookieless, no personal data | Hosted in the EU (no transfer outside the EEA) |
Principles
- Minimization — each subprocessor receives only the data strictly necessary for its role.
- Processing agreements — relationships are governed by contractual data protection clauses (DPA / GDPR clauses).
- Security in transit — communication with all vendors takes place over TLS; the electronic signature provider uses mTLS or an API token.
- Due diligence — vendors are assessed at selection — see the Vendor Management Policy.
Differs depending on the model
Both models use AWS microservices (S3, API Gateway, Lambda, CloudWatch Logs). The difference lies in the allocation method: shared infrastructure in the Shared Model, versus dedicated per-client resources in the Enterprise Model.
Transfers
The only possible transfers outside the EEA come from technical monitoring vendors (New Relic, Sentry), covered by standard contractual clauses. Plausible is hosted in the EU and does not involve any transfer. Details and guarantees: International Transfers.