ssm.ro Docs
Compliance & Data Protection

Subprocessors

The canonical list of subprocessors and third-party vendors that process data for SSM.ro

To provide the service, SSM.ro uses a restricted set of trusted subprocessors and third-party vendors. All of them receive only the data necessary for their role, subject to data protection clauses.

Third Parties vs. AWS, depending on the model

  • Dedicated Model (Enterprise): the client's data is processed entirely within the client's dedicated AWS infrastructure (email via AWS SES) — no third-party subprocessors for client data.
  • Shared Model (SaaS): uses a restricted set of third-party subprocessors, notably Postmark for transactional email.
  • GitHub is not a subprocessor — it holds only the source code and does not receive client data. Sentry and New Relic receive only technical telemetry, with no document content or personal data.

List of subprocessors

SubprocessorRoleData processedGuarantee / authentication
Heroku (Salesforce)Hosting platform (application, Postgres, Redis)Application and account data (encrypted at rest)Managed provider; TLS; proprietary certifications
Amazon Web Services (AWS)Document storage (S3); dedicated services (Enterprise)Document contentSSE, Block Public Access; least-privilege IAM
Electronic Signature ProviderQualified electronic signature (eIDAS QTSP)Document hash (standard); signatory identification data only exceptionally (qualified certificate issuance); full document if the provider requires complete transmissionHTTPS + mTLS or API token
PostmarkTransactional email (Shared Model)Email, notification/OTP contentHTTPS API, dedicated server token
Amazon SES (AWS)Transactional email (Dedicated Model)Email, notification/OTP contentHTTPS; AWS IAM-scoped credentials
New RelicObservability / APMTechnical diagnostic telemetry (performance/error traces) + the associated account identifier; generally no personal dataTLS; per-account key
SentryError monitoringRuntime exception traces + the identifier of the account that generated the error; generally no personal dataTLS; per-project DSN
PlausibleTraffic analytics — only the ssm.ro marketing siteAggregate traffic statistics; cookieless, no personal dataHosted in the EU (no transfer outside the EEA)

Principles

  • Minimization — each subprocessor receives only the data strictly necessary for its role.
  • Processing agreements — relationships are governed by contractual data protection clauses (DPA / GDPR clauses).
  • Security in transit — communication with all vendors takes place over TLS; the electronic signature provider uses mTLS or an API token.
  • Due diligence — vendors are assessed at selection — see the Vendor Management Policy.

Differs depending on the model

Both models use AWS microservices (S3, API Gateway, Lambda, CloudWatch Logs). The difference lies in the allocation method: shared infrastructure in the Shared Model, versus dedicated per-client resources in the Enterprise Model.

Transfers

The only possible transfers outside the EEA come from technical monitoring vendors (New Relic, Sentry), covered by standard contractual clauses. Plausible is hosted in the EU and does not involve any transfer. Details and guarantees: International Transfers.