Sub-processors

Last updated: August 22, 2026

SiteLetter is operated by Donatas Petrauskas, acting as a sole proprietor under individuali veikla (individual activity) registered in Lithuania, registration number 1534445 ("SiteLetter").

This page is the current list of third-party providers SiteLetter uses to run the Service. Where SiteLetter acts as your processor, for example when it monitors websites on your instruction, these providers are its sub-processors under GDPR Article 28(2) and 28(4). Where SiteLetter acts as controller, for example for your own account and billing data, they are its processors. The list is the same either way, so it is published once.

Read this together with the Privacy Policy, which explains what data SiteLetter collects and why. If you have signed SiteLetter's Data Processing Agreement, this page is the list referred to in its sub-processor clause.

1. How Changes Are Notified

SiteLetter publishes an intended addition or replacement on this page, with the date the change takes effect, before the new provider begins processing data. Every change is recorded in the log in Section 4, so you can see what was added and what was removed over time.

There is no mailing list. SiteLetter does not operate a broadcast notification channel and does not undertake to email every customer individually, so notice is given by publication here and it is up to you to check. If you would rather be told directly, email support@siteletter.com and ask to be added to the notice list. That list is kept by hand.

You can object to an intended change on reasonable data protection grounds by writing to support@siteletter.com. The Data Processing Agreement sets out what happens next.

2. Current Sub-processors

Current as of August 22, 2026.

Provider Purpose Data Processed Location Transfer Mechanism
Amazon Web Services Hosting and compute, object storage, content delivery (CloudFront), and email delivery (SES). All service data held in storage: screenshots, captured page HTML, extracted page text, thumbnails and favicons. All outbound email, including recipient addresses and message content. Primary region eu-north-1 (Stockholm, Sweden). Uptime probe functions also run in us-east-1 (USA) and ap-southeast-1 (Singapore); they receive a hostname and a path and return only an up/down result. CloudFront edge locations serve North America, Europe and Israel. Pending. No data processing agreement is signed yet; one is being put in place. Storage and the database stay in the EU either way.
MongoDB Atlas Primary database. All account and monitoring data, including recipient email addresses, client records, report snapshots and activity log entries. AWS eu-central-1 (Frankfurt, Germany). Data is stored and processed in the EU. No data processing agreement is signed yet; one is being put in place.
OpenAI Ireland Ltd Classifying visual changes between two captures of a monitored page. Website screenshot images, plus the before/after text of the regions that changed. No redaction is applied, so anything a monitored page displayed at the moment of capture is included. Contracting entity in Ireland, because SiteLetter is established in the EEA. Processing takes place in the United States. Data processing agreement signed 17 June 2026. EU Standard Contractual Clauses are incorporated through its Schedule 1.
Stripe Payment processing and subscription billing. Account holder's name and email address, billing details entered directly on Stripe's own hosted pages, and a SiteLetter organisation identifier. No card data passes through or is stored by SiteLetter. United States. Pending. No data processing agreement is signed yet; one is being put in place.
Sentry Backend error tracking. Error stack traces, request URL, method and headers, and the IP address that reaches the API. Request bodies are dropped and credential-bearing headers are redacted before the event is sent. United States. The error data is stored there, not only routed through it. Pending. No data processing agreement is signed yet; one is being put in place.
Cloudflare (Turnstile) Anti-bot challenge on the signup form and the free public tools. The visitor's browser loads the widget from Cloudflare, so Cloudflare receives the visitor's IP address and browser signals. SiteLetter's server-side verification sends only the secret key and the challenge token, and does not forward the visitor's IP. Cloudflare's global network. Pending. No data processing agreement is signed yet; one is being put in place.
Cloudflare (Web Analytics) Cookieless traffic statistics on the marketing site. Page URL, referrer, country, browser and device type. The beacon is loaded by the visitor's browser, so the request itself carries an IP address and user agent to Cloudflare. No cookies are set, no IP address is stored, and no fingerprinting is used. Cloudflare's global network. Pending. No data processing agreement is signed yet; one is being put in place.
Cloudflare (Email Routing) Inbound mail forwarding for the siteletter.com domain. Email sent to a siteletter.com address, including the sender address, subject and message body, in transit to the destination mailbox. Cloudflare's global network. Pending. No data processing agreement is signed yet; one is being put in place.
Umami Cookieless traffic statistics on the marketing site, alongside Cloudflare Web Analytics. Page URL, referrer, campaign tags, country, browser and device type. The script is loaded by the visitor's browser, so the request itself carries an IP address and user agent to Umami. No cookies are set, no IP address is stored, and no fingerprinting is used: repeat visits are counted by a salted hash computed on Umami's servers and rotated. It runs on siteletter.com only and never on the app, so no account, client or monitoring data reaches it. Umami Cloud, EU region, selected at account registration. Data is stored and processed in the EU region. No data processing agreement is signed yet; one is being put in place.

Where a cell reads pending, no data processing agreement with that provider has been signed yet and one is being put in place. SiteLetter would rather say that plainly than name a safeguard that is not in force. SiteLetter holds no security certification and makes no certification claim for itself; each provider's own certifications are a matter for that provider.

3. What Is Not on This List

  • Slack and Microsoft Teams. If you configure an alert to an incoming webhook, SiteLetter posts the alert text to the address you supplied. That destination is your own recipient, not a SiteLetter sub-processor, and SiteLetter does not control how the platform behind it processes the data.
  • Domain registries and registrars. Domain expiry checks query public RDAP and WHOIS servers directly. The query carries the hostname being checked and no personal data, and it uses open directory services rather than a commercial vendor.
  • Google. Lighthouse audits run inside SiteLetter's own scan task using a local browser. No PageSpeed Insights API or other Google service is called, web fonts are self-hosted, and there is no Google sign-in.
  • The sites you monitor. SiteLetter fetches pages from the websites you add. Those sites are the subject of the monitoring, not providers acting on SiteLetter's behalf.

4. Change Log

Newest first. Entries are added, never rewritten, so the history stays readable.

Date Change
August 22, 2026 Section 1 no longer fixes the notice period at 30 days. An intended change is still published here before the new provider begins processing, and you can still object on data protection grounds; only the fixed deadline is gone.
August 22, 2026 Umami added for cookieless traffic statistics on the marketing site, alongside Cloudflare Web Analytics, with data stored in its EU region. It runs on siteletter.com only and receives no account, client or monitoring data, so SiteLetter is the controller for it rather than a processor.
August 21, 2026 First publication of this page. The list above is the set of sub-processors in use on this date, recorded as the starting point. Changes before this date were not logged, with the one exception below.
June 17, 2026 OpenAI: data processing agreement signed, incorporating EU Standard Contractual Clauses. No change to the list itself, a change to the safeguard covering an existing transfer.

5. Contact

Questions about this list, a request for the Data Processing Agreement, or an objection to a change: email support@siteletter.com.