Last updated: June 2026
To deliver our email-authentication service (configuring, monitoring and enforcing DMARC, SPF, DKIM, MTA-STS and BIMI), DMARC Engine engages a small number of third-party sub-processors to process personal data on our behalf. This page lists the sub-processors currently in use and is provided to support the general written authorisation set out in our Data Processing Agreement (DPA) under Article 28(2) of the UK GDPR and EU GDPR. The list below is current as of the "Last updated" date at the top of this page and is reviewed whenever our arrangements change. To subscribe to advance notice of any change to our sub-processors, email privacy@dmarcengine.com and ask to be added to our change-notification list. You have the right to object to the addition or replacement of a sub-processor on reasonable, data-protection-related grounds, as described in our DPA.
| Sub-processor | Purpose | Data processed | Region |
|---|---|---|---|
| Cloudflare, Inc. | Core hosting and infrastructure: compute (Workers), SQL database (D1), object storage (R2), key-value cache (KV), CDN, WAF and DDoS protection, and email routing and sending. | All service data, including account data, domain and DNS configuration, ingested DMARC aggregate (RUA) and failure (RUF) reports, server logs and transactional email content. | Global edge network (data centres in the US, EU and worldwide) |
| Stripe | Payment processing for paid plans (engaged only when you make a payment). | Billing contact details and transaction records. Card and payment-instrument details are entered on and handled directly by Stripe, which is PCI DSS compliant; we do not store full card numbers on our systems. | US / EU / global |
| Cloudflare Email Service / Resend (whichever is active) | Delivery of transactional email such as account, alert and report notifications, sent from a verified sending subdomain. | Recipient email address and the content of the transactional message. | Global |
| Google LLC (Google Analytics & Google Ads) | Website and marketing-campaign analytics, conversion measurement and advertising (including remarketing). Engaged only for visitors who have given prior consent through our cookie banner. | Online identifiers (such as cookie IDs), device and usage/measurement data, approximate location derived from IP, and advertising click identifiers (for example gclid). No account, domain-configuration or DMARC report data is shared. | United States / global |
Where you choose to sign in using a social-login or single sign-on identity provider (Google, Microsoft, LinkedIn, GitHub or Facebook), that provider acts as an independent authentication provider for that sign-in only, processing the identity information you authorise it to share. These providers are not engaged by us as general sub-processors of your service data; their handling of your data is governed by their own privacy terms.
Each sub-processor listed above is engaged under written data-processing terms that impose data-protection obligations no less protective than those in our own DPA, require appropriate technical and organisational security measures, and restrict their use of data to the provision of services to us. Because these providers operate global infrastructure, personal data may be transferred to or accessed from countries outside the United Kingdom or the European Economic Area. Where such transfers occur, we rely on an appropriate safeguard recognised under the UK GDPR and EU GDPR, such as the UK International Data Transfer Agreement (IDTA), the UK Addendum, or the European Commission's Standard Contractual Clauses (SCCs), together with any supplementary measures required to maintain an adequate level of protection. Our hosting and infrastructure provider, Cloudflare, maintains SOC 2 Type II and ISO 27001 certifications for the underlying infrastructure on which the service runs.
We will keep this page up to date and, where required by our DPA, provide advance notice before adding or replacing a sub-processor so that you have the opportunity to object on reasonable, data-protection-related grounds. The "Last updated" date at the top of this page reflects the most recent change to the list. This list is provided in good faith for transparency and may be updated from time to time. For more detail on how we handle personal data generally, see our Privacy Policy. Questions about our sub-processors can be sent to privacy@dmarcengine.com.