Sub-processors
Last updated: May 2026
Justido Design operates through two legal entities — Justido GmbH (data controller for EU/EEA and DACH visitors) and Justido LLC (data controller for US visitors). Both entities engage the same small number of third-party providers ("sub-processors") to deliver this marketing site and the AI chat demo. This page lists every direct sub-processor — what they do, what data reaches them, where they sit, and the safeguard in force. The safeguards below cover the EU and US controller chains.
Direct sub-processors
Large-language-model inference for the homepage AI chat demo (Claude Sonnet 4.6 via the Anthropic API).
- Data processed
- Conversation messages typed into the chat demo, plus IP address and request metadata at inference time.
- Location
- United States
- Safeguard
- Anthropic Customer DPA terms apply via API subscription. EU 2021 SCCs and UK IDTA incorporated. Inputs and outputs are not used to train Anthropic's models per the Anthropic API terms.
Website hosting, serverless functions, and edge CDN — serves justido.design including EU-region routing for /de/* traffic.
- Data processed
- Request logs (IP, user agent, path, timestamps), in-transit form data, deployment artefacts.
- Location
- United States; global CDN edge; EU-region (fra1) for /de/* traffic
- Safeguard
- Signed DPA on file. EU 2021 SCCs and UK IDTA incorporated per vercel.com/legal/dpa.
Privacy-friendly web analytics — no cookies, no cross-site tracking, EU-hosted.
- Data processed
- Anonymized pageview events (route, referrer, derived country and device only). No identifiers persist between visits.
- Location
- European Union (Hetzner, Germany)
- Safeguard
- EU-internal processing; data never leaves the EU. DPA available on request. GDPR-compliant by design.
Discovery-call booking widget, calendar management, CRM, and follow-up automation.
- Data processed
- Contact details (name, email, phone), booking metadata, follow-up email and SMS content (when sent), workflow events.
- Location
- United States
- Safeguard
- Signed DPA on file. EU-US Data Privacy Framework + UK Extension + Swiss-US DPF (certified); EU 2021 SCCs and UK IDTA incorporated.
Transactional SMS delivery (booking confirmations, day-of reminders).
Vendor selection is pending. SMS delivery is not yet active; this row will be filled in when a US- and EU-eligible provider is chosen.
We update this list when we add, change, or remove a sub-processor. To be notified of changes, email hello@justido.design with the subject "Sub-processor updates".