SUBPROCESSORS AND OTHER RECIPIENTS Effective date: 22 September 2026 · Last updated: 22 September 2026 1. Purpose and notice This page identifies providers that may process Customer Personal Data for SENRIKO and distinguishes independent recipients. It forms part of the DPA and Privacy Policy (https://senriko.com/legal/privacy). SENRIKO will normally notify Account owners at least 15 days before a new Subprocessor begins materially processing Customer Personal Data. Objections must identify reasonable data-protection grounds and be submitted to help@senriko.com during that period. 2. Subprocessors Provider | Service and data | Principal processing location | Role Hetzner Online GmbH | Application, database, hosted files, screenshots and backups | Germany, current core deployment in Nuremberg | Hosting/infrastructure Subprocessor Resend / Plus Five Five, Inc. | Transactional email, alerts, verification/reset links, reports and selected service messages | United States and provider infrastructure | Email-delivery Subprocessor ImprovMX Incorporated | Forwarding mail addressed to senriko.com, including message content in transit | France and United States as described by provider | Mail-routing Subprocessor for relevant correspondence Google LLC and relevant affiliates | Customer-authorised Analytics Admin/Data APIs; Operator Gmail used for support/complaints; public-Site GA4 in a separate controller context | United States and global infrastructure | Subprocessor for selected connected/support functions; independent/controller role for some Google services Cloudflare, Inc. | Turnstile and anti-abuse/security signals where enabled | Global network, including United States | Security/anti-abuse Subprocessor A provider processes only the data needed for its function. Exact legal entity and transfer mechanism can depend on the Customer’s country and the provider’s current terms. 3. Independent controllers and non-Subprocessor recipients Recipient | Purpose | Role Relevant Paddle entity | Checkout, payment, tax, fraud prevention, receipts, refunds and chargebacks | Authorised reseller/Merchant of Record and independent controller for the buyer transaction Customer’s monitored Site, CRM, email, messenger and analytics property | Destination selected and controlled by the Customer | Customer-controlled or independent recipient, not appointed by SENRIKO DNS, RDAP and WHOIS operators | Technical domain/DNS query | Independent registry/operator Courts, regulators, authorities and advisers | Valid legal demand, compliance, defence and professional advice | Independent recipient subject to law/confidentiality Corporate successor or transaction party | Due diligence and transfer of the Service/business | Independent recipient/controller subject to confidentiality and continued protection 4. Customer-selected integrations When a Customer directs SENRIKO to send data to a Site, alert address, Google property or another integration selected by that Customer, the Customer is responsible for authority, recipient notice, legal basis and destination security. The DPA continues to govern SENRIKO’s own processing up to the instructed transfer. 5. Contact Questions and objections: help@senriko.com. A Customer requesting vendor contractual details must protect provider-confidential and security-sensitive information.