TuployTuploy

Subprocessors

Effective date: April 13, 2026 · Last updated: April 13, 2026

This page lists the third-party subprocessors that ALIADO EXTERNO, SLU ("Tuploy") engages to provide the Platform. It is maintained in compliance with Article 28(2) and (4) GDPR and is incorporated by reference into the Data Processing Agreement and the Terms and Conditions.

Each subprocessor listed below has entered into a written agreement with Tuploy containing data protection obligations no less protective than those set out in our DPA. Tuploy remains fully liable for the performance of its subprocessors' obligations.

1. Notification of changes

1.1 Tuploy will give at least 15 days prior notice of any intended addition or replacement of a subprocessor by updating this page and notifying subscribed Customers by email or through an in-dashboard notification.

1.2 Customers may object to a new subprocessor on reasonable data protection grounds within that period, by writing to privacy@tuploy.com. If the parties cannot resolve the objection, the Customer may terminate the affected services without penalty in accordance with the DPA.

1.3 To receive change notifications, Customers should ensure that the email address associated with their account is current. The most recent version of this list always prevails over any cached copy.

2. Categories of subprocessors

Tuploy engages subprocessors across the following functional categories:

  • Infrastructure and networking: physical and virtual hosting, bandwidth and network delivery of the Platform and of Customer workloads.

All other components of the Platform — container orchestration, source-code and image registry, transactional email and monitoring — run on infrastructure operated directly by Tuploy and are not subcontracted to third parties. TLS certificates are issued through Let's Encrypt, which operates as a public certificate authority and is not engaged as a processor of Customer Personal Data. Payment processing is handled by Paddle, which acts as an independent controller in its capacity as Merchant of Record and is therefore not a subprocessor under Article 28 GDPR.

3. Current subprocessors

The table below lists the subprocessors currently engaged by Tuploy. The specific commercial entity, location of data processing and a link to the subprocessor's own privacy policy are maintained here and updated as needed.

SubprocessorCategoryLocation of processingPrivacy / terms
OVH SASInfrastructure and networkingFrance (EU)ovhcloud.com/personal-data-protection

4. International transfers

Where a subprocessor processes Customer Personal Data outside the European Economic Area or a country recognized as offering an adequate level of protection, Tuploy relies on appropriate safeguards under Chapter V GDPR, including the Standard Contractual Clauses adopted by the European Commission (Decision (EU) 2021/914) and, where necessary, supplementary technical and organizational measures.

5. Contact

Questions about this list, objections to a new subprocessor, or requests for additional information should be directed to privacy@tuploy.com.