SafeToOpen Ltd uses the following third-party sub-processors to deliver its services. Each is assessed before onboarding and bound by data protection terms consistent with our DPA.
| Sub-processor | Purpose | Data processed | Location of processing | Safeguards |
|---|---|---|---|---|
| SiteHost New Zealand Ltd | Cloud hosting of SafeToOpen detection services and stored data | Submitted page data, verdicts, account data | New Zealand | Data processing terms; NZ Privacy Act 2020; ISO 27001-aligned hosting controls |
Before publication, add any other vendor that stores or processes customer data — typically: payment provider (e.g., Stripe/Paddle — card data is held by the provider, not SafeToOpen), transactional email service, support/helpdesk tooling, and any breach-database service used for the email checkup feature. Completeness matters: reviewers cross-check this list against the extension's actual network traffic, and an undisclosed processor discovered that way undermines the whole trust pack. If a vendor only ever sees data that never includes customer data, it does not belong on this list.
Change notification
We update this page when sub-processors change and notify customers by email at least 30 days before a new sub-processor processes customer data, giving customers the opportunity to object as set out in the DPA.
Last updated: July 2026 · Review cadence: quarterly