Vendor transparency
Subprocessors and Service Providers
Effective and last updated: August 5, 2026
Public list
| Provider | Purpose | Data categories | Processing location |
|---|---|---|---|
| Cloudflare | Hosting, Workers, D1, R2, DNS, bot protection and inbound routing | Account, security, message and attachment data as configured | Cloudflare infrastructure |
| Resend or configured outbound provider | Transactional and outbound email | Sender/recipient, subject, body and attachments needed for delivery | Provider infrastructure |
Vendor controls
Before adding a provider, JGAMail should document purpose, data categories, location, contract/DPA status, security review, retention/deletion terms, breach obligations and next review date. The administrator console maintains this register.
Changes
Material new subprocessors should be published before use where feasible. Questions or objections may be submitted to [email protected].