Sub-processors
Last updated: 2026-09-20
This page lists every third party that processes personal data on behalf of Webkonsulenterne A/S (CVR 40887731) when you use the Alertly service, as required under the GDPR Article 28. It is the authoritative list referenced by our Privacy Policy and by Data Processing Agreements signed with enterprise customers.
1. Current sub-processors
Each row states the vendor, why we use them, what personal data they receive, where they process it, and the legal basis for any transfer outside the EU/EEA.
| Sub-processor | Purpose | Data categories | Location | Transfer basis |
|---|---|---|---|---|
| Webkonsulenterne A/S — self-hosted infrastructure | Application hosting, PostgreSQL database, background job workers. Managed via Coolify on EU-located VPS. | Account data, monitoring event data, integration credentials (encrypted at rest). | European Union (Denmark) | N/A — controller-processor within the EU |
| Cloudflare, Inc. | DNS, TLS termination, and edge caching for alertly.site and the dashboard. | Request metadata (IP address, user-agent, URL path, timestamps) for visitors and dashboard users. No monitoring event payload passes through Cloudflare as data. | United States, with EU edge presence | EU Standard Contractual Clauses + Cloudflare Data Processing Addendum |
| Resend, Inc. | Transactional email delivery — welcome emails, monthly PDF reports, invitations, password resets. | Recipient email address, sender identity, message subject and body content. | United States | EU Standard Contractual Clauses |
| Frisbii (Reepay ApS) | Subscription billing, hosted checkout, invoice generation. Card details never touch Alertly servers. | Billing name, email, address, VAT number, subscription state, invoice references. | Denmark | N/A — processor within the EU |
| Telegram FZ-LLC | Delivery of real-time alert messages to your configured Telegram chat(s). Alertly acts as a bot client only. | Alert message body (may include site URL, event type, error snippets, and diagnostic metadata), your Telegram Chat ID and Bot Token. | United Arab Emirates | EU Standard Contractual Clauses + operator opt-in per-channel |
2. Not sub-processors — customer-authorised data sources
When you connect an integration (Cloudflare, Google Analytics / Ads / Search Console / Merchant Center / PageSpeed, Meta Commerce, cPanel/WHM, the alert-reporter WordPress plugin), Alertly reads monitoring data from that service under credentials you supplied. Those vendors are your own contractors, not ours — Alertly is the processor for the resulting event data once it lands on our servers, but we do not push your personal data back to those vendors. They are therefore excluded from the list above.
3. Change notifications
We give at least 30 days' advance notice before adding a new sub-processor or materially changing an existing one. Notice is sent to the primary email address on your Alertly account and posted on this page at the same time.
If you object to a new sub-processor, you may terminate the affected Service without penalty within 30 days of the notice by emailing [email protected]. Prepaid, unused subscription time is refunded.
4. Data Processing Agreement
Enterprise customers can request a signed Data Processing Agreement (DPA) that binds Alertly under GDPR Art. 28 and lists the current sub-processors as a schedule. Contact [email protected].
5. Contact
Webkonsulenterne A/S · CVR 40887731 · Hadsundvej 112, 9550 Mariager, Denmark · [email protected] · +45 54 62 54 21