Sub-processors and service providers
Last updated: October 2, 2026
Dannie Hansen Consulting ApS uses the providers below to operate Limita. Their roles depend on the particular data and purpose. This register supports our Privacy Policy and Data Processing Agreement.
Customer-data subprocessors are identified separately from providers supporting our own operations, billing and accounting, and from the Trello service selected by the customer.
1. Customer-data subprocessors
These providers support processing performed on a customer’s behalf, including customer-data support and diagnostics. Appendix B of the DPA identifies the same list.
Hetzner Online GmbH
Platform hosting, database and encrypted backups
- Legal contact address
- Industriestr. 25, 91710 Gunzenhausen, Germany.
- Data
- Customer service data, including board and member identifiers, time records, estimates, custom fields, clients and integration credentials.
- Locations
- Platform in Nuremberg, Germany; backups in Falkenstein, Germany. Provider support is within the EU.
- Processing and transfers
- No transfer outside the EEA. Hosting and backups are provided in Germany under Hetzner’s data-processing agreement.
Sentry (Functional Software, Inc.)
Error reporting and diagnostics
- Legal contact address
- 45 Fremont Street, 8th Floor, San Francisco, CA 94105, United States.
- Data
- Exceptions, diagnostic breadcrumbs and technical context, which may include workspace, member and session identifiers. Session replay is disabled. Sentry keeps error events for up to 90 days.
- Locations
- EU region in Frankfurt for service events. Account, integration and organisation metadata and support can involve the United States. Sentry Software Canada Inc. provides parts of the service and technical support from Canada.
- Processing and transfers
- Sentry’s published DPA provides for covered EU-US Data Privacy Framework transfers and Standard Contractual Clauses as fallback. EU storage does not exclude international processing or access.
Proton AG
Email support and privacy requests
- Legal contact address
- Route de la Galaise 32, 1228 Plan-les-Ouates, Switzerland. Registration CHE-354.686.492.
- Data
- Contact details, message content, attachments and email metadata. Acts as a customer-data subprocessor where support correspondence contains customer personal data.
- Locations
- Switzerland, Germany and Norway.
- Processing and transfers
- EEA processing and the European Commission adequacy decision for Switzerland.
Cloudflare, Inc.
Delivery of in-app help and onboarding media from media.limita.org, public website delivery, and DNS for limita.org
- Legal contact address
- 101 Townsend St., San Francisco, CA 94107, United States.
- Data
- IP addresses, requested URLs and HTTP headers, such as the browser user agent, of Power-Up users loading help and onboarding clips and of website visitors, and DNS lookups for limita.org names. Requests to the app and API at app.limita.org go directly to Hetzner and do not pass through Cloudflare.
- Locations
- Global network, including the United States and other countries outside the EEA.
- Processing and transfers
- Transfers to Cloudflare, Inc. in the United States rely on its certification under the EU-U.S. Data Privacy Framework. Cloudflare’s data processing addendum incorporates the EU Standard Contractual Clauses for transfers that framework does not cover.
2. Business operations and billing
These providers primarily support processing for which Limita is controller. Their inclusion here does not mean that all of their processing occurs only on our instructions. Stripe acts as an independent controller for subscription purchases.
PagerDuty, Inc.
Limita’s operational incident alerts
- Legal contact address
- Attn: Legal Department, 600 Townsend St. #200, San Francisco, CA 94103, United States.
- Data
- Service-health alerts, infrastructure identifiers and operator contact information. Customer content and member identifiers must not be added without a separately assessed and notified processing arrangement.
- Locations
- Alerts are sent to PagerDuty’s United States service region and processed in the United States. PagerDuty may process support and operational data outside an account’s service region.
- Processing and transfers
- PagerDuty, Inc. is certified under the EU-U.S. Data Privacy Framework, and its data processing addendum, incorporated in its terms of service, includes the EU Standard Contractual Clauses. This service supports Limita’s own operational activities; it is not authorised to receive customer records under the customer DPA.
Stripe
Merchant of record for subscription purchases (Stripe Managed Payments)
- Data
- Stripe is merchant of record for subscription purchases through its affiliate Sold through Link, LLC, and checkout shows purchases as “Sold through Link”. It collects the purchaser’s name, contact and billing details, tax ID and payment details, and processes them for checkout, payment, tax, invoicing, fraud prevention and its regulatory duties as an independent controller. Limita sends Stripe the Trello Workspace identifier and platform, a placeholder customer name (“Organization” and the start of that identifier), trial start and end dates, the chosen plan, cancellation and resumption requests, and any business details an administrator supplied for invoicing. Stripe returns subscription status, plan interval, billing-period end and customer and subscription identifiers, and shares purchaser and order details with Limita.
- Locations
- Includes Ireland and the United States, with further processing under Stripe’s published terms.
- Processing and transfers
- Stripe, LLC is certified under the EU-U.S. Data Privacy Framework. Stripe’s DPA and Data Transfers Addendum include the EU Standard Contractual Clauses. Its processing as merchant of record is governed by the Link Terms of Service and Link Privacy Policy.
Visma Dinero ApS
Limita’s bookkeeping
- Legal contact address
- Gærtorvet 1-5, 1799 København V, Denmark. CVR 34731543.
- Data
- Accounting records, including customer/invoice details and payment amounts. Not used to store time-tracking histories.
- Locations
- Provider based in Denmark. Its published subprocessors are in the EEA except one in the United States.
- Processing and transfers
- Dinero’s data-processing agreement requires the EU Standard Contractual Clauses for any transfer outside the EEA. Those terms apply to Limita’s accounting records.
Proton AG also hosts our ordinary business and privacy correspondence, and Cloudflare also delivers the public website and DNS, as described above.
3. The customer’s Trello platform
Atlassian provides Trello under the customer’s own relationship with that platform. Limita reads authorised board, card, checklist and member information through Trello and registers webhooks for relevant updates.
Trello’s processing locations and international transfers depend on the customer’s Atlassian services and terms. See Atlassian’s Data Processing Addendum. Trello is not treated as a Limita subprocessor merely because the customer chooses to use it.
4. Changes and questions
For customer-data subprocessors, the DPA requires advance written notice of additions or replacements and an opportunity to object before the new provider processes customer data. Updating this page alone does not replace that notice.
The customer should keep its designated contact details current. Contact privacy@limita.org to designate a privacy contact, request provider information or raise an objection.
Service region, contractual entity and international support access are different questions. EU storage does not imply that every provider activity takes place in the EEA. Information about the safeguards applicable to your customer data is available on request.