Last updated: July 30, 2026.
To deliver the service, ConsentFly engages the subprocessors listed below. Each one has been assessed for security, the existence of contractual data-protection clauses, and the international transfer mechanism where applicable. This page is updated whenever we add or replace a subprocessor.
For details on which data is processed, why, and for how long, see the Privacy Policy. The contractual regime applicable to customers using ConsentFly as a processor is described in the DPA.
Current list
| Subprocessor | Purpose | Location | International transfer |
|---|---|---|---|
| Cloudflare, Inc. | Authoritative DNS for the ConsentFly domains. Every record is unproxied: site and API traffic does not cross Cloudflare's network, and no request content is processed by it. | USA, with global presence (anycast) | Standard Contractual Clauses (SCC) from the European Commission; ISO 27001 and SOC 2 Type II certified. |
| Vercel Inc. | Hosting for the public consentfly.com.br site and the dashboard SSR (Next.js). All API calls pass through it via a same-origin rewrite. | USA (with EU regions when configured) | Standard Contractual Clauses (SCC) from the European Commission; SOC 2 Type II certified. |
| Railway Corp. | Hosting for the backend (Go/Gin), the primary PostgreSQL database, the Redis cache, and the object bucket that stores export files. | USA (us-east4, Virginia) | Standard Contractual Clauses (SCC) from the European Commission. |
| Resend, Inc. | Transactional email delivery (account verification, password reset, billing alerts). | USA, with infrastructure on AWS | Standard Contractual Clauses (SCC) from the European Commission; AWS is SOC 2 and ISO 27001 certified. |
| AbacatePay | Payment processing, invoice generation, and receipt issuing. | Brazil | Processed within Brazilian territory; direct application of the LGPD without need for an international transfer mechanism. |
| ipapi.co (Kloudend, Inc.) | Approximate country/region resolution from an IP address. The address looked up is our edge layer's egress address, not the visitor's — the visitor's IP never reaches ConsentFly. Resolution is therefore regional and approximate, and no IP address is persisted. | USA | Standard Contractual Clauses (SCC) from the European Commission. |
| Google LLC (OAuth Sign-in) | Optional Google Sign-In authentication. We receive only the user ID, verified email, and name from Google — no other Google account data. | USA, with global presence | Standard Contractual Clauses (SCC) from the European Commission; Google operates under various certifications (ISO 27001, SOC 2, ISO 27701). |
| Sentry (Functional Software, Inc.) | Error and exception monitoring on the backend. We apply a PII filter before submission (emails and subject identifiers are stripped from the payload). | USA | Standard Contractual Clauses (SCC) from the European Commission; ISO 27001 and SOC 2 Type II certified. Optional subprocessor — can be disabled on the backend via environment variable. |
Changes to the list
When we add a new subprocessor that processes customer personal data in a processor role, we notify by email with at least 15 days' notice so the customer can evaluate the change. In case of objection, the customer can cancel the subscription without penalty before the new subprocessor goes into production.
Contact
For questions about subprocessors or to receive formal change alerts:
Email: suporte@consentfly.com.br