Duplicati Sub-processor List

Last updated

Effective date

This page lists the third parties (sub-processors) that Duplicati Inc engages to process personal data on behalf of its customers in providing the Duplicati Console and related services, and forms the sub-processor annex of the Duplicati Data Processing Agreement, which is available to customers on request and will be published alongside this list. It also lists where each sub-processor processes the data and the mechanism that covers any transfer out of the European Economic Area, the United Kingdom or Switzerland.

Duplicati notifies customers of any intended addition or replacement of a sub-processor at least 30 days before it takes effect. To receive these notices, send an email to security@duplicati.com with the subject "Subscribe to sub-processor changes" from the address that should receive them. Customers who have a Data Processing Agreement with Duplicati may object to a change on the terms set out in that agreement; any other customer may raise concerns at the same address.

Infrastructure sub-processors

Sub-processor

Entity

Purpose

Data

Processing location

Transfer mechanism

DigitalOcean

DigitalOcean, LLC, New York, US

Hosting of the Console application, ingress, remote-management relay, database and encrypted report storage

Console user data, machine metadata, encrypted reports, standard-organization log data

Amsterdam, Netherlands

DigitalOcean DPA with EU Standard Contractual Clauses for US administrative access

IDrive e2

IDrive Inc., Calabasas, US

Object storage for Duplicati-provided backup storage

Encrypted backup data only

The data centre nearest to the customer by default; customers may choose any data centre IDrive offers

IDrive DPA with EU Standard Contractual Clauses

Google Cloud

Google LLC, Mountain View, US

Managed backup service runtime; OAuth token handling for third-party storage connections

Contents of customer cloud productivity accounts in memory (stored encrypted); transient OAuth tokens

europe-west1, Belgium; Google global infrastructure for transient token handling

Google Cloud Data Processing Addendum with EU Standard Contractual Clauses; EU-US Data Privacy Framework

Amazon Web Services

Amazon Web Services, Inc., Seattle, US

Immutable storage of audit and deployment records

Account, organization and machine identifiers and event types only

eu-north-1, Stockholm, Sweden

AWS Data Processing Addendum with EU Standard Contractual Clauses; EU-US Data Privacy Framework

Better Stack

Better Stack s.r.o., Prague, Czech Republic

Application log aggregation and uptime monitoring

Organization, machine and user identifiers, timings, error codes; no content

European Union

None required

Service sub-processors

Sub-processor

Entity

Purpose

Data

Processing location

Transfer mechanism

SparkPost

Bird.com Inc., Bethesda, Maryland, US

Delivery of service and notification emails

Console user email addresses and names; notification content (job status, backup names, machine identifiers)

United States

Bird Data Processing Agreement incorporating the EU Standard Contractual Clauses (Module 2)

OpenAI

OpenAI OpCo, LLC, San Francisco, US

Generation of backup report summaries for standard organizations (not used for Confidential Organizations)

Organization name, machine names and identifiers, backup identifiers and statuses, report content of standard organizations

United States

OpenAI Data Processing Addendum incorporating the EU Standard Contractual Clauses and the UK Addendum

Zendesk

Zendesk, Inc., San Francisco, US

Support ticketing

Contact details and correspondence of users who contact support

United States

Zendesk DPA with EU Standard Contractual Clauses; EU-US Data Privacy Framework

Zoom

Zoom Video Communications, Inc., San Jose, US

Customer troubleshooting sessions (end-to-end encrypted, not recorded)

Participant names and email addresses; transient audio and video

Transient; not stored

Zoom Global DPA with EU Standard Contractual Clauses; EU-US Data Privacy Framework

Stripe

Stripe, Inc., San Francisco, US

Payment processing and invoicing

Billing contact details and payment data (held by Stripe only)

United States

Stripe DPA with EU Standard Contractual Clauses; EU-US Data Privacy Framework

Duplicati personnel

Duplicati's own personnel access the systems above from Denmark. Duplicati Inc is a United States company; the transfer mechanism for data processed by Duplicati itself is set out in Section 11 of the Data Processing Agreement.

Change history

Date

Change

2026-10-08

Initial publication

Questions: security@duplicati.com