Duplicati Sub-processor List
Last updated
Effective date
This page lists the third parties (sub-processors) that Duplicati Inc engages to process personal data on behalf of its customers in providing the Duplicati Console and related services, and forms the sub-processor annex of the Duplicati Data Processing Agreement, which is available to customers on request and will be published alongside this list. It also lists where each sub-processor processes the data and the mechanism that covers any transfer out of the European Economic Area, the United Kingdom or Switzerland.
Duplicati notifies customers of any intended addition or replacement of a sub-processor at least 30 days before it takes effect. To receive these notices, send an email to security@duplicati.com with the subject "Subscribe to sub-processor changes" from the address that should receive them. Customers who have a Data Processing Agreement with Duplicati may object to a change on the terms set out in that agreement; any other customer may raise concerns at the same address.
Infrastructure sub-processors
Sub-processor | Entity | Purpose | Data | Processing location | Transfer mechanism |
|---|---|---|---|---|---|
DigitalOcean | DigitalOcean, LLC, New York, US | Hosting of the Console application, ingress, remote-management relay, database and encrypted report storage | Console user data, machine metadata, encrypted reports, standard-organization log data | Amsterdam, Netherlands | DigitalOcean DPA with EU Standard Contractual Clauses for US administrative access |
IDrive e2 | IDrive Inc., Calabasas, US | Object storage for Duplicati-provided backup storage | Encrypted backup data only | The data centre nearest to the customer by default; customers may choose any data centre IDrive offers | IDrive DPA with EU Standard Contractual Clauses |
Google Cloud | Google LLC, Mountain View, US | Managed backup service runtime; OAuth token handling for third-party storage connections | Contents of customer cloud productivity accounts in memory (stored encrypted); transient OAuth tokens | europe-west1, Belgium; Google global infrastructure for transient token handling | Google Cloud Data Processing Addendum with EU Standard Contractual Clauses; EU-US Data Privacy Framework |
Amazon Web Services | Amazon Web Services, Inc., Seattle, US | Immutable storage of audit and deployment records | Account, organization and machine identifiers and event types only | eu-north-1, Stockholm, Sweden | AWS Data Processing Addendum with EU Standard Contractual Clauses; EU-US Data Privacy Framework |
Better Stack | Better Stack s.r.o., Prague, Czech Republic | Application log aggregation and uptime monitoring | Organization, machine and user identifiers, timings, error codes; no content | European Union | None required |
Service sub-processors
Sub-processor | Entity | Purpose | Data | Processing location | Transfer mechanism |
|---|---|---|---|---|---|
SparkPost | Bird.com Inc., Bethesda, Maryland, US | Delivery of service and notification emails | Console user email addresses and names; notification content (job status, backup names, machine identifiers) | United States | Bird Data Processing Agreement incorporating the EU Standard Contractual Clauses (Module 2) |
OpenAI | OpenAI OpCo, LLC, San Francisco, US | Generation of backup report summaries for standard organizations (not used for Confidential Organizations) | Organization name, machine names and identifiers, backup identifiers and statuses, report content of standard organizations | United States | OpenAI Data Processing Addendum incorporating the EU Standard Contractual Clauses and the UK Addendum |
Zendesk | Zendesk, Inc., San Francisco, US | Support ticketing | Contact details and correspondence of users who contact support | United States | Zendesk DPA with EU Standard Contractual Clauses; EU-US Data Privacy Framework |
Zoom | Zoom Video Communications, Inc., San Jose, US | Customer troubleshooting sessions (end-to-end encrypted, not recorded) | Participant names and email addresses; transient audio and video | Transient; not stored | Zoom Global DPA with EU Standard Contractual Clauses; EU-US Data Privacy Framework |
Stripe | Stripe, Inc., San Francisco, US | Payment processing and invoicing | Billing contact details and payment data (held by Stripe only) | United States | Stripe DPA with EU Standard Contractual Clauses; EU-US Data Privacy Framework |
Duplicati personnel
Duplicati's own personnel access the systems above from Denmark. Duplicati Inc is a United States company; the transfer mechanism for data processed by Duplicati itself is set out in Section 11 of the Data Processing Agreement.
Change history
Date | Change |
|---|---|
2026-10-08 | Initial publication |
Questions: security@duplicati.com
