Last Updated: 2026-05-29
To deliver the UnMark service, we engage certain third-party sub-processors that may have access to limited personal data as part of providing their services. This page lists all sub-processors we currently use, the services they provide, and the locations where data is processed. We conduct due diligence on all sub-processors and contractually require them to comply with applicable data protection laws and maintain appropriate security measures.
| Sub-processor | Service Category | Data Location | Purpose of Processing |
|---|---|---|---|
| Vercel | Cloud Hosting & Edge Computing | United States | Hosting the UnMark web application, serving frontend assets, executing edge functions, and content delivery. |
| AWS | Cloud Infrastructure & Video Processing | United States, EU | Providing compute resources for AI video watermark removal processing and temporary file storage during processing. |
| Creem | Payment Processing | Global | Processing subscription payments, managing recurring billing, and maintaining payment records. |
| Axiom | Logging & Monitoring | European Union | Server-side application logging, performance monitoring, and error tracking. No client-side cookies or tracking technologies are deployed by Axiom on our Service. |
| Resend | Transactional Email Delivery | United States | Sending transactional emails including account verification, password reset, billing receipts, and service notifications. |
| OAuth Authentication | United States | Enabling Google OAuth as an optional sign-in method. Google cookies are set only when you actively choose to sign in via Google. |
Before engaging any sub-processor, we conduct a thorough review of their security practices, privacy policies, and compliance certifications. All sub-processors are bound by data processing agreements that require them to: - Process personal data only on our documented instructions - Implement appropriate technical and organizational security measures - Assist us in responding to data subject rights requests - Notify us of any security incidents without undue delay - Maintain confidentiality of all processed data - Delete or return data upon termination of the agreement We regularly review our sub-processors' compliance with these obligations.
We may add or replace sub-processors from time to time to improve our service or for operational reasons. For enterprise and business customers subject to data processing agreements (DPA), we will provide prior written notice of any new sub-processor engagement. You will have the right to object to a new sub-processor on reasonable data protection grounds within fourteen (14) days of such notice. This page will be kept up to date to reflect our current sub-processor list. The last updated date at the top of this page indicates the most recent change.
We do not sell, rent, or trade your personal data to any third party, including our sub-processors. Sub-processors only access the minimum data necessary to perform their specific function. No sub-processor is authorized to use your data for their own purposes, including for marketing, advertising, or improving their own services.