Legal
Sub-processors
The third parties that process data on our behalf, what each one does, and where it holds the data.
Musket Goose (Pty) Ltd · Effective
1. What this list is
These are the companies that process data on our behalf. If you are filling in a supplier questionnaire or a due diligence pack, this is the answer to the sub-processor question and you may cite this page.
A sub-processor is a company we hand data to so that it can do a job for us. That is different from a company we simply buy something from. Everyone on this list can, in the ordinary course of doing their job, hold or transit information about people.
We update this page when a provider is added or removed. If you have a contract with us that requires notice of a change, that notice comes from the contract, not from you watching this page. Ask jack.spence@musketgoose.com to be told directly.
2. Providers we use today
| Provider | What it does | What it can see | Where |
|---|---|---|---|
| Cloudflare, Inc. | Application hosting and content delivery. The website and the operator platform run here. We do not enable Cloudflare request log retention, and no Cloudflare product that would set a cookie is switched on, but Cloudflare necessarily processes the IP address of every visitor in order to serve the request. | Everything that transits the site, plus request metadata at the edge: IP address, approximate location, user agent, and the path requested. | Cloudflare's global edge network. United States company. |
| Neon, LLC, a Databricks, Inc. company | The Postgres database behind the operator platform. A Neon project's region is fixed when the project is created and cannot be changed afterwards, so this data is in the United States for as long as the project exists. | Operator accounts, employee and payroll records, the shareholder register, client and lead contact details, invoices and financial records, support conversations, internal messages, and audit logs. | United States. Amazon Web Services, US East (Northern Virginia). |
| Umami Software, Inc. | Website analytics for the public site. We use Umami Cloud rather than self-hosting it. Their published privacy notice covers people who hold Umami accounts, not visitors to this site. | Page views, referrer, screen size, language, and page title. No cookie, no device identifier, and nothing we can tie back to a person. | United States company. Servers in the United States and the European Union. |
3. The agreements behind them
Each provider's data processing agreement and privacy notice, so that you can read the terms rather than take our word for what they say.
| Provider | Data processing agreement | Privacy notice |
|---|---|---|
| Cloudflare, Inc. | https://www.cloudflare.com/cloudflare-customer-dpa/ | https://www.cloudflare.com/privacypolicy/ |
| Neon, LLC, a Databricks, Inc. company | https://www.databricks.com/legal/databricks-data-processing-addendum | https://www.databricks.com/legal/privacynotice |
| Umami Software, Inc. | https://umami.is/dpa | https://umami.is/privacy |
4. How this works under POPIA
Worth saying plainly, because it is the question a South African client's legal team will ask and a vague answer wastes everybody's afternoon.
None of these providers offers a POPIA specific agreement. Every one of them contracts on the European Standard Contractual Clauses through the agreements linked above. Section 72 of POPIA permits a transfer out of South Africa where the recipient is bound by an agreement giving an adequate level of protection with onward transfer restrictions substantially similar to POPIA's, and those clauses are the instrument we rely on.
So: we do not claim any of these companies is certified under South African law, because none of them is. We rely on European standard terms, which impose substantially what POPIA asks for, and we say so rather than letting a reader assume more.
Where we process personal information for a client, section 21 of POPIA requires a written agreement between us. We sign one as a matter of course, and it flows the same obligations down to everyone on this page.
5. Providers we have stopped using
Kept here rather than deleted. If you are comparing this page against a copy you took earlier, a vendor that vanished without explanation looks like a disclosure we never made.
| Provider | What it did | Where |
|---|---|---|
| Vercel Inc. | Application host until August 2026, when the site moved to Cloudflare. Retired on 19 August 2026, when musketgoose.com stopped resolving to Vercel. Kept on this page rather than deleted, so that anyone holding an earlier copy can see when it left rather than wonder whether it was ever disclosed. | United States |
6. Companies that receive data but are not our processors
One company belongs in a different category, and putting it in the table above would be wrong.
A domain registrar does not process registration data on our instruction. What it collects, publishes and retains is set by ICANN's rules, which makes it an independent controller of that data rather than our operator. Listing it as a sub-processor would misdescribe the relationship to anyone relying on this page.
| Company | What it does | Where | Privacy notice |
|---|---|---|---|
| GoDaddy.com, LLC | Domain registrar for musketgoose.com, and the DNS operator for it. Holds the registration contact details for the domain, under rules set by ICANN rather than by us. It is an independent controller of that data, not our operator. | United States | https://www.godaddy.com/legal/agreements/privacy-policy |
7. What is deliberately not on this list
- Our accountants, auditors and attorneys. They receive information, but as professionals under their own duties rather than as our processors.
- Banks and payment providers, which act on their own regulatory obligations.
- SARS, the Companies and Intellectual Property Commission and other authorities, which receive information because the law requires it.
- Software we run for a client. There we are the operator and the client's own sub-processor list governs, not ours.
8. Questions
If a provider here is a problem for your organisation, tell us before you sign rather than after. Some are replaceable and some are not, and we would rather have that conversation early. Write to jack.spence@musketgoose.com.
Questions about this document? Email jack.spence@musketgoose.com
