DATA PROCESSORS AND DATA PROCESSING AGREEMENTS (DPAs)
Last updated May 30, 2026
OVERVIEW
This document lists our primary third-party service providers that process personal data on behalf of WannaDate LLC ("processors" or "sub‑processors") and summarizes the status of our Data Processing Agreements (DPAs) with each provider.
This list is intended to support compliance reviews, vendor due‑diligence, and data protection inquiries. It should be read together with our Privacy Policy (https://wannadate.app/privacy-policy), which describes how and why we process personal data.
SERVICE AVAILABILITY: WannaDate? currently offers the Services only to users located in the United States, with paid services currently unavailable to residents of California, New York, Illinois, Iowa, Connecticut, Ohio, and New Jersey. Personal data is processed in the United States. We will update this document and our Privacy Policy when we expand service to additional U.S. states, countries, or regions.
PRIMARY PROCESSORS
1. DigitalOcean, LLC
- Role: Infrastructure and hosting provider
- Purpose: Hosts our production environment, including application servers and databases, on virtual private servers.
- Data processed: IP addresses, usage logs, and application data stored in our databases (including user account data, profile data, and transactional metadata).
- Location: United States (with data centers in multiple regions; current deployment is in a US data center).
- DPA status: Data processing terms in place via DigitalOcean’s standard Data Processing Agreement and related data protection commitments.
2. Mailgun Technologies, Inc.
- Role: Email delivery provider
- Purpose: Sends transactional and system emails (e.g., verification emails, password reset, notifications) on our behalf.
- Data processed: Email addresses, basic message metadata (timestamps, delivery events), and limited email content needed to deliver messages.
- Location: United States and EU infrastructure (routing according to Mailgun configuration).
- DPA status: Data processing terms in place via Mailgun’s standard Data Processing Agreement, including EU‑style data protection commitments.
3. Cloudflare, Inc.
- Role: CDN, DNS, and security provider
- Purpose: Provides content delivery network (CDN), DDoS protection, TLS termination, DNS, and Web Application Firewall (WAF) services.
- Data processed: IP addresses, request/response metadata, and security logs related to traffic to wannadate.app.
- Location: Global edge network (with regional routing); logs stored under Cloudflare’s data protection framework.
- DPA status: Data processing terms in place via Cloudflare’s standard Data Processing Agreement and data protection addenda.
4. Payment processor(s)
- Role: Payment processor (platform fees only)
- Purpose: Processes payments for platform fees (token purchases and premium subscriptions) using secure hosted payment pages.
- Data processed: Payment card details, billing details, transaction metadata, and related information necessary to process payments and manage chargebacks/refunds.
- Location: United States and/or other regions depending on the processor’s infrastructure and data handling practices.
- DPA status: Data processing terms are in place via the applicable merchant agreements and data protection commitments with each payment processor we use from time to time.
5. SMTP2GO (fallback only)
- Role: Fallback email delivery provider (not currently active)
- Purpose: Listed as a contingent fallback SMTP relay for transactional email delivery in the event our primary email provider (Mailgun) is unavailable. Mailgun is the active transactional email provider; this entry is preserved for transparency and may be removed when we confirm full retirement.
- Data processed (if engaged): Email addresses, basic message metadata (timestamps, delivery events), and limited email content needed to deliver messages.
- Location: Global infrastructure with servers in the United States, Australia, and Europe.
- DPA status: Data processing terms available via SMTP2GO's standard Terms of Service and data protection commitments if and when re-engaged.
6. UptimeRobot
- Role: Uptime monitoring provider
- Purpose: Monitors the availability and response time of our production website.
- Data processed: Website URL, response status, response time, and related availability metrics. No user personal data is processed by UptimeRobot.
- Location: United States and European infrastructure.
- DPA status: UptimeRobot does not process user personal data; standard terms of service apply.
ADDITIONAL SERVICES
From time to time, we may engage additional processors for:
- Error logging and monitoring
- Analytics and performance monitoring
- Backup and storage
Any additional processors will be subject to written data protection terms consistent with our Privacy Policy and applicable law. Where legally required, we will update our Privacy Policy and this document to reflect new processors.
DATA TRANSFERS
We currently offer the Services only in the United States; cross-border transfers from other regions are not part of our current operations. We will update this section if we expand internationally.
Where personal data is transferred outside the country or region of origin (for example, from the EU/EEA to the United States), we rely on appropriate transfer mechanisms permitted under applicable data protection laws (such as standard contractual clauses, data processing addenda, or equivalent safeguards provided by our processors).
CONTACT
If you have questions about our processors or DPAs, or require copies of applicable data protection terms (where legally permitted), please contact:
WannaDate LLC 8735 Dunwoody Place, Suite N Atlanta, GA 30350 United States Email: [email protected]