Sub-processor List
Effective 18 July 2026. Last updated 18 July 2026.
Sub-processor list
Purpose
This page lists every third party that processes mintfax customer data on mintfax’s behalf, and states the notice, objection, and change-control rules that apply when that list changes.
Scope
This policy applies to all mintfax environments (sandbox and live) and to all customers operating under a mintfax Business Associate Agreement (BAA), Data Processing Addendum (DPA), or standard terms of service. The operator entity is named in the Contact section.
Definitions
Sub-processor means a third party that mintfax engages to process customer data on mintfax’s behalf, as that term is used in Article 28 of the General Data Protection Regulation (Regulation (EU) 2016/679).
Customer data means data submitted to or generated by the mintfax API or dashboard, including Protected Health Information (PHI) content and operational metadata as defined in the Data Retention Policy.
Primary sub-processor means a sub-processor currently processing customer data in production.
Standby sub-processor means a sub-processor pre-disclosed on this page that mintfax may activate on short notice, without further advance notice at the point of activation.
Effective date means the date this version of the list took effect. Last-updated date means the date this page was last changed.
1. Current sub-processors
The following third parties are engaged as primary sub-processors and process mintfax customer data in the ordinary course of the service.
| Sub-processor | Role | Region | DPA | Status |
|---|---|---|---|---|
| Amazon Web Services | Compute, S3 object storage, KMS key management, DynamoDB, CloudWatch logging | us-east-1 | AWS Data Processing Addendum | Primary |
| Stripe | Payment processing for credit purchases | Per sub-processor DPA | Stripe Data Processing Agreement | Primary |
| Postmark | Transactional email, including compliance and change-notice email | Per sub-processor DPA | Postmark Data Processing Addendum | Primary |
| Upland InterFAX | Outbound fax transmission over the public switched telephone network | Per sub-processor DPA | Upland Legal | Primary |
AWS is the platform on which all mintfax customer PHI content, operational metadata, encryption keys, and application logs are stored and processed. Storage and processing take place in a single US region; that region is named in the Region column above and in Section 5 below.
For each of Stripe, Postmark, and Upland InterFAX, the region of processing is governed by that sub-processor’s own DPA (linked in the DPA column), which the customer accepts by reference when accepting the mintfax DPA. mintfax does not make an independent region choice for these three sub-processors.
Stripe processes payment-card data for customers who purchase mintfax credits.
Postmark delivers transactional email from mintfax to customer account admins, including the change-notice email described in Section 3.
Upland InterFAX is the primary fax carrier, providing outbound transmission of fax jobs originated through the mintfax API.
2. Standby sub-processors
The following third parties are pre-disclosed as standby sub-processors. Adding a party to this section is subject to the 14-day notice in Section 3. Activating a standby sub-processor (moving it from standby to primary) does not require additional advance notice.
| Sub-processor | Role | Region | DPA | Status |
|---|---|---|---|---|
| Sub-processor #2 (pending selection) | Backup fax carrier for redundancy and geographic diversity | To be disclosed at least 14 days before activation | To be added | Standby |
When a standby entry is activated, the row is updated in place to primary and the Last-updated date is regenerated. The change also appears in the notice mechanisms described in Section 3.
3. Change notice
Additions of a new primary sub-processor, and replacements of an existing primary sub-processor, are announced at least 14 days in advance of the change taking effect. Additions to the Standby Sub-processors section carry the same 14-day window.
Notice is delivered through the following channels:
- Email to account admins of every account that has accepted the DPA.
- Dashboard banner in the mintfax dashboard during the notice window.
- Public list update. This page is updated with the pending change during the notice window, and the
Last-updateddate is regenerated. - Machine-readable feed. A machine-readable feed of change notifications is planned before general DPA availability; the URL will be listed on this page when live.
Removal of a sub-processor without replacement is announced through the same channels, but does not require 14 days of advance notice.
The 14-day sub-processor notice is separate from the 30-day advance notice for regional-expansion changes, which is described in Section 5 and carried in the DPA. The two windows apply to different kinds of change and are not interchangeable.
4. Right to object
Customers may object to the addition or replacement of a primary sub-processor during the 14-day notice window, in accordance with Article 28(2) of the General Data Protection Regulation. Objections must be filed to [email protected] before the change takes effect.
An objection must be based on reasonable data-protection grounds. Commercial preference does not obligate a response under this mechanism.
Where a reasonable objection is filed, mintfax responds with one of the following options:
- Keep the existing sub-processor for the objecting customer, where feasible.
- Migrate the objecting customer to an alternative sub-processor.
- Terminate the affected service for the objecting customer, with a prorated refund of any unused prepaid credit, where neither of the above is possible.
5. Data residency
All customer PHI content and operational metadata are stored and processed in a single US AWS region: us-east-1. The region string in Section 1 is authoritative.
The Data Processing Addendum commits to 30 days’ advance notice of any regional-expansion change, and to customer region choice when additional regions become available. This 30-day residency notice is separate from, and additional to, the 14-day sub-processor notice in Section 3.
6. Encryption
PHI content at rest is encrypted using SSE-KMS with mintfax-managed AWS KMS customer master keys, one per environment, with KMS automatic key rotation enabled. Database rows are encrypted using the cloud provider’s default at-rest encryption.
All data in transit uses TLS 1.2 or higher. Webhook endpoints registered with the http:// scheme are rejected at registration.
Details of the encryption controls and the audit-stream tamper-evidence chain are set out in the Data Retention Policy.
7. Retention
PHI content default retention is 30 days from terminal classification of a fax. Retention is customer-configurable per environment in the range 7 to 365 days. Zero-footprint mode scrubs PHI content immediately on terminal classification.
Full retention rules, including on-demand deletion and audit-stream retention, are set out in the Data Retention Policy.
8. Compliance boundary
mintfax contractual commitments in the DPA and BAA cover the following:
- The mintfax API infrastructure.
- PHI content storage and encryption.
- Operational databases and application logs.
The following are outside the mintfax compliance boundary:
- Upstream fax-carrier infrastructure, other than the contractual sub-processor commitments carried by the DPA.
- Recipient fax infrastructure, including the receiving line, receiving fax device, and recipient email or storage systems.
- Customer webhook endpoints and any downstream systems that consume mintfax webhook payloads.
- Payment processors, other than the contractual sub-processor commitments carried by the DPA with Stripe.
mintfax is a developer-first fax service. HIPAA and the General Data Protection Regulation (including UK GDPR and Brazil LGPD) are addressed through the BAA and DPA; SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI DSS Level 1 are not held and are not offered.
Snapshot on DPA acceptance
Acceptance of the mintfax DPA writes a snapshot of the sub-processor list, as it stands on the acceptance date, into the customer’s evidence record. The list on this page remains the source of truth for current state; the snapshot is a point-in-time record for audit purposes.
Related documents
- Data Processing Addendum
- Data Retention Policy
- Privacy Policy
- Terms of Service
- Data Retention API reference
Contact
For questions about this policy, to object to a proposed sub-processor change, or to request a copy of the sub-processor snapshot associated with your account, contact [email protected]. Response SLA is one business day.
Operated by Ediblesites Ltd, UK Company Reg. 12109195, 71-75 Shelton Street, London, WC2H 9JQ, United Kingdom.