Data Processing
Last updated: July 21, 2026
This page describes how and where Directify processes personal data, and lists the subprocessors we use. It is written for directory owners who need to complete a processor register, vendor assessment or GDPR Article 30 records — if your DPO needs something in a different format, email support@directify.app.
Contracting entity
Directify is operated by:
WebTouch Ltd Rakovski 4150, Bulgaria Company ID (EIK): 202834358 VAT ID: BG202834358
WebTouch Ltd is incorporated in Bulgaria, a member state of the European Union. This is the entity you contract with under our Terms of Service.
Roles
For the personal data inside your directory — visitor form submissions and enquiries, submitter/business accounts, reviews, newsletter subscribers, and listing content — you are the controller and Directify is the processor, acting only on your instructions.
For your own account data (your name, email, billing details, support correspondence), Directify is an independent controller under our Privacy Policy.
Data Processing Agreement (Article 28)
An Article 28 GDPR data processing agreement covering the processing described on this page is available on request — email support@directify.app and we will send it for countersignature.
Where your data lives
All primary data is stored at rest within the EU:
- The application, database, search index and cache run on our own servers in Nuremberg, Germany (Hetzner).
- Uploaded files and images are stored in Cloudflare R2 object storage restricted to the EU jurisdiction.
- Encrypted database backups are taken daily and stored in the same EU region of Cloudflare R2.
- Transactional email is sent from Ireland (AWS eu-west-1).
No directory or form data is stored at rest outside the EU/EEA.
Subprocessors
The third parties that process directory data on our behalf:
| Subprocessor | Legal entity & country | Purpose | Processing location | Transfer safeguard |
|---|---|---|---|---|
| Hetzner | Hetzner Online GmbH, Germany | Infrastructure hosting: application servers, database, search index, cache | Germany (Nuremberg) | Not required (EEA) |
| Cloudflare | Cloudflare, Inc., USA | Object storage (R2, EU jurisdiction) for uploaded files and encrypted database backups; DNS, CDN and TLS for custom domains, so visitor traffic transits Cloudflare's edge network | Storage: EU; network edge: global | EU-US Data Privacy Framework; 2021 Standard Contractual Clauses (Module 3) as fallback |
| Amazon Web Services | Amazon Web Services EMEA SARL, Luxembourg | Transactional email delivery (SES) | Ireland (eu-west-1) | Not required (EEA entity, EEA region) |
We will inform account owners of any intended addition or replacement of a subprocessor by updating this page and emailing the account owner at least 30 days before the new subprocessor processes directory data, with the opportunity to object on reasonable data-protection grounds.
Services that are not subprocessors
- Payments — for paid submissions and listing upgrades you connect your own Stripe or PayPal account, so you have a direct relationship with the payment provider under its own terms. Card data goes straight to the provider and never touches Directify's servers; we store only order metadata (plan, status, payer email).
- AI features — AI text generation runs under your own API key with the provider you configure (OpenAI or Anthropic), at your instruction. Nothing is sent unless you use those features.
- Search and analytics — full-text search (Typesense) and visitor analytics are self-hosted on our own EU infrastructure. No third-party analytics run on directory pages.
Feature-dependent services
- Geocoding — if your directory uses map features, listing address strings only (never visitor data) are sent server-side to a geocoding service to obtain map coordinates. Results are cached so each address is looked up once. Providers used: LocationIQ (Unwired Labs), Photon (komoot GmbH, Germany), geocode.maps.co (Map Maker), and OpenStreetMap Nominatim (OpenStreetMap Foundation, UK).
- Web fonts — directory pages load web fonts from the Google Fonts CDN (Google LLC), which means a visitor's IP address reaches Google's servers when fonts load. No cookies are set and no other data is shared.
International transfers
Because WebTouch Ltd is established in the EU, engaging Directify is an intra-EEA controller-to-processor relationship for EU/EEA customers — no Chapter V transfer mechanism (and no SCC module) is needed between you and us; the Article 28 DPA governs the processing.
Onward transfers only arise where a subprocessor's parent entity is established outside the EEA (currently Cloudflare, Inc.). Those relationships are covered by the subprocessor's certification under the EU-US Data Privacy Framework and by the 2021 Commission Standard Contractual Clauses (Module 3, processor to processor) as fallback.
Retention, deletion and backups
- While your account is active, we keep your directory's data for as long as you keep it in the Service. Records you delete (a listing, a lead, a submitter account) are removed from the production database and search index without undue delay.
- On termination of your account or deletion of a directory, all directory data is deleted from production systems within 30 days. You can export your data from your panel before closing your account.
- Backups are encrypted, taken daily, and retained on a 30-day rolling cycle enforced by an automatic storage lifecycle policy — so deleted data ages out of backups within 30 days. Backups are used solely for disaster recovery and are never restored into production except to recover from data loss.
Data subject rights
You can handle most data subject requests yourself from your panel: view, correct, export and delete listings, leads, submitter accounts, reviews and subscribers. For anything not self-serve — for example a full extract for an access request — email support@directify.app and we will assist within 5 business days, at no charge.
If a data subject contacts us directly about data in your directory, we forward the request to you and do not respond substantively except on your instruction or where legally required.
Personal data breaches
We notify affected account owners without undue delay — targeting initial notice within 72 hours — after becoming aware of a personal data breach affecting their directory's data, including the Article 33(3) GDPR particulars as they become available, and we cooperate on any notification you need to make to your supervisory authority or to data subjects.
Security
An overview of our technical and organisational measures: TLS on all connections including custom domains, passwords stored only as salted one-way hashes, logical tenant isolation between directories, SSH-key-only production access restricted to authorised personnel, daily encrypted backups, regular dependency and security updates, and payment-card data handled exclusively by the payment providers. A fuller description is included in the DPA.
Questions
Email support@directify.app — we're glad to complete vendor questionnaires or answer your DPO's follow-ups.