Legal Data
Sub-processors
The three companies that receive personal data on our behalf, each with its legal entity, what it gets, why, and a link to its own data processing agreement.
Contents4 sections
Three. Named, with what each one receives and the agreement it operates under, because a procurement review that cannot find this page assumes the list is longer than it is.
None of them receives anything from inside your terminals. There is no sub-processor that could, because we never have that data in the first place.
The list
Stripe — payments
- Entity: Stripe, LLC (Americas) or Stripe Payments Europe, Limited (elsewhere), depending on where your account sits.
- Receives: your email address, whatever billing name, address and tax id you enter at checkout, and your card details — which go from your browser to Stripe directly and never pass through our servers.
- Purpose: taking payment, running the billing portal you cancel from, calculating VAT and sales tax, and telling our licence server when a subscription starts, renews or ends.
- Where: United States and Ireland.
- Terms: stripe.com/legal/dpa · stripe.com/privacy
Stripe is also an independent controller for its own fraud prevention. That part is theirs, governed by their policy, and is the reason a payment processor keeps a transaction record even after we have deleted everything on our side.
Resend — licence emails
- Entity: Plus Five Five, Inc., trading as Resend, San Francisco, California.
- Receives: your email address and the message body — which contains your licence key.
- Purpose: delivering the one email that carries your key, when a trial starts and when a purchase completes. There is no newsletter and no marketing list here; this is transactional only.
- Where: United States.
- Terms: resend.com/legal/dpa
Resend’s DPA incorporates Standard Contractual Clauses and states EU–U.S. Data Privacy Framework compliance.
Railway — hosting, database, downloads and updates
- Entity: Railway Corporation.
- Receives: everything the licence server stores — the licences, machines, trials and events tables described in the Privacy Policy — plus platform request logs which contain IP addresses and user agents. From the download and update service, your IP address and user agent, and nothing else: not your email, not your key, not your fingerprint.
- Purpose: running the licence server and its Postgres database, serving the installer from
https://download.nogenic.com, answering the update check an installed copy makes every four hours, and hosting this website. - Where: United States.
- Terms: railway.com/legal/dpa
Railway is by some distance the widest-reaching entry on this page, and it is worth being precise about why: it is three separate services on one account, not one machine. The licence server holds the database. The distribution service holds the installer, and is separate on purpose — a service pinned to a storage volume cannot scale, and the licence server is the thing that decides whether the app opens at all. This website is the third. Each can fail without the others.
The database is reached over Railway’s private network rather than the public proxy, and we do not disable certificate verification to make a connection work — the credential travelling over it is the one that can mint licences.
The download endpoint is deliberately unauthenticated: Dispatch gates at launch rather than at download, so nothing about who you are is asked for or recorded in order to fetch the installer.
The marketing pages and documentation on this site are static and set no cookies. The account area runs server-side and sets one session cookie — see Cookies.
What is deliberately not on this list
- No analytics provider. There is none.
- No error tracking or crash reporting, in the app or on the site.
- No customer support platform. Support is email, and the mailbox is dispatch@nogenic.com.
- No CDN in front of the licence server. It is reached directly.
- No advertising or marketing tooling of any kind.
- No mailing list provider. There is no newsletter and no waitlist to be on — the only address held is the one on your licence, and Resend above is what sends to it.
Each of those is a company that would otherwise have to appear here. They are absent because they are not used, not because the list has been trimmed.
GitHub used to be on this list and is not any more. It was here as the host of the installer and the update feed; both moved to the distribution service described above, so your machine no longer talks to GitHub while Dispatch runs. GitHub still holds the source code and runs the release build, which is not a thing that receives personal data about you.
Changes to this list
We update this page and change the date at the top whenever a sub-processor is added or removed. If you have a data processing agreement with us, you get the notice period it specifies before a new one starts processing.
For anyone without one: adding a sub-processor is a material change to the Privacy Policy, so it is emailed to the address on your licence before it takes effect.
A DPA for business buyers
There is no signable DPA.
Most of what one would contain is already on this page and in the Privacy Policy: who the sub-processors are, what each receives, where it is processed, how long it is kept, what happens on deletion, and how a change is notified. What a signed agreement adds on top of that is a counterparty who has committed to it in writing, and standard contractual clauses for transfers out of the EU and the UK. Neither of those exists yet, and saying so is more useful than an unsigned template on a page.
If your procurement process requires one, write to dispatch@nogenic.com and say so — it is worth knowing how often it is actually asked for.