Media Design Legal
Subprocessors List
Complete list of subprocessors authorized by Media Design S.R.L. to process personal data on behalf of clients.
1. Purpose of this page
Under GDPR Art. 28(2), the Processor must inform the Controller of any sub-processor engaged and obtain the Controller's consent. This page constitutes the public list of sub-processors authorised by Media Design S.R.L. to process personal data in the context of services provided to clients. Clients who have signed a DPA with Media Design S.R.L. have granted general authorisation to engage the sub-processors listed at the time of signing.
2. How we select sub-processors
Each sub-processor is evaluated before engagement against the following criteria:
- GDPR Art. 28: existence of a valid DPA or standard contractual clauses (SCCs) with the sub-processor;
- GDPR Art. 32: auditing of security measures (ISO 27001, SOC 2 certifications or equivalent security report);
- Transfer Impact Assessment (TIA): risk assessment for extra-EEA transfers, in accordance with EDPB Recommendations 01/2020;
- Compatibility with the purposes and legal basis of the processing activities for which they are engaged.
3. Notification of changes
Media Design S.R.L. notifies any addition or replacement of a sub-processor at least 30 days in advance by:
- updating this page (with changes marked in the Changelog in section 7);
- sending a notification email to all clients who have opted in to sub-processor notifications (opt-in at DPA signing);
- announcement in the client portal.
4. Controller's right to object
The Controller (client) has the right to object in writing to the engagement of a new sub-processor or the replacement of an existing one within 30 days of notification. The objection must be justified and documented. The procedure is detailed in the DPA signed between the Controller and Media Design S.R.L.
5. Sub-processors list (Schrems II + EU-US DPF + SCC)
For each sub-processor listed below, we explicitly indicate the jurisdiction, categories of data processed, transfer mechanism (Decision C(2023) 4745 — EU-US Data Privacy Framework of 10.07.2023, or Standard Contractual Clauses Module 2 — Decision 2021/914), and the applicable adequacy decision. This list is updated with at least 14 days' prior notice for material changes.
| # | Subprocessor | Jurisdiction | Data categories | Transfer mechanism | Adequacy decision |
|---|---|---|---|---|---|
| 1 | Google LLC (Google Analytics 4) | USA | Pseudonymous visitor IDs, IP-derived geolocation (truncated to country), device/browser fingerprint, page views, events, conversions | EU-US Data Privacy Framework (Google LLC DPF certified) | C(2023) 4745 |
| 2 | Meta Platforms Ireland Ltd (Meta Pixel / Conversions API) | Ireland (EU); affiliate transfer to Meta Platforms Inc, USA | Pixel events, hashed email (CAPI), IP address, device identifiers | Meta Platforms Inc is EU-US DPF certified; Meta Ireland processes EU data initially. Residual Schrems II concerns acknowledged for certain transatlantic data flows. | C(2023) 4745 |
| 3 | TikTok Technology Limited (Ireland) (TikTok Pixel / Events API) | Ireland (EU); potential indirect transfer to TikTok Inc (USA) and ByteDance Ltd (China) | Pixel events, hashed email, device identifiers | Standard Contractual Clauses Module 2 (Commission Implementing Decision 2021/914 of 4 June 2021) + Transfer Impact Assessment (TIA) due to indirect China-transfer risk. DPF does not apply. | SCC: Decision 2021/914 |
| 4 | HubSpot Inc (CRM) | USA | Lead name, email, phone, company, deal stage, all CRM interactions | EU-US Data Privacy Framework (HubSpot Inc DPF certified) | C(2023) 4745 |
| 5 | SC Smartbill SRL (invoicing / fiscal documents) | Romania (EU) | Fiscal data, invoices, client identification data | No transfer outside the EEA. Data remains in Romania/EU; no transfer mechanism required. | N/A — intra-EU |
| 6 | Stripe, Inc / Stripe Payments Europe Ltd (payment processing) | Stripe Payments Europe Ltd: Ireland (EU); Stripe Inc: USA | Payment metadata, billing details | Stripe Payments Europe Ltd processes EU customer data initially. Stripe Inc (USA) is EU-US DPF certified for transatlantic data flows. | C(2023) 4745 |
| 7 | Netopia Payments SRL (payment gateway) | Romania (EU) | Transaction metadata, payer identification data | No transfer outside the EEA. Data remains in Romania/EU; no transfer mechanism required. | N/A — intra-EU |
| 8 | OpenAI, L.L.C (AI features — planned) | USA | Prompts, generated content, conversation context | EU-US Data Privacy Framework (OpenAI DPF-registered as of September 2024). NOT currently in active use. Will be activated only after data subjects have been notified. | C(2023) 4745 |
5.1 Note on international transfers post-Schrems II
As of 10 July 2023, the European Commission's adequacy decision C(2023) 4745 (EU-US Data Privacy Framework) constitutes the primary mechanism for transferring personal data to US entities that are certified on dataprivacyframework.gov. For sub-processors that do not hold DPF certification, or whose service scope falls outside their certification (most notably TikTok, due to the risk of indirect transfers to China), we rely on Standard Contractual Clauses Module 2 (Commission Implementing Decision 2021/914 of 4 June 2021) accompanied by a Transfer Impact Assessment (TIA), in accordance with EDPB Guidelines 01/2024. Media Design S.R.L. periodically verifies that US-based sub-processors remain actively listed on the DPF registry; if a certification is withdrawn, SCC + TIA are activated immediately as a fallback mechanism.
5.2 Data subject rights with respect to sub-processors
Under Art. 21 GDPR, you have the right to object to the processing of your personal data by any of the sub-processors listed above, to the extent that such processing is based on legitimate interests or carried out for direct marketing purposes. Requests to exercise data subject rights (access, rectification, erasure, portability, restriction, objection) should be submitted via the dedicated form at /legal/data-subject-request/form. Media Design S.R.L. will respond within 30 calendar days of receiving the request and, where relevant, will liaise with the sub-processor concerned on your behalf.
5.3 Legacy table (internal collaborators)
| Sub-processor | Supplier / Legal entity | Server location | Purpose of processing | Transfer mechanism |
|---|---|---|---|---|
| Cloudflare | Cloudflare, Inc. (USA) | EU + USA (global CDN) | CDN, DNS, WAF, DDoS protection, performance optimisation | SCCs (Decision 2021/914) + EU-US DPF |
| Google Analytics 4 | Google Ireland Limited (IE) | EU + USA | Site traffic analysis (anonymised), user behaviour reporting | SCCs (Decision 2021/914) + EU-US DPF |
| Google Ads | Google Ireland Limited (IE) | EU + USA | Ad conversions, remarketing (with consent) | SCCs (Decision 2021/914) + EU-US DPF |
| Google Workspace | Google Ireland Limited (IE) | EU + USA | Business email, internal operational document storage | SCCs (Decision 2021/914) + EU-US DPF |
| Meta Ads (Facebook + Instagram) | Meta Platforms Ireland Limited (IE) | EU + USA | Ad conversions, Pixel remarketing (with consent) | SCCs (Decision 2021/914) + EU-US DPF |
| LinkedIn Ads + Insight Tag | LinkedIn Ireland Unlimited Company (IE) | EU + USA | B2B ad conversions, remarketing (with consent) | SCCs (Decision 2021/914) + EU-US DPF |
| HubSpot CRM | HubSpot Ireland Limited (IE) | EU + USA | B2B lead management, CRM, prospect behaviour tracking | SCCs (Decision 2021/914) |
| Smartbill | Intelligent IT SRL (RO) | Romania | Electronic invoicing, ANAF e-Factura, financial management | National law (RO) — no extra-EEA transfer |
| Stripe | Stripe Technology Europe, Limited (IE) | EU + USA | Online payment processing (upon activation of the payments module) | SCCs (Decision 2021/914) + EU-US DPF; PCI-DSS Level 1 |
| Netopia | Netopia SRL (RO) | Romania | Online card payment processing (upon activation) | National law (RO) — no extra-EEA transfer; PCI-DSS |
| Postmark / Mailgun | ActiveCampaign, LLC / Mailgun Technologies, Inc. (USA) | USA (+ EU optional) | Transactional email (system notifications, confirmations) | SCCs (Decision 2021/914) |
| PFA / SRL collaborators | Sole traders and individual companies (RO) | Romania | Service delivery (design, copywriting, development) under the client contract | Individual DPA signed per collaborator; national law (RO) |
6. How to report discrepancies
If you identify a sub-processor not appearing on this list but processing data in the context of Media Design S.R.L. services, or if you find that a listed sub-processor is not GDPR-compliant, contact us at:
- Email: contact@mediadesignro.ro — subject: "Unlisted sub-processor" or "Sub-processor non-compliance"
- Phone: +40 744 933 131
We investigate all reports within 10 business days and update the list if confirmed.
7. Changelog
| Date | Change |
|---|---|
| 1 June 2026 | Initial version of the MediaDesign.ro public sub-processors list |
8. Contact
For any question regarding sub-processors or the DPA:
- Email: contact@mediadesignro.ro
- Phone: +40 744 933 131
- Postal address: MEDIA DESIGN S.R.L., Str. Lt. Col. Pretorian Nr. 3, Bl. N116, Sc. A, Ap. 7, Zalău, Sălaj county, postal code 450131, Romania
Last updated: 1 June 2026.