Authorized Sub-processors & Infrastructure
To provide high-availability managed web hosting, ultra-fast static edge delivery, secure transactional messaging, and resilient database backends, WebSage by CodeBitel engages vetted third-party infrastructure providers (Sub-processors).
Sub-processor Evaluation & Governance Charter
Every sub-processor engaged by WebSage undergoes rigorous security vetting, architectural uptime review, and statutory compliance assessment under India’s Digital Personal Data Protection Act, 2023 (DPDPA) and the European Union’s General Data Protection Regulation (GDPR).
1. Global Datacenter Regions & Sovereign Infrastructure
WebSage provisions compute nodes, isolated database replicas, and edge acceleration across tier-1 carrier-neutral enterprise datacenters located in the following primary sovereign jurisdictions:
India (Domestic Sovereign Hub)
Primary RegionFacilities: Mumbai, Pune, Delhi NCR, Bengaluru, Chennai, and Kolkata.
High-frequency compute instances, managed MySQL/PostgreSQL databases, and direct edge PoPs. Fully compliant with Indian Data Residency directives, RBI payment localization guidelines, and CERT-In reporting rules.
Japan (East Asia Hub)
APAC EastFacilities: Tokyo and Osaka.
Ultra-low-latency NVMe edge compute serving Japan and Greater East Asia. Certified to ISO/IEC 27001, Tier-3 facility resiliency, and APPI data protection safeguards.
Singapore (Central APAC Gateway)
APAC CentralFacilities: Jurong and Tai Seng carrier-dense clusters.
High-bandwidth subsea backbone interconnection connecting Southeast Asia, India, and Australia. Tier-3/Tier-4 redundant architecture with PCI-DSS Level 1 physical perimeter security.
European Union (EU Sovereign Cloud)
GDPR RegionFacilities: Frankfurt (Germany) and Amsterdam (Netherlands).
Dedicated compute and backup snapshot nodes governed strictly by GDPR Article 28 and EU Standard Contractual Clauses (SCCs). Certified ISO 27001, ISO 9001, ISO 50001 (energy management), and ISO 14001.
United States (North America Core)
AmericasFacilities: Ashburn (Virginia), Silicon Valley (California), and Dallas (Texas).
High-throughput cloud instances and encrypted object storage repositories. SOC 2 Type II and ISO 27001 audited with 24/7 biometric physical perimeter surveillance.
2. Infrastructure & Technical Sub-processor Categories
WebSage maintains strict operational confidentiality regarding our proprietary multi-cluster server topology while ensuring all underlying facilities adhere to international Tier-3/Tier-4 security benchmarks and global data protection standards (GDPR & DPDPA). The following functional categories support the platform:
| Functional Category | Operational Scope & Processing Role | Data Residency & Location | Security & Compliance Standards |
|---|---|---|---|
| Enterprise Cloud Compute & Database Infrastructure | Isolated high-performance virtual compute, NVMe SSD storage arrays, managed database instances (MySQL/PostgreSQL) & encrypted off-site snapshot replication. | India (Mumbai, Pune), EU Sovereign Hub (Frankfurt, Amsterdam), USA, Singapore & Japan Tier-3/Tier-4 Facilities. | ISO/IEC 27001 (Information Security), ISO 9001 (Quality), ISO 50001 (Energy), ISO 14001, SOC 2 Type II, and GDPR / DPDPA compliant. |
| Edge Acceleration, Anycast DNS & DDoS Shield | Global Anycast DNS resolution, edge asset caching, Brotli compression, TLS 1.3 encryption termination & automated multi-layer L3/L4/L7 DDoS mitigation. | Global Edge Network (Low-latency PoPs in Delhi, Mumbai, Chennai, Bengaluru, Kolkata, Tokyo, Singapore, Frankfurt, London, Ashburn, San Jose). | ISO 27001, SOC 2 Type II, PCI-DSS Level 1, DPDPA compliant edge defense. |
| High-Deliverability Transactional Email Relays | Multi-route outbound transactional delivery for customer order receipts, GST tax invoices, password resets, and administrative security alerts. | Dedicated Authenticated Outbound Relays (US & EU encrypted nodes). | TLS 1.3 enforced, SPF / DKIM / DMARC cryptographically authenticated with continuous IP reputation management. |
| TRAI-DLT Registered Telecom & Messaging Gateways | Instant OTP verification, automated order dispatch tracking updates, and WhatsApp Business API transaction notifications. | India (TRAI DLT Registered Telecom Network). | TRAI Registered, ISO 27001 certified telecom routing, End-to-End Encrypted WhatsApp Business API. |
| Automated Security Telemetry & Uptime Synthetics | Continuous 60-second synthetic health pings, response latency tracing, Core Web Vitals profiling, and anomaly alerting. | Multi-region distributed monitoring probes (US, EU, APAC). | SOC 2 Type II, zero access to client payload data (telemetry metadata only). |
3. Third-Party Integrations (Client & Merchant-Directed)
When clients deploy custom e-commerce stores, CRM workflows, or booking engines through WebSage, they may optionally connect their own accounts with certified third-party service providers. In these scenarios, data is transmitted strictly under the client's direct contract and instructions:
Integrations with Razorpay, Cashfree, Stripe, and PayU. Authorized by the Reserve Bank of India (RBI) and fully certified under PCI-DSS Level 1 tokenization standards. WebSage never stores, processes, or retains raw credit/debit card numbers or CVVs.
Courier partners (Shiprocket, Delhivery, Blue Dart) utilized for real-time shipping rate computation, automated AWB generation, and consignment pickup dispatching. Transmitted customer data is restricted to shipping addresses and telephone coordinates.
Google Analytics 4 (GA4), Cloudflare Web Analytics (cookie-free), and Google Search Console tags configured at client request. All implementations default to IP anonymization and cookie-consent banners aligned with DPDP/GDPR.
4. Sub-processor Governance & Data Protection Standards
All infrastructure facilities utilized by WebSage are evaluated under enterprise Data Processing Agreements (DPAs) and cloud vendor terms to ensure rigorous data isolation, encryption standards, and alignment with the Digital Personal Data Protection Act, 2023 (DPDPA) and the EU GDPR:
- End-to-End Cryptographic Protection: Data in transit is enforced with TLS 1.3 encryption; all off-site snapshots and persistent database volumes are encrypted at rest using AES-256 with managed KMS keys.
- Security Audits & Re-assessment: We perform recurring annual technical re-assessments of all critical sub-processors to confirm SOC 2 Type II or ISO 27001 recertifications.
- Breach Notification Protocol: In the event of a confirmed security incident impacting any sub-processor facility, WebSage requires notification within 24–48 hours to enable timely regulatory reporting to CERT-In and affected clients.
5. Notification of Updates & Right to Object
WebSage maintains an updated public list of all authorized sub-processors on this page. When a material change occurs or a new infrastructure sub-processor is onboarded:
- We update this registry and provide written or electronic notification to subscribed clients at least 30 calendar days prior to authorizing the new sub-processor to process client data.
- Clients may object to the appointment of a new sub-processor on reasonable data protection or compliance grounds by submitting written notice to [email protected] within 15 days of notification.
- If an objection cannot be resolved through technical reconfiguration or alternate routing, the client may terminate the affected service agreement without early termination penalty.
Compliance & Data Protection Desk
For questions regarding WebSage sub-processors, executing an enterprise Data Processing Agreement (DPA), or requesting audit summaries, please reach out to our legal compliance team: