LegacyGuardPrávní dokumenty

LegacyGuard · legal documents

Sub-processors

Sub-processors are third-party services that process user data on our behalf — for example a payment gateway or a transactional email platform. Publishing them is a legal requirement under GDPR Article 13(1)(e), but it is also a matter of principle: everyone who touches your data should be visible on this list. We update it whenever we add a new sub-processor or change the terms of an existing one, and at a minimum once per year. If we plan to onboard a new sub-processor, we will notify you in advance — at least 30 days before processing begins.

RSS feed

Status definitions

active
Sub-processor is in active use. DPA is signed and reviewed regularly.
in preparation
Contract and DPA are finalised; integration is under way. No data flows yet.
planned
Sub-processor under evaluation. No data flows until the contract is formally signed.
decommissioned
Sub-processor has been disconnected; data was securely migrated or deleted.
LegacyGuard sub-processor list — GDPR Article 13(1)(e)
NameRoleLocationDataDPACross-border transferUpdated
Hetzner Online GmbHactive
Primary hosting infrastructure (Cloud servers, Object Storage, Volumes, Backups, Cloud Firewall) + self-hosted Postgres databaseEU — DE Frankfurt (FSN1) primary, FI Helsinki (HEL1) DR target
  • vault content (AES-256-GCM envelope-encrypted — server-side custodial model)
  • user account metadata (email, display name, account timestamps)
  • magic-link tokens (HMAC-SHA256, short-TTL)
  • TOTP shared secrets (AES-256-GCM at rest)
  • audit log records
  • beneficiary contact data (email, name, relationship)
  • system logs (request metadata)
DPA
Cloudflare, Inc.active
DNS, CDN/edge, WAF, R2 object storage (EU bucket lg-vault-prod-eu), Email Routing, Cloudflare Tunnel for ops accessUS entity (Delaware) — EU Data Localisation Suite enabled; R2 bucket EU jurisdiction; workload stays in EU
  • vault content (AES-256-GCM ciphertext — passes through CDN/R2; server-side encrypted)
  • request metadata (IP addresses, user-agent, TLS metadata at edge)
  • DNS query logs (zone-level)
  • email-routing envelope metadata (sender/recipient addresses)
DPA
USEU-U.S. DPFparticipant #5666SCC 2021/914 modules 2+3
Note

EU-US DPF primary (LEG-2417 verified 2026-08-06, participant #5666, EU-US + UK Ext + Swiss-US) + SCC 2021/914 mod 2+3 fallback. US CLOUD Act applies to US entity even with EU Data Localisation Suite.

Resend (Resend Inc.)active
Transactional email delivery — magic-link authentication, beneficiary notifications, lifecycle emailsUS entity (Delaware) — správa a část provozních operací v USA; workload EU region DE Frankfurt (eu-west-1)
  • recipient email addresses (account holders + beneficiaries)
  • email body content (magic-link URL, notification copy, recipient name)
  • delivery telemetry (sent/delivered/bounced/opened events)
DPA
USEU-U.S. DPFparticipant #8907SCC 2021/914 modules 2+3
Note

EU-U.S. DPF primary (LEG-2347 verified, participant #8907) + SCC 2021/914 mod 2+3 fallback per LEG-2320 F1 dual-track. US CLOUD Act aplikuje na US entitu i při EU workload regionu.

Plausible Insights OÜplanned
Privacy-by-design product + marketing analytics (cookie-less, no PII, no cross-site tracking)EU — Estonia legal entity; infrastructure Hetzner DE Frankfurt
  • pseudonymous page-view events (page path, referrer, UTM params, country-level geo, anonymised browser/OS)
DPA
PostHog Inc.active
Product analytics (EU Cloud region) — first-class credential per env-coherence guard (POSTHOG_KEY + POSTHOG_ENV_EXPECT); production integration verification pending LEG-1758US entity (San Francisco, CA) — EU Cloud region https://eu.posthog.com per .env.example
  • pseudonymous product-analytics events (page views, feature interactions, session identifiers)
DPA
USSCC 2021/914 modules 2
Note

SCC 2021/914 Module 2 only — PostHog DPA (https://posthog.com/dpa) explicitly offers "text from module 2 and no other modules"; Module 3 is not on offer. PostHog, Inc. self-certifies EU-US DPF + UK Extension + Swiss-US DPF in its DPA and privacy policy, but the participant ID is not published in vendor documentation and dataprivacyframework.gov verification is pending LEG-2417 (DPF-Prime, PostHog added to scope). Until verified, dpf is withheld from legalBasis — same fail-closed pattern as Cloudflare/Sentry. US CLOUD Act applies to PostHog, Inc. (San Francisco, CA) regardless of EU Cloud region selection; eu.posthog.com is a region choice, not an entity boundary (per PostHog privacy policy: "hosted in the United States, or in Germany if you are a PostHog Cloud customer who has selected EU hosting").

Stripe Payments Europe, Ltd.in preparation
Payments processing (subscription billing), Stripe Tax (EU OSS VAT), SCA/3DS, billing portalEU — Ireland (Dublin); Stripe Inc. (US) fallback for non-EEA corridors with SCC + DPF
  • payment card metadata (BIN, last4, network — full PAN tokenised by Stripe)
  • billing identity (name, email, billing address, country, VAT ID)
  • transaction records (amount, currency, timestamp, dispute/refund history)
  • Stripe Customer ID + Subscription ID (linked to LegacyGuard user ID)
DPA
Functional Software, Inc. (Sentry)in preparation
Application error monitoring, backend exception capture, source-map uploadUS entity (California) — EU data residency region DE Frankfurt (sentry.io/eu)
  • exception stack traces + breadcrumbs (PII scrubbing enabled)
  • user ID (pseudonymous LegacyGuard UUID — NOT email)
  • request metadata (URL, method, status, anonymised IP)
  • browser/OS fingerprint at error time
DPA
USEU-U.S. DPFparticipant #5869SCC 2021/914 modules 2+3
Note

EU-US DPF primary (LEG-2417 verified 2026-08-06, participant #5869, EU-US + UK Ext + Swiss-US) + SCC 2021/914 mod 2+3 fallback. US CLOUD Act applies to US entity even with EU data residency election.

GitHub, Inc.active
Source code hosting, CI/CD (GitHub Actions), container registry — no user PIIUS (Microsoft subsidiary)No user personal data — internal operational tool.DPA
AgileBits Inc. (1Password)active
Internal team secrets vault — Phase 0 interim; no user PIICanada / USNo user personal data — internal operational tool.DPA unavailable
Proton AG (Proton Pass for Business)planned
Internal team secrets vault — migration target from 1Password; no user PIISwitzerland (EU-adequate)No user personal data — internal operational tool.DPA
Identity verification provider — TBDplanned
Document-only beneficiary identity verification (Activity #4) — provider TBD; shortlist: Veriff, Sumsub, iDenfyTBD — EU-resident processor mandatory
  • (future) beneficiary ID document scan, structured ID data, verification outcome
DPA unavailable

Want 30-day advance notice of changes?

Whenever we add a new sub-processor or change an existing one, we will email you at least 30 days before the change takes effect — giving you time to act.

Need a DPA for your organisation?

If you process customer or employee data through LegacyGuard, we can provide you with a Data Processing Agreement. Contact us at privacy@legacyguard.vip.

Request a DPA

A formal Data Protection Officer will be designated prior to public launch. Until then, please direct all data protection enquiries to privacy@legacyguard.vip; every request is handled within the timelines set out in GDPR Article 12(3).

Sub-processors — LegacyGuard · LegacyGuard