LegacyGuard · legal documents
Sub-processors
Sub-processors are third-party services that process user data on our behalf — for example a payment gateway or a transactional email platform. Publishing them is a legal requirement under GDPR Article 13(1)(e), but it is also a matter of principle: everyone who touches your data should be visible on this list. We update it whenever we add a new sub-processor or change the terms of an existing one, and at a minimum once per year. If we plan to onboard a new sub-processor, we will notify you in advance — at least 30 days before processing begins.
Status definitions
- Sub-processor is in active use. DPA is signed and reviewed regularly.
- Contract and DPA are finalised; integration is under way. No data flows yet.
- Sub-processor under evaluation. No data flows until the contract is formally signed.
- Sub-processor has been disconnected; data was securely migrated or deleted.
| Name | Role | Location | Data | DPA | Cross-border transfer | Updated |
|---|---|---|---|---|---|---|
Hetzner Online GmbHactive | Primary hosting infrastructure (Cloud servers, Object Storage, Volumes, Backups, Cloud Firewall) + self-hosted Postgres database | EU — DE Frankfurt (FSN1) primary, FI Helsinki (HEL1) DR target |
| DPA | – | |
Cloudflare, Inc.active | DNS, CDN/edge, WAF, R2 object storage (EU bucket lg-vault-prod-eu), Email Routing, Cloudflare Tunnel for ops access | US entity (Delaware) — EU Data Localisation Suite enabled; R2 bucket EU jurisdiction; workload stays in EU |
| DPA | USEU-U.S. DPF — participant #5666SCC 2021/914 modules 2+3 NoteEU-US DPF primary (LEG-2417 verified 2026-08-06, participant #5666, EU-US + UK Ext + Swiss-US) + SCC 2021/914 mod 2+3 fallback. US CLOUD Act applies to US entity even with EU Data Localisation Suite. | |
Resend (Resend Inc.)active | Transactional email delivery — magic-link authentication, beneficiary notifications, lifecycle emails | US entity (Delaware) — správa a část provozních operací v USA; workload EU region DE Frankfurt (eu-west-1) |
| DPA | USEU-U.S. DPF — participant #8907SCC 2021/914 modules 2+3 NoteEU-U.S. DPF primary (LEG-2347 verified, participant #8907) + SCC 2021/914 mod 2+3 fallback per LEG-2320 F1 dual-track. US CLOUD Act aplikuje na US entitu i při EU workload regionu. | |
Plausible Insights OÜplanned | Privacy-by-design product + marketing analytics (cookie-less, no PII, no cross-site tracking) | EU — Estonia legal entity; infrastructure Hetzner DE Frankfurt |
| DPA | – | |
PostHog Inc.active | Product analytics (EU Cloud region) — first-class credential per env-coherence guard (POSTHOG_KEY + POSTHOG_ENV_EXPECT); production integration verification pending LEG-1758 | US entity (San Francisco, CA) — EU Cloud region https://eu.posthog.com per .env.example |
| DPA | USSCC 2021/914 modules 2 NoteSCC 2021/914 Module 2 only — PostHog DPA (https://posthog.com/dpa) explicitly offers "text from module 2 and no other modules"; Module 3 is not on offer. PostHog, Inc. self-certifies EU-US DPF + UK Extension + Swiss-US DPF in its DPA and privacy policy, but the participant ID is not published in vendor documentation and dataprivacyframework.gov verification is pending LEG-2417 (DPF-Prime, PostHog added to scope). Until verified, dpf is withheld from legalBasis — same fail-closed pattern as Cloudflare/Sentry. US CLOUD Act applies to PostHog, Inc. (San Francisco, CA) regardless of EU Cloud region selection; eu.posthog.com is a region choice, not an entity boundary (per PostHog privacy policy: "hosted in the United States, or in Germany if you are a PostHog Cloud customer who has selected EU hosting"). | |
Stripe Payments Europe, Ltd.in preparation | Payments processing (subscription billing), Stripe Tax (EU OSS VAT), SCA/3DS, billing portal | EU — Ireland (Dublin); Stripe Inc. (US) fallback for non-EEA corridors with SCC + DPF |
| DPA | – | |
Functional Software, Inc. (Sentry)in preparation | Application error monitoring, backend exception capture, source-map upload | US entity (California) — EU data residency region DE Frankfurt (sentry.io/eu) |
| DPA | USEU-U.S. DPF — participant #5869SCC 2021/914 modules 2+3 NoteEU-US DPF primary (LEG-2417 verified 2026-08-06, participant #5869, EU-US + UK Ext + Swiss-US) + SCC 2021/914 mod 2+3 fallback. US CLOUD Act applies to US entity even with EU data residency election. | |
GitHub, Inc.active | Source code hosting, CI/CD (GitHub Actions), container registry — no user PII | US (Microsoft subsidiary) | No user personal data — internal operational tool. | DPA | – | |
AgileBits Inc. (1Password)active | Internal team secrets vault — Phase 0 interim; no user PII | Canada / US | No user personal data — internal operational tool. | DPA unavailable | – | |
Proton AG (Proton Pass for Business)planned | Internal team secrets vault — migration target from 1Password; no user PII | Switzerland (EU-adequate) | No user personal data — internal operational tool. | DPA | – | |
Identity verification provider — TBDplanned | Document-only beneficiary identity verification (Activity #4) — provider TBD; shortlist: Veriff, Sumsub, iDenfy | TBD — EU-resident processor mandatory |
| DPA unavailable | – |
Need a DPA for your organisation?
If you process customer or employee data through LegacyGuard, we can provide you with a Data Processing Agreement. Contact us at privacy@legacyguard.vip.
Request a DPAA formal Data Protection Officer will be designated prior to public launch. Until then, please direct all data protection enquiries to privacy@legacyguard.vip; every request is handled within the timelines set out in GDPR Article 12(3).