Subprocessors List

Last Updated: November 14, 2025

Effective Date: November 14, 2025

Overview

This page lists all third-party service providers (subprocessors) that Guard.ch engages to process customer data in the course of providing our virtual machine management services.

Guard.ch is committed to transparency about our subprocessors and will update this list when we add, replace, or remove subprocessors. Customers will be notified of changes in accordance with our Data Processing Agreement (DPA).

Notification of Changes

How We Notify You:

  • Email notification to your account email address
  • Update to this Subprocessors List page with revision date
  • Minimum 30 days' advance notice (when reasonably possible)

Your Right to Object: If you object to a new or replacement subprocessor on reasonable data protection grounds, you may notify us within 30 days at support@guard.ch. See our DPA for details on objection procedures.

Current Subprocessors

Infrastructure and Hosting

SubprocessorPurposeData LocationData ProcessedSafeguardsPrivacy Policy
Hetzner Online GmbH<br/>Industriestr. 25<br/>91710 Gunzenhausen<br/>GermanyInfrastructure hosting and primary data storageHelsinki, Finland (EU)All customer data, account information, VM metadata, operational dataGDPR compliance (EU-based provider), ISO 27001 certifiedHetzner Privacy Policy
OVH US LLC<br/>21351 Gentry Drive<br/>Dulles, VA 20166<br/>USAInfrastructure hosting for US customer VM sessions only (no persistent data storage)Hillsboro, Oregon, USAVM session data for US-region customers (temporary only)Standard Contractual Clauses, EU-US Data Privacy FrameworkOVH Privacy Policy

Payment Processing

SubprocessorPurposeData LocationData ProcessedSafeguardsPrivacy Policy
Stripe, Inc.<br/>510 Townsend Street<br/>San Francisco, CA 94103<br/>USAPayment processing, subscription management, and invoicingUSA (multiple data centers)Email, billing information, payment transaction data, Stripe customer IDStandard Contractual Clauses, EU-US Data Privacy Framework, PCI DSS Level 1 certifiedStripe Privacy Policy

Security and Infrastructure Services

SubprocessorPurposeData LocationData ProcessedSafeguardsPrivacy Policy
Cloudflare, Inc.<br/>101 Townsend Street<br/>San Francisco, CA 94107<br/>USADNS services, CDN, DDoS protection, and WAFGlobal network (data may transit through various locations)IP addresses, DNS queries, HTTP request metadataEU-US Data Privacy Framework, ISO 27001, SOC 2 Type IICloudflare Privacy Policy

Logging and Monitoring

SubprocessorPurposeData LocationData ProcessedSafeguardsPrivacy Policy
Axiom, Inc.<br/>660 4th Street #367<br/>San Francisco, CA 94107<br/>USALog aggregation, monitoring, and observabilityUSAServer access logs, application logs, error logs (including IP addresses, timestamps, request URLs) - 30-day retentionStandard Contractual Clauses, SOC 2 Type IIAxiom Privacy Policy

Authentication Services (Optional)

SubprocessorPurposeData LocationData ProcessedSafeguardsPrivacy Policy
Google LLC<br/>1600 Amphitheatre Parkway<br/>Mountain View, CA 94043<br/>USAOAuth authentication (optional) and website analytics (Google Analytics)USA and globalOAuth: Email and basic profile data when you choose Google login<br/>Analytics: Website usage data, anonymized IP addresses, browser/device info, page viewsEU-US Data Privacy Framework, ISO 27001Google Privacy Policy
Microsoft Corporation<br/>One Microsoft Way<br/>Redmond, WA 98052<br/>USAOAuth authentication (optional)USA and globalEmail and basic profile data when you choose Microsoft loginEU-US Data Privacy Framework, ISO 27001, SOC 2Microsoft Privacy Policy

Advertising Services

SubprocessorPurposeData LocationData ProcessedSafeguardsPrivacy Policy
Playwire LLC<br/>3399 Peachtree Road NE, Suite 200<br/>Atlanta, GA 30326<br/>USAAdvertising services and ad deliveryUSAIP addresses, browser/device information, ad interaction data, browsing behavior on Guard.chStandard Contractual ClausesPlaywire Privacy Policy

Data Transfer Mechanisms

For subprocessors located outside Switzerland and the European Economic Area (EEA), Guard.ch ensures appropriate safeguards for international data transfers:

EU-US Data Privacy Framework

The following subprocessors are certified under the EU-US Data Privacy Framework:

  • Stripe, Inc.
  • Cloudflare, Inc.
  • Google LLC
  • Microsoft Corporation
  • OVH US LLC

You can verify certifications at: https://www.dataprivacyframework.gov/list

Standard Contractual Clauses (SCCs)

For subprocessors not covered by the Data Privacy Framework, Guard.ch uses Standard Contractual Clauses approved by:

  • The Swiss Federal Data Protection and Information Commissioner (FDPIC)
  • The European Commission

SCCs are in place with:

  • Axiom, Inc.
  • Playwire LLC
  • All other US-based subprocessors as supplemental safeguards

Copies of Transfer Mechanisms

Customers may request copies of the Standard Contractual Clauses or other transfer mechanisms by contacting support@guard.ch.

Important Notes

VM Content

Guard.ch does not access or process the content of your virtual machines. Any personal data you store, process, or transmit within your VMs is your sole responsibility. Guard.ch has no technical capability to access VM content and acts solely as an infrastructure provider for VMs.

The subprocessors listed above process only:

  • Account and authentication data
  • VM metadata (IDs, creation times, usage statistics)
  • Billing and payment information
  • Access logs and operational data

Primary Data Storage

All persistent customer data is stored in the European Union (Hetzner Helsinki data center, Finland). OVH US is used only for running VM sessions for US-region customers; no persistent customer data is stored on OVH infrastructure.

Additional Third-Party Services

Guard.ch infrastructure may use additional third-party services that do not process customer personal data (e.g., DNS registrars, code repositories, development tools). These are not listed as subprocessors as they do not process personal data on behalf of customers.

Subprocessor Security and Compliance

Guard.ch requires all subprocessors to:

  1. Implement Appropriate Security Measures:

    • Encryption in transit and at rest
    • Access controls and authentication
    • Regular security assessments
    • Incident response procedures
  2. Maintain Compliance:

    • Comply with applicable data protection laws (Swiss FADP, EU GDPR)
    • Maintain relevant certifications (ISO 27001, SOC 2, PCI DSS where applicable)
    • Undergo regular security audits
  3. Contractual Obligations:

    • Execute Data Processing Agreements with Guard.ch
    • Agree to process data only on Guard.ch's instructions
    • Implement confidentiality obligations
    • Provide security breach notification
    • Assist with data subject rights requests
    • Delete or return data upon request

Data Retention by Subprocessors

SubprocessorData Retention PeriodPurpose
HetznerDuration of service + 30 daysInfrastructure hosting
OVH USSession duration only (no persistent storage)VM sessions
StripeDuration of service + up to 7 yearsPayment records, fraud prevention, legal compliance
CloudflareVaries by service (typically 24 hours to 30 days for logs)Security, performance optimization
Axiom30 daysLog retention and monitoring
Google (OAuth)Per Google's retention policiesAuthentication
Google (Analytics)14-50 months (configurable)Analytics
MicrosoftPer Microsoft's retention policiesAuthentication
PlaywirePer Playwire's retention policiesAdvertising analytics

Guard.ch's overall data retention practices are governed by our Privacy Policy and DPA.

Subprocessor Due Diligence

Guard.ch conducts due diligence on all subprocessors before engagement, including:

  • Security and privacy assessments
  • Review of data protection policies and practices
  • Verification of compliance certifications
  • Contractual review and negotiation
  • Ongoing monitoring and periodic reassessment

Requesting Information

For questions about our subprocessors or to request additional information:

Email: support@guard.ch

Postal Address: See our Imprint for full contact details.

You may request:

  • Copies of Data Processing Agreements with subprocessors (subject to confidentiality restrictions)
  • Copies of Standard Contractual Clauses
  • Additional information about security measures
  • Clarification about data processing activities

Change History

DateChangeSubprocessor(s) Affected
November 14, 2025Initial publication of comprehensive Subprocessors ListAll subprocessors listed

Future changes will be documented in this section with the date, nature of the change, and affected subprocessors.


Last Review Date: November 14, 2025

Next Scheduled Review: May 14, 2026


This Subprocessors List is maintained in accordance with our Data Processing Agreement and Privacy Policy. For more information about our data protection practices, please refer to those documents.