Last updated: 12 August 2026 · This page is the authoritative current list of sub-processors engaged by Ansvar.
Change log: 12 August 2026 — added Scaleway S.A.S. (Object Storage) as off-site backup storage: a daily add-only, write-once mirror of infrastructure backups in France (EEA), running alongside the existing Azure Blob mirror while backup storage migrates to Scaleway. The mirror has been in operation since 12 July 2026; this roster entry was published late, on 12 August 2026. 27 July 2026 — DigiCert, Inc. removed from the sub-processor roster and reclassified as an ancillary recipient: it receives only the daily aggregate Merkle root hash and Processes no Personal Data on Ansvar's behalf, so it is not a sub-processor under Article 28 GDPR; the disclosure is retained under "Ancillary recipients". 23 July 2026 — added links to each sub-processor's own data-processing terms (no change to the roster). 9 July 2026 — added Microsoft Ireland Operations Limited (Azure Blob Storage, off-site backup storage in the EEA).
This page lists the sub-processors that Ansvar Systems AB ("Ansvar") engages to Process Personal Data on behalf of its customers in connection with the Ansvar Gateway and related services. The Current sub-processors table below is the authoritative, up-to-date list and is the list incorporated into Annex 3 of the Data Processing Addendum; the separate Ancillary recipients disclosure is published for transparency and is not incorporated into Annex 3. Ansvar remains liable to the customer for the acts and omissions of its sub-processors.
| Name | Role / service | Address of establishment | Location(s) of the Processing | Transfer mechanism |
|---|---|---|---|---|
| Hetzner Online GmbH | Cloud infrastructure and hosting; key-management infrastructure | Industriestr. 25, 91710 Gunzenhausen, Germany | Finland (Helsinki) — production Kubernetes cluster (compute, hosting, key-management, and the audit-ledger database); Germany (Falkenstein) — encrypted off-site backups (Storage Box) | None required — processing within the EEA |
| Microsoft Ireland Operations Limited (Azure Blob Storage) | Off-site backup storage (disaster recovery) — a daily add-only mirror of infrastructure backups, including database backups, held with write-once retention | One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland | North Europe region (Ireland, EEA) | None required — storage within the EEA; limited onward transfer to Microsoft Corp. (US) possible for support/telemetry, covered by EU SCCs + EU–US Data Privacy Framework (Microsoft self-certified) |
| Scaleway S.A.S. (Object Storage) | Off-site backup storage (disaster recovery) — a daily add-only mirror of infrastructure backups, including database backups, held with write-once retention (object lock) | 8 rue de la Ville l'Évêque, 75008 Paris, France | France (fr-par region, EEA) | None required — processing within the EEA |
| Cloudflare, Inc. | TLS termination, CDN, WAF, DDoS protection | 101 Townsend Street, San Francisco, CA 94107, USA | EU edge (TLS termination) + US routing | Terminates TLS and processes traffic in transit at the EU edge; some routing/processing may occur in the US. Covered by the EU–US Data Privacy Framework (Cloudflare self-certified) + EU SCCs (Module 2/3) as fallback. |
| Stripe | Payment processing for paid subscriptions | 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland | Primarily Ireland (EEA); onward to Stripe, Inc. (US) for some processing | EU SCCs + EU–US Data Privacy Framework (Stripe, Inc. self-certified) |
| Scaleway S.A.S. (TEM) | Transactional email (account, billing, security notifications) | 8 rue de la Ville l'Évêque, 75008 Paris, France | France (fr-par region) | None required — processing within the EEA |
| Microsoft 365 | Productivity, email, and support tooling | One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland | EU Data Boundary (EEA); limited onward to Microsoft Corp. (US) for support/telemetry | EU SCCs + EU–US Data Privacy Framework (Microsoft self-certified); EU Data Boundary minimises transfers |
The party below receives data from Ansvar in connection with the Services but does not Process Personal Data on Ansvar's behalf. It is therefore not a sub-processor under Article 28 GDPR and does not form part of Annex 3. It is disclosed here for transparency. See Annex 4 (Audit Ledger), A4.8 for the integrity-and-timestamping detail.
| Name | Role / service | Address of establishment | Location(s) | What it receives |
|---|---|---|---|---|
| DigiCert, Inc. | RFC-3161 timestamping of the aggregate Merkle root hash only — Company Audit Ledger feature | 2801 N. Thanksgiving Way, Lehi, UT 84043, USA | United States (RFC-3161 timestamp authority) | The daily aggregate Merkle root imprint and the RFC-3161 protocol metadata that accompanies it — no tenant identifier, no per-receipt hash, no Ledger content. No Personal Data is transferred (no PII, irreversible), so no Chapter V transfer mechanism is required. Backstop: DigiCert, Inc. self-certifies under the EU–US Data Privacy Framework (incl. the UK Extension and Swiss–US DPF) per its published privacy notice. |
For vendor due diligence — verifying our Article 28 chain, or building your own — each sub-processor publishes its data-processing terms here. These links are provided for reference only: they are not incorporated into the DPA or this Annex, and the linked vendor terms do not modify Ansvar's obligations under the DPA.
DigiCert, Inc. is not a sub-processor (see Ancillary recipients above) and receives only the daily aggregate Merkle root hash, so its terms are not listed here.
Ansvar provides prior written notice to customers of any intended addition or replacement of a sub-processor at least fifteen (15) calendar days before the change takes effect, and customers may object within ten (10) calendar days on reasonable data-protection grounds specific to the relevant sub-processor, in accordance with the "Sub-processors" section of the DPA. To be notified of changes, or to raise an objection, contact privacy@ansvar.eu.
See the Data Processing Addendum for the full GDPR Article 28 processing terms, the Privacy Notice for processing where Ansvar acts as controller, and the Terms of Service for the general subscription terms.