Subprocessors

Last updated: 2026-08-26

These are the third parties that process customer data on our behalf. The list is short on purpose - every additional vendor is an additional place your data exists - and this page is updated before a new one starts processing anything.

Provider What it does for us Data it touches Region
Google Cloud Platform
Google Ireland Ltd / Google LLC
Runs the application and database (Cloud Run, managed Postgres) All service data: accounts, monitoring configuration, scan results EU (europe-west3 - Frankfurt)
Firebase Hosting
part of Google
Serves this website and the application’s static assets over a CDN Request metadata (IP address, user agent) as any CDN sees Global edge network
Paddle.com Market Ltd Merchant of record: checkout, payment processing, tax calculation and remittance, invoicing, subscription management Billing identity (name, e-mail, country, tax ID if given) and full payment details - which never reach our servers United Kingdom (UK adequacy for EU data; SCCs where required)
PostHog
PostHog, Inc. - US Cloud
Product analytics: how the website and app are used, so we can improve them. On this website it runs an anonymous, cookieless visit count for everyone (nothing stored on your device), and richer, identified analytics only after you accept in the consent banner Usage events - pages viewed, clicks, device and browser, approximate location from IP; in the app, events tied to your account. Never certificate contents or private keys United States; SCCs apply for EU/UK data
Planned addition. A transactional e-mail provider will be added here before e-mail alerting ships - it will see recipient addresses and alert contents, nothing more. If you subscribe to updates on this page (or just check the date above), you will see it land here first.

What every subprocessor is bound to

  • A written agreement restricting processing to our documented instructions.
  • Confidentiality and security obligations at least as protective as our own privacy policy.
  • For processing outside the EEA/UK: recognised transfer safeguards (Standard Contractual Clauses or an adequacy decision).

Notice of changes

We update this page before engaging a new subprocessor for customer data. Customers with a DPA that requires direct notice receive it by e-mail with reasonable advance time to object. Questions to privacy@sslscan.net.