Subprocessor List
Effective date: 24 August 2026 Last updated: 25 August 2026
This list identifies providers used to deliver VaultGuard Sync (Cloud). “Customer Personal Data” has the meaning in the Data Processing Addendum. Providers can also process limited controller data for billing, account, security, or support purposes under the Privacy Policy.
Managed-service subprocessors
| Provider | Service and data | Main processing location |
|---|---|---|
| Amazon Web Services EMEA SARL and AWS affiliates | Hosting; API and Lambda compute; encrypted object storage; KMS key wrapping; DynamoDB metadata; Cognito authentication; WAF and logs; Amazon SES transactional email | Primary workload in eu-central-1, Frankfurt, with AWS support and resilience processing governed by AWS terms |
| Google Cloud EMEA Limited / Google Workspace affiliates | Support mailbox and customer communications sent to VaultGuard | European account region where configured; limited global support access under Google terms |
AWS stores supported vault file bodies as ciphertext. It also hosts service-visible metadata and the authorised managed operations described in the Privacy Policy.
Billing and security providers
These providers process personal data for a narrower controller purpose and can act as an independent controller, processor, or both depending on the activity:
| Provider | Purpose | Customer vault content |
|---|---|---|
| Stripe Payments Europe, Limited and Stripe affiliates | Checkout, payment method setup, subscription billing, invoicing, tax and fraud prevention | Not sent |
| Cloudflare, Inc. | Turnstile human-verification and abuse-prevention signals on signup and sign-in verification surfaces | Not sent |
Optional website and campaign partners
After affirmative consent, Google (Tag Manager, Analytics, and Ads), Meta (Pixel and conversion measurement), and Apollo (website visitor measurement) process public-site, device, and attribution data. They do not receive customer vault contents, filenames, paths, or encryption keys from these tools. Depending on the processing and applicable law, they can act as independent controllers rather than Customer Personal Data subprocessors.
User-selected AI providers and desktop agents are not VaultGuard subprocessors: the user configures them, and requests go directly from the user’s device to the selected provider.
Changes and objections
Business customers generally authorise the subprocessors on this list through the DPA. We will update this page and give the notice required by the DPA or an order form before a new subprocessor begins processing Customer Personal Data. A Customer can object on reasonable data-protection grounds by emailing support@vaultguard.cloud during the stated notice period.