Subprocessors
Last updated: 15 September 2026
About Subprocessors
Guardiso uses third-party services (subprocessors) to provide the ISMS platform. Below is the complete list of subprocessors who may have access to customer personal data.
We have signed Data Processing Agreements (DPAs) with all subprocessors. For transfers outside the EEA, we use Standard Contractual Clauses (SCCs).
Subprocessor List
Change Notifications
We notify customers 30 days before adding a new subprocessor. Notification is sent to the organisation administrator's email address.
If you have objections regarding a new subprocessor, you may file an objection within 30 days of receiving the notification. In that case, we will work together to find a solution or allow contract termination without penalties.
Data Flow Details
Scaleway, S.A.S.
Scaleway stores all application data, including the PostgreSQL database with user and organization data. All data is encrypted with AES-256 at rest. Data centers hold ISO 27001, SOC 2, and HDS certifications.
Anthropic Ireland, Limited
AI features are optional. You can use the platform without them. When a user uses the Guardiso Assistant, ONLY the query content is sent to Anthropic (for example "generate a password management policy"). Anthropic processes data transiently. It does not store it after the request completes and does NOT use it for AI model training. Your database, files, configuration, and personal data are never sent to Anthropic. The contracting entity for a customer in the European Economic Area is Anthropic Ireland, Limited, established in Dublin, and prompts reach the provider servers in the United States. The transfer is made on the basis of standard contractual clauses.
OpenAI Ireland Ltd.
OpenAI is used exclusively to generate embedding vectors for semantic search across the knowledge base (RAG pipeline, text-embedding-3-small model). Only document fragments are sent to OpenAI for vectorisation. OpenAI returns numeric vectors and does not retain content after the request completes. Customer data is never used to train models. The contracting entity for a customer in the European Economic Area is OpenAI Ireland Ltd., and the transfer is made on the basis of standard contractual clauses.
Google Ireland Limited
Google processes data only for OAuth 2.0 authentication (email address, name, profile picture). We do not share additional user data with Google. For users in the European Economic Area the service is provided by Google Ireland Limited, established in Dublin, and the transfer to Google LLC in the United States is covered by the EU–US Data Privacy Framework.
Stripe Payments Europe, Limited
Payments are handled by the European entity Stripe Payments Europe, Limited, based in Ireland (EU). The group entity in the United States that receives the data is Stripe, LLC. Guardiso never sees or stores full payment card data. Card details flow directly from the user's browser to Stripe through their secure forms (Stripe Elements). Only subscription tokens and transaction metadata (amount, currency, status) reach Guardiso. Transfer is based on Stripe DPA and Standard Contractual Clauses.
Plus Five Five, Inc. (Resend service)
Resend handles transactional email: one-time sign-in links (magic link), organisation invitations, incident notifications and expiring-evidence reminders. The contracting entity is Plus Five Five, Inc. of the United States, trading as Resend. The eu-west-1 region we selected governs only where mail is sent from, not where it is stored. The provider stores it in the United States. Only email addresses and platform-generated message content reach the provider. The transfer is made on the basis of standard contractual clauses.
Cloudflare, Inc.
Cloudflare processes IP addresses and HTTP request metadata for DDoS protection and DNS resolution, using EU edge data centres (including Warsaw). The service is provided by Cloudflare, Inc. of the United States, and the transfer is covered by the EU–US Data Privacy Framework. Cloudflare does not have access to encrypted application content.
Superlative Enterprises Pty Ltd (Have I Been Pwned service)
On the customer instruction the platform checks whether email addresses in the customer domain have appeared in publicly known data breaches. Only the email address reaches the provider. Passwords are never transmitted or stored. The contracting entity is Superlative Enterprises Pty Ltd, a company registered in the state of Queensland, Australia, and personal data is stored in a Microsoft Azure data centre in the Western United States. The transfer is made on the basis of standard contractual clauses incorporated into that provider data processing agreement.
Fakturownia sp. z o.o.
Fakturownia issues invoices for the subscription. It receives the purchaser data needed for an invoice, that is the company name, address and tax identification number. The company is established in Warsaw and stores the data on servers within the European Economic Area. The data does not leave that area.
Contact
If you have questions about subprocessors or data processing:
- General: kontakt@guardiso.com
- Security: security@guardiso.com
See also: