← Home
PLEN

Subprocessors

Last updated: 15 September 2026

About Subprocessors

Guardiso uses third-party services (subprocessors) to provide the ISMS platform. Below is the complete list of subprocessors who may have access to customer personal data.

We have signed Data Processing Agreements (DPAs) with all subprocessors. For transfers outside the EEA, we use Standard Contractual Clauses (SCCs).

Subprocessor List

NamePurposeWhere data is processedDPA Status
Scaleway, S.A.S.Application hosting, database, file storagePoland (Warsaw region)DPA, data stays in the EEA
Cloudflare, Inc.DNS, attack protection, traffic analyticsUnited States (edge nodes also in the EU)DPA and EU–US Framework
Anthropic Ireland, LimitedLanguage model: Guardiso Assistant, policy and analysis generationUnited States (the provider servers; the contracting entity is established in Dublin, Ireland)DPA and contractual clauses
OpenAI Ireland Ltd.Text embeddings for knowledge base searchUnited States (processing outside the European Economic Area; the contracting entity is the Irish company)DPA and contractual clauses
Google Ireland Ltd. / Google LLCSign-in with Google (identity provider)Ireland (the Google group also in the US)DPA and EU–US Framework
Plus Five Five, Inc. (Resend service)Transactional email: login links, invitations, notificationsUnited States (data is stored there; the eu-west-1 region only governs where mail is sent from)DPA and contractual clauses
Stripe Payments Europe, LimitedPayment and subscription processingIreland (the Stripe group also in the US)DPA and contractual clauses
Fakturownia sp. z o.o.Invoice issuingPolandDPA, data stays in the EEA
Superlative Enterprises Pty Ltd (Have I Been Pwned service)Checking whether a company email address appears in a known breachUnited States (a Microsoft Azure data centre in the Western United States; the entity is registered in the state of Queensland, Australia)DPA and contractual clauses

Change Notifications

We notify customers 30 days before adding a new subprocessor. Notification is sent to the organisation administrator's email address.

If you have objections regarding a new subprocessor, you may file an objection within 30 days of receiving the notification. In that case, we will work together to find a solution or allow contract termination without penalties.

Data Flow Details

Scaleway, S.A.S.

Scaleway stores all application data, including the PostgreSQL database with user and organization data. All data is encrypted with AES-256 at rest. Data centers hold ISO 27001, SOC 2, and HDS certifications.

Anthropic Ireland, Limited

AI features are optional. You can use the platform without them. When a user uses the Guardiso Assistant, ONLY the query content is sent to Anthropic (for example "generate a password management policy"). Anthropic processes data transiently. It does not store it after the request completes and does NOT use it for AI model training. Your database, files, configuration, and personal data are never sent to Anthropic. The contracting entity for a customer in the European Economic Area is Anthropic Ireland, Limited, established in Dublin, and prompts reach the provider servers in the United States. The transfer is made on the basis of standard contractual clauses.

OpenAI Ireland Ltd.

OpenAI is used exclusively to generate embedding vectors for semantic search across the knowledge base (RAG pipeline, text-embedding-3-small model). Only document fragments are sent to OpenAI for vectorisation. OpenAI returns numeric vectors and does not retain content after the request completes. Customer data is never used to train models. The contracting entity for a customer in the European Economic Area is OpenAI Ireland Ltd., and the transfer is made on the basis of standard contractual clauses.

Google Ireland Limited

Google processes data only for OAuth 2.0 authentication (email address, name, profile picture). We do not share additional user data with Google. For users in the European Economic Area the service is provided by Google Ireland Limited, established in Dublin, and the transfer to Google LLC in the United States is covered by the EU–US Data Privacy Framework.

Stripe Payments Europe, Limited

Payments are handled by the European entity Stripe Payments Europe, Limited, based in Ireland (EU). The group entity in the United States that receives the data is Stripe, LLC. Guardiso never sees or stores full payment card data. Card details flow directly from the user's browser to Stripe through their secure forms (Stripe Elements). Only subscription tokens and transaction metadata (amount, currency, status) reach Guardiso. Transfer is based on Stripe DPA and Standard Contractual Clauses.

Plus Five Five, Inc. (Resend service)

Resend handles transactional email: one-time sign-in links (magic link), organisation invitations, incident notifications and expiring-evidence reminders. The contracting entity is Plus Five Five, Inc. of the United States, trading as Resend. The eu-west-1 region we selected governs only where mail is sent from, not where it is stored. The provider stores it in the United States. Only email addresses and platform-generated message content reach the provider. The transfer is made on the basis of standard contractual clauses.

Cloudflare, Inc.

Cloudflare processes IP addresses and HTTP request metadata for DDoS protection and DNS resolution, using EU edge data centres (including Warsaw). The service is provided by Cloudflare, Inc. of the United States, and the transfer is covered by the EU–US Data Privacy Framework. Cloudflare does not have access to encrypted application content.

Superlative Enterprises Pty Ltd (Have I Been Pwned service)

On the customer instruction the platform checks whether email addresses in the customer domain have appeared in publicly known data breaches. Only the email address reaches the provider. Passwords are never transmitted or stored. The contracting entity is Superlative Enterprises Pty Ltd, a company registered in the state of Queensland, Australia, and personal data is stored in a Microsoft Azure data centre in the Western United States. The transfer is made on the basis of standard contractual clauses incorporated into that provider data processing agreement.

Fakturownia sp. z o.o.

Fakturownia issues invoices for the subscription. It receives the purchaser data needed for an invoice, that is the company name, address and tax identification number. The company is established in Warsaw and stores the data on servers within the European Economic Area. The data does not leave that area.

Contact

If you have questions about subprocessors or data processing:

See also: