Subprocessors
This register shows which providers process personal data in connection with Guard.ch, what they do and where processing takes place. Subscribe to change notices
Introduction and scope
Guard.ch, operated by Zesiger.net, uses third-party providers to deliver the Service. This register lists their roles, the data categories involved, processing locations and transfer safeguards.
Guard.ch processes investigation content on the customer’s instructions. Providers that process this content, such as browser node operators and AI analysis services, are subprocessors under Article 28(2) and (4) GDPR. For account, billing, security and platform data, Guard.ch is the controller and the relevant providers process data on our behalf. We list both groups for transparency. Section 6.1 of the Privacy Policy explains the roles.
This page is the public register referenced by our Data Processing Agreement. Where this register and the Data Processing Agreement conflict on a material point, the Data Processing Agreement prevails for the contracting customer.
Change notification
We update this register at least thirty (30) days before adding or replacing a subprocessor that processes customer personal data, so that customers can review the change and object before it takes effect. Changes that do not affect how customer personal data is processed, stored or transferred (for example a vendor's corporate rename, an address update, or the removal of a vendor) are reflected on the next routine update without the notice period.
Customers and prospects can subscribe to written change notifications by sending the word "subscribe" to [email protected]. The mailing list is used only for subprocessor and legal-document notices; you can unsubscribe at any time by replying with "unsubscribe".
Infrastructure and hosting
Customer data retained between investigations, including the production database, account and billing records, workspace assets and backups, is held in one primary region at Hetzner in Helsinki (EEA). Investigation content exists only inside the container while an investigation runs. Browser nodes in Singapore, Salt Lake City and Beauharnois run these containers and stream the view to users. The browser’s working files live in the container’s writable layer during the investigation; the container and layer are removed afterwards.
The edge nodes are dedicated servers rented from the data-centre providers listed below for each location. Provider legal terms and transfer-impact details are available to customers on written request to [email protected].
Hetzner Online GmbH
- Role and purpose
Hosting and persistent storage: the production database, S3-compatible object storage for workspace assets (logos), account records and billing documents, and encrypted backups.
- Data categories
Stored customer personal data: account data, payment metadata, investigation records (URL, timestamps, status), logs and backups.
- Location
Helsinki, Finland (EEA). Registered office: Gunzenhausen, Germany.
- Data protection and transfers
Processing inside the EEA; the GDPR applies directly, and under Swiss data protection law the EEA is recognised as adequate, so no additional transfer mechanism is required. Hetzner data processing agreement in place.
OVHcloud (OVH Singapore PTE Ltd)
- Role and purpose
Hosts the edge node that runs isolated investigation containers and WebRTC streaming for investigations served from Asia Pacific.
- Data categories
Ephemeral investigation data inside the investigation container, for the duration of the investigation only. No customer data at rest between investigations.
- Location
Singapore. OVHcloud publishes Singapore as an Asia-Pacific dedicated-server region.
- Data protection and transfers
Singapore holds no EU or Swiss adequacy decision. OVHcloud data processing terms, EU Standard Contractual Clauses (processor-to-processor module) and the Swiss FDPIC-recognised equivalent, plus encryption in transit (TLS 1.3, DTLS-SRTP) for the analyst stream.
FiberState, LLC
- Role and purpose
Hosts the edge node that runs isolated investigation containers and WebRTC streaming for investigations served from North America.
- Data categories
Ephemeral investigation data inside the investigation container, for the duration of the investigation only. No customer data at rest between investigations.
- Location
Salt Lake City, Utah, United States. Entity address published by FiberState: 106 East 13200 South, Draper, UT 84020, United States.
- Data protection and transfers
FiberState is not certified under the EU-US Data Privacy Framework. EU Standard Contractual Clauses (processor-to-processor module) and the Swiss FDPIC-recognised equivalent, a transfer impact assessment on file, and encryption in transit.
OVHcloud (OVH Hebergement INC)
- Role and purpose
Hosts the edge node that runs isolated investigation containers and WebRTC streaming for investigations served from North America.
- Data categories
Ephemeral investigation data inside the investigation container, for the duration of the investigation only. No customer data at rest between investigations.
- Location
Beauharnois, Quebec, Canada. OVHcloud publishes Beauharnois as a North America dedicated-server region.
- Data protection and transfers
Canada's commercial sector (PIPEDA) is recognised as adequate by the European Commission (Decision 2002/2/EC) and by Switzerland. OVHcloud data processing terms, EU Standard Contractual Clauses and the Swiss equivalent are additionally in place.
Network, frontend delivery and bot protection
Cloudflare provides DNS for guard.ch and serves the guard.ch web frontend from its edge network. Backend API requests from the dashboard, and everything a running investigation shows, are served from our own origin infrastructure; Cloudflare's role is limited to DNS, delivery of the web frontend and Turnstile. Cloudflare Turnstile runs on the registration, sign-in, email-code verification, password reset and investigation launcher forms to mitigate automated abuse.
Cloudflare, Inc. (DNS and frontend delivery)
- Role and purpose
Authoritative DNS for guard.ch and delivery of the guard.ch web frontend (marketing site and dashboard application) from Cloudflare's edge, including TLS termination on those routes.
- Data categories
Visitor IP address, user agent and request metadata for requests to the guard.ch frontend. Backend API requests and investigation content are served from our own origin infrastructure in the hosting locations listed in this register; Cloudflare's role is limited to DNS, delivery of the web frontend and Turnstile.
- Location
Registered office: San Francisco, California, United States. Global anycast edge.
- Data protection and transfers
Certified under the EU-US Data Privacy Framework and the Swiss-US extension (see the official Data Privacy Framework participant list); EU Standard Contractual Clauses and the Swiss FDPIC-recognised equivalent under the Cloudflare data processing agreement operate as a fallback.
Cloudflare, Inc. (Turnstile)
- Role and purpose
Managed bot challenges on the registration, sign-in, email-code verification, password reset and investigation launcher (/start) forms.
- Data categories
IP address, user agent and interaction signals for the duration of the challenge, plus a per-request site token. No account content or investigation content.
- Location
Registered office: San Francisco, California, United States. Global anycast edge.
- Data protection and transfers
Certified under the EU-US Data Privacy Framework and the Swiss-US extension (see the official Data Privacy Framework participant list); EU Standard Contractual Clauses and the Swiss FDPIC-recognised equivalent operate as a fallback.
Identity and authentication
Guard.ch supports passkeys, email-and-password sign-in and federated sign-in with Google or Microsoft. Federated providers receive data only when the user actively chooses that sign-in method; users who sign in with a passkey or email and password cause no data to flow to the providers below. When acting as identity providers, Google and Microsoft also process the sign-in event under their own terms as independent controllers of their respective identity services; they are listed here for transparency.
Google LLC (Sign in with Google)
- Role and purpose
OAuth 2.0 identity assertion when a user chooses Sign in with Google. Google returns the user's verified email address, name and profile picture URL, which Guard.ch uses to provision or look up the account.
- Data categories
OAuth identifiers and the basic profile fields above. Data flows only when the user actively selects this sign-in method.
- Location
Mountain View, California, United States.
- Data protection and transfers
Certified under the EU-US Data Privacy Framework and the Swiss-US extension (see the official Data Privacy Framework participant list); EU Standard Contractual Clauses and the Swiss FDPIC-recognised equivalent operate as a fallback.
Microsoft Corporation (Sign in with Microsoft)
- Role and purpose
OAuth 2.0 / OpenID Connect identity assertion against Microsoft Entra ID when a user chooses Sign in with Microsoft. Microsoft returns the user's verified email address, display name and tenant identifier.
- Data categories
OAuth and SSO identifiers and the basic profile fields above. Data flows only when the user actively selects this sign-in method.
- Location
Redmond, Washington, United States.
- Data protection and transfers
Certified under the EU-US Data Privacy Framework and the Swiss-US extension (see the official Data Privacy Framework participant list); the Microsoft Products and Services Data Protection Addendum with EU Standard Contractual Clauses and the Swiss FDPIC-recognised equivalent operates as a fallback.
Payments
Stripe processes every payment for Guard.ch subscriptions. Guard.ch contracts with Stripe Payments Europe, Ltd.; processing may also involve Stripe, Inc. and other Stripe group entities under Stripe's data processing agreement. Guard.ch never receives or stores full card numbers: the payment method is tokenised at Stripe, and only the token, the card brand and the last four digits are stored in our billing records. For certain activities, such as fraud monitoring and its own regulatory compliance, Stripe acts as an independent controller as described in its own privacy documentation.
Stripe Payments Europe, Ltd.
- Role and purpose
Payment processing for Guard.ch subscriptions: checkout, subscription billing, invoices, refunds and dispute handling. Stripe Payments Europe, Ltd. is the Stripe entity Guard.ch contracts with.
- Data categories
Billing name and address, email address, payment method tokens and transaction records. Card numbers stay within Stripe's PCI DSS scope; Guard.ch never receives or stores the primary account number.
- Location
Dublin, Ireland (EEA).
- Data protection and transfers
Processing inside the EEA under the GDPR. Stripe data processing agreement in place.
Stripe, Inc.
- Role and purpose
Stripe group processing in the United States, including processing connected to customers billed outside the EEA, the United Kingdom and Switzerland, and Stripe's payment, risk and fraud-prevention infrastructure.
- Data categories
The same billing and transaction data categories as above, to the extent Stripe routes them to its US infrastructure.
- Location
South San Francisco, California, United States.
- Data protection and transfers
Certified under the EU-US Data Privacy Framework and the Swiss-US extension (see the official Data Privacy Framework participant list); EU Standard Contractual Clauses and the Swiss FDPIC-recognised equivalent under the Stripe data processing agreement operate as a fallback.
Communications
Outbound transactional email (account verification codes, one-time sign-in codes, contact-form confirmations and similar account and service notices) is sent from [email protected], the shared transactional mail address of the browser.lol and guard.ch platform, through the Google Workspace SMTP relay. Investigation capture content is never included in transactional email.
Google Ireland Limited (Google Workspace, Gmail)
- Role and purpose
Outbound transactional email: account verification codes, one-time sign-in codes, contact-form confirmations and similar account and service notices, sent from [email protected] (the shared transactional mail address of the browser.lol and guard.ch platform) through the Google Workspace SMTP relay. Payment receipts and invoices are sent by Stripe, not through this relay.
- Data categories
Recipient email address and the content of the transactional message.
- Location
Dublin, Ireland (EEA). Mail data may be processed by Google LLC in the United States.
- Data protection and transfers
Google Workspace Data Processing Amendment. For processing by Google LLC in the US: certification under the EU-US Data Privacy Framework and the Swiss-US extension (see the official Data Privacy Framework participant list), with EU Standard Contractual Clauses and the Swiss FDPIC-recognised equivalent as a fallback.
AI and lookups
Guard.ch uses selected third-party services for analysis: OpenRouter for model requests, Serper for web searches, and Google Web Risk and WhoisJSON for hostname and domain lookups. OpenRouter routes model requests to the selected provider; Guard.ch does not contract directly with those model vendors. OpenRouter receives investigation content sent to an AI feature. Serper receives search queries containing the investigated domain; Google Web Risk and WhoisJSON receive only a hostname or domain name. The entries below give the details.
OpenRouter, Inc. (LLM routing)
- Role and purpose
Large language model inference for every AI feature: the automated analysis of an investigation and its follow-up questions, and the anomaly detection over aggregated operational logs. OpenRouter is the only party we send model requests to. It forwards each request to the model vendor selected for that task, so those vendors act as sub-processors engaged by OpenRouter rather than parties Guard.ch contracts with directly.
The web search behind the analysis is the separately listed Serper lookup, not a search feature of the model provider.
OpenRouter maintains its own subprocessor list under its data processing agreement. The list is available through a trust portal that requires access, so it cannot be reproduced here. Its 30-day change notifications require a separate subscription and expressly exclude model providers.
- Data categories
For the investigation analysis, investigation-derived content submitted to the AI feature (for example extracted page text, signals from the investigation, and the prompts, follow-up questions and responses involved).
For the operational anomaly detection, aggregated log lines and pseudonymous identifiers only, never investigation content. Account credentials are not transmitted.
Prompt and response content is not retained by default. Both optional content-logging settings are disabled for our account. OpenRouter retains request metadata, such as token counts and latency, but excludes prompt and response content. Its contractual deadline for deletion on request is 30 business days, including backups.
- Location
United States (OpenRouter, Inc., 169 Madison Avenue, New York, NY 10016), and further countries outside the EEA and the United Kingdom in which the routed model vendors operate. OpenRouter's in-region EU routing is an enterprise-tier option that Guard.ch does not use, so this processing is not EU-based.
- Data protection and transfers
OpenRouter's published data processing agreement (last updated 5 May 2026), which is incorporated automatically by use of the service.
OpenRouter is not certified under the EU-US Data Privacy Framework, checked against the official Data Privacy Framework participant list, so transfers rest on the Standard Contractual Clauses alone: Module 2 (controller to processor, Decision 2021/914) under section 13 of that agreement, the UK International Data Transfer Addendum for UK transfers, and for Switzerland the same clauses with the FDPIC as the competent supervisory authority.
OpenRouter states that it does not use inputs or outputs for model training. It holds a SOC 2 Type 2 report, available under its own access process.
AI model providers accessed through OpenRouter (currently OpenAI and Google)
- Role and purpose
These providers process the model requests forwarded by OpenRouter. Guard.ch selects a model per task by configuration and can change that selection without a change to the Service. OpenRouter contracts with the model providers; Guard.ch has no direct contract with them. Listed here so it is transparent where AI processing ultimately happens, not because Guard.ch transmits data to these vendors directly.
- Data categories
The same content OpenRouter receives for the task in question, as described in the entry above: investigation-derived content for the analysis features, aggregated operational log lines for the anomaly detection.
- Location
Determined by OpenRouter's routing rather than by Guard.ch. OpenRouter's in-region EU routing is an enterprise-tier option Guard.ch does not use, so this processing takes place outside the EEA and the United Kingdom.
- Data protection and transfers
Transfers rely on the Standard Contractual Clauses in OpenRouter's data processing agreement. Guard.ch has no direct agreement with these vendors. These transfers do not rely on the vendors' own certifications, which differ: Google LLC is certified under the EU-US Data Privacy Framework and its Swiss-US extension, while OpenAI is not listed in the Data Privacy Framework. Whether a routed request may be used for model training depends on the vendor, and OpenRouter's own default is permissive; Guard.ch sets the training opt-out at account level and sends no per-request provider policy.
Serper (web search)
- Role and purpose
The web search behind the AI analysis. When the model needs to cross-reference the investigated host against the open web, Guard.ch sends the query to Serper, which runs it as a search and returns the result list. The model never reaches a search engine itself, and the browser used for an investigation never contacts a search provider.
- Data categories
The search queries the model formulates, plus a country and language hint for the result set. By design a query is a short keyword query containing the investigated domain or hostname; its exact wording is generated by the model. Page content, capture content and account data are not sent.
- Location
Governed by the laws of the United Kingdom. The provider does not publicly state a processing location.
- Data protection and transfers
The provider's privacy policy states that transfers out of the EEA rest on an adequacy decision or the Standard Contractual Clauses, with a copy available on request.
Google LLC (Web Risk)
- Role and purpose
Hostname reputation lookup: the hostnames resolved during an investigation are checked against Google's Web Risk threat lists as one signal feeding the automated verdict.
- Data categories
The hostnames checked during an investigation. No URL paths or query strings, no account data and no other investigation content.
- Location
Mountain View, California, United States.
- Data protection and transfers
Certified under the EU-US Data Privacy Framework and the Swiss-US extension (see the official Data Privacy Framework participant list); EU Standard Contractual Clauses and the Swiss FDPIC-recognised equivalent operate as a fallback.
WhoisJSON (whois lookup)
- Role and purpose
Commercial WHOIS API used as a fallback for the domain registration record: when the free RDAP and registry sources return nothing usable for the registrable domain of the investigated URL, the same domain name is queried here instead.
- Data categories
The registrable domain name of the investigated URL only. No URL paths or query strings, no account data and no investigation content. The provider states that it caches responses for three hours by default.
- Location
Governed by French law, with exclusive jurisdiction of the courts of Paris. The provider does not publicly state a processing location.
- Data protection and transfers
Not publicly stated by the provider.
Reference data sources (not subprocessors)
The enrichment shown in an investigation (IP geolocation, ASN data, network metadata, threat and tracker classifications, domain popularity) is produced from reference datasets that we license or obtain from public sources, download on a schedule, and query inside our own database. These providers supply data to us; they do not receive or process customer personal data and are therefore not subprocessors. They currently include MaxMind (GeoLite2 City and ASN), PeeringDB (via CAIDA snapshots), abuse.ch (Feodo Tracker, ThreatFox, URLhaus) and the Tranco list.
External domain and DNS lookups
The following lookups send a domain name or hostname outside our infrastructure during an investigation. Google Web Risk and WhoisJSON are already listed above; this explains how the lookups work:
- Public WHOIS and RDAP directories receive the investigated domain name. The query goes to the relevant registry or registrar and, where needed, a public RDAP redirector.
- If public directories return no usable result, we send the same domain name to the commercial WHOIS API listed above.
- Public DNS resolvers receive the investigated hostname. We compare answers from filtering and unfiltered resolvers; each operator handles the query under its own public terms.
International transfers
Guard.ch is operated from Switzerland. Switzerland is recognised as adequate by the European Commission and under the UK adequacy regulations, so personal data can move between the EEA, the UK and our Swiss establishment without additional transfer safeguards. Stored customer data stays in the EEA (Hetzner, Helsinki); only the ephemeral edge processing and the specific vendor services listed above involve processing outside the EEA and Switzerland.
For US vendors that are certified under the EU-US Data Privacy Framework and the Swiss-US extension, as identified per vendor in this register against the official Data Privacy Framework participant list, that certification is the primary transfer mechanism and the EU Standard Contractual Clauses operate as a fallback. For all other transfers outside the EEA, Switzerland and the UK, the EU Standard Contractual Clauses (2021/914) and the Swiss FDPIC-recognised equivalent are the baseline mechanism, supplemented by the European Commission's adequacy decision for the Canadian commercial sector (PIPEDA) for the Beauharnois edge location. Where the UK GDPR applies to an onward transfer, the UK International Data Transfer Addendum to the EU Standard Contractual Clauses is used where required. As a Swiss entity, Guard.ch is not eligible for Data Privacy Framework certification.
We maintain transfer impact assessments for the non-EEA destinations and make a copy (redacted where necessary) available to customers on written request to [email protected]. Section 9 of the Privacy Policy explains our international data transfers.
Customer objections
Customers may object to the engagement of a new or replacement subprocessor on reasonable data protection grounds (for example a documented incompatibility with the customer's own regulatory regime). Objections must be sent in writing to [email protected] within fourteen (14) days of the change notification, and in any event before the announced change takes effect.
On receipt we will work with the customer in good faith to find a workable alternative. If no alternative can reasonably be agreed before the change takes effect, the customer may terminate the affected portion of the service without penalty and receive a pro-rata refund of prepaid fees for the unused term, consistent with the Terms of Service and the Data Processing Agreement.
Contact
Send questions about this register, requests for contractual documents, notification subscriptions and objections to [email protected]. Zesiger.net’s postal address is in the Legal notice.