Sub-processors
Evidence status updated: 12 July 2026
Vakteye uses service providers for scanning, hosting, authentication, storage, task orchestration, email, error monitoring, abuse prevention, DNS and bot protection. The functional inventory below describes intended use; it is not a residency or transfer-mechanism guarantee.
Controllers can request the current named entities, contracting countries, purposes and change history from legal@vakteye.com. An NDA is not required to receive information needed to assess an Article 28 appointment.
Before production processing, the controller-specific schedule must be reconciled to current account configuration and dated vendor evidence, including the DPA, sub-processors, processing and support locations, retention and any Article 45 or 46 transfer mechanism. Unverified entries remain a release blocker.
Functions and regions
| Function | Region | Role |
|---|---|---|
| Primary database, authentication, file storage | EU | Processor |
| Frontend hosting and edge delivery | EU (regional edge nodes) | Processor |
| Background scanner workers | EU (regional infrastructure) | Processor |
| Background scanning task orchestration | EU | Processor |
| Transactional email delivery | EU (regional infrastructure) | Processor |
| Domain resolution and bot-challenge tokens | Global anycast network | Processor |
| Server-side error and exception monitoring | EU | Processor |
| Rate-limit and abuse-protection cache | EU | Processor |
| Anonymous website usage analytics, self-hosted in the EU | EU | Processor (self-hosted — no third-party data transfer) |
Request the named list
Customers and prospective controllers can request the named sub-processor schedule and supporting evidence by writing to legal@vakteye.com.