Subprocessors List

November 14, 2025
Updated September 12, 2026
8 min read

1. Introduction

This document lists the third-party subprocessors engaged by Browser.lol (operated by Zesiger.net) to process personal data in connection with the Service. Browser.lol and Guard.ch are operated by the same entity and run on a shared platform (one account system, one API, one database), so several vendors below serve both services.

Each subprocessor is assessed before engagement and is contractually bound to protect personal data in accordance with applicable data protection laws, including the GDPR and the Swiss FADP.

Payment processing for the paid Browser.lol subscriptions is performed by Mollie B.V., listed in Section 3. Card and payment credentials are entered directly with Mollie and never reach our servers.

This list is updated whenever we engage new subprocessors or make changes to existing ones. Customers will be notified at least 30 days in advance of changes that affect how personal data is processed, stored or transferred.

2. Change Notification Process

2.1. How We Notify You

When we intend to add or replace a subprocessor in a way that affects how personal data is processed, stored or transferred, we will notify you at least 30 days before the change takes effect through one or more of:

  • Email notification to your registered account email address
  • A notice in your account dashboard
  • An update to this page together with the "Last Updated" date

Changes that do not affect how personal data is processed, stored or transferred (for example a vendor's corporate rename, an address update, or the removal of a vendor) may be reflected by updating this page only.

2.2. Your Right to Object

You may object to the addition or replacement of a subprocessor on reasonable grounds relating to data protection. To object:

  1. Email [email protected] within 30 days of our notification
  2. Describe your specific data protection concerns about the subprocessor
  3. We will discuss your concerns in good faith and seek a resolution
  4. If no resolution can be reached, you may terminate the affected Services without penalty

3. Payment Processing

Mollie B.V.

Service: Payment processing (card payments) for the paid subscriptions, including recurring charges and refunds

Data Processed: Name, email address, payment method details (entered directly with Mollie; card credentials never reach our servers), transaction amount, currency and timestamp, and the IP address and device data Mollie collects for fraud prevention

Purpose: Processing subscription payments, renewals and refunds, and payment-related fraud prevention. Mollie is the only payment processor engaged for Browser.lol.

Location: Amsterdam, Netherlands (EEA)

Data Transfer Mechanism: EEA processing (no third-country transfer); Mollie data processing agreement in place

Privacy Policy: https://www.mollie.com/privacy

4. Infrastructure and Hosting Providers

Hetzner Online GmbH

Service: Durable hosting: production database, object storage (including mail attachments and encrypted backups), account and billing records

Data Processed: All durable customer data: account data, session metadata, integrated mail messages, workspace metadata, billing artefacts

Purpose: Single primary storage region and primary infrastructure provider; there is no durable copy of customer data outside this region

Location: Helsinki, Finland (EEA). Entity seat: Gunzenhausen, Germany.

Data Transfer Mechanism: EEA processing (no third-country transfer); Hetzner data processing agreement in place

Privacy Policy: https://www.hetzner.com/legal/privacy-policy

OVHcloud (OVH Singapore PTE Ltd)

Service: APAC edge compute for browser workspaces (ephemeral containers only, no persistent data storage)

Data Processed: Temporary workspace compute and streaming traffic. All persistent data remains in Helsinki.

Purpose: Low-latency browser workspaces for users in the Asia-Pacific region

Location: Singapore. Singapore holds no EU or Swiss adequacy decision.

Data Transfer Mechanism: EU Standard Contractual Clauses (2021/914) and the Swiss FDPIC-recognised equivalent; encryption in transit (TLS, DTLS-SRTP)

Privacy Policy: https://www.ovhcloud.com/en/personal-data-protection/

FiberState, LLC

Service: North America edge compute for browser workspaces (ephemeral containers only, no persistent data storage)

Data Processed: Temporary workspace compute and streaming traffic. All persistent data remains in Helsinki.

Purpose: Low-latency browser workspaces for users in North America

Location: Salt Lake City, Utah, United States

Data Transfer Mechanism: FiberState is not certified under the EU-US Data Privacy Framework. EU Standard Contractual Clauses and the Swiss FDPIC-recognised equivalent; encryption in transit

OVHcloud (OVH Hebergement INC)

Service: North America edge compute for browser workspaces (ephemeral containers only, no persistent data storage)

Data Processed: Temporary workspace compute and streaming traffic. All persistent data remains in Helsinki.

Purpose: Low-latency browser workspaces for users in North America

Location: Beauharnois, Quebec, Canada

Data Transfer Mechanism: Canada holds an EU adequacy decision (PIPEDA) recognised by Switzerland; Standard Contractual Clauses and the Swiss equivalent are additionally in place

Privacy Policy: https://www.ovhcloud.com/en/personal-data-protection/

5. Content Delivery, Security and Mail Routing

Cloudflare, Inc.

Service: Authoritative DNS, delivery of the web frontend (including TLS termination on those routes), bot protection (Turnstile) on registration, sign-in and similar forms, and Email Routing for inbound messages to the integrated mail service

Data Processed: IP addresses, request metadata, security signals; for Email Routing: inbound email envelopes and content in transit to our infrastructure

Purpose: Website delivery and performance, bot and DDoS protection, inbound mail routing

Location: Entity seat: San Francisco, California, United States. Global anycast edge.

Data Transfer Mechanism: Certified under the EU-US Data Privacy Framework including the Swiss-US extension; EU Standard Contractual Clauses and the Swiss equivalent as fallback

Privacy Policy: https://www.cloudflare.com/privacypolicy/

6. Identity Providers

Google LLC (Sign in with Google)

Service: OAuth 2.0 identity assertion when you choose to sign in with Google

Data Processed: Verified email address, name, profile picture URL

Purpose: Optional single sign-on

Location: Mountain View, California, United States

Data Transfer Mechanism: Certified under the EU-US Data Privacy Framework including the Swiss-US extension; Standard Contractual Clauses as fallback

Privacy Policy: https://policies.google.com/privacy

Microsoft Corporation (Sign in with Microsoft)

Service: OAuth 2.0 / OpenID Connect against Microsoft Entra ID for organizations that enable single sign-on

Data Processed: Verified email address, display name, tenant identifier

Purpose: Optional enterprise single sign-on

Location: Redmond, Washington, United States

Data Transfer Mechanism: Certified under the EU-US Data Privacy Framework including the Swiss-US extension; Microsoft data protection terms with Standard Contractual Clauses as fallback

Privacy Policy: https://privacy.microsoft.com/en-us/privacystatement

7. Communication Services

Google Ireland Limited (Google Workspace, Gmail)

Service: Outbound transactional email (account verification, receipts, service notices), sent from [email protected] (the shared transactional mail address of the browser.lol and guard.ch platform) through the Google Workspace SMTP relay

Data Processed: Recipient email address, message subject and content of transactional emails

Purpose: Reliable delivery of transactional email

Location: Dublin, Ireland (EEA). Mail data may be processed by Google LLC in the United States.

Data Transfer Mechanism: Google Workspace Data Processing Amendment; for US processing by Google LLC: EU-US Data Privacy Framework including the Swiss-US extension, Standard Contractual Clauses as fallback

Privacy Policy: https://policies.google.com/privacy

8. AI and Machine Learning Services

OpenRouter, Inc.

Service: LLM API gateway used for the optional AI features of the integrated mail service (summaries, call-to-action detection); OpenRouter forwards requests to the configured inference provider (currently Google Gemini models) as a sub-subprocessor

Data Processed: Email message content submitted for summarization, without account credentials

Purpose: AI-powered mail features. This is the only channel through which user mail content reaches an AI provider.

Location: United States (OpenRouter). The location of the routed inference provider depends on the model configured at the time of the request.

Data Transfer Mechanism: OpenRouter is not certified under the EU-US Data Privacy Framework. EU Standard Contractual Clauses (2021/914) and the Swiss FDPIC-recognised equivalent are the applicable transfer mechanism

Privacy Policy: https://openrouter.ai/privacy

OpenAI OpCo, LLC

Service: Automated anomaly detection over aggregated server-side operational logs

Data Processed: Server-side log excerpts. The content of browser workspace sessions and user mail is never sent to this provider.

Purpose: Operational monitoring and alerting

Location: San Francisco, California, United States

Data Transfer Mechanism: OpenAI data processing agreement; certified under the EU-US Data Privacy Framework, Standard Contractual Clauses as fallback. API traffic is excluded from model training by contract.

Privacy Policy: https://openai.com/privacy/

9. Security and Verification Services

Reoon

Service: Email address verification at account registration

Data Processed: The email address provided during registration

Purpose: Detect invalid or disposable email addresses and prevent fraudulent registrations. Addresses are submitted for verification only and are not retained by the provider beyond verification.

Location: See the provider's privacy policy for its processing locations

Data Transfer Mechanism: EU Standard Contractual Clauses and the Swiss FDPIC-recognised equivalent where required

Privacy Policy: https://www.reoon.com/privacy-policy/

Google LLC (Web Risk)

Service: Hostname reputation lookups against known malware, social engineering and unwanted software infrastructure

Data Processed: Hostnames being checked. No account data is sent with these lookups.

Purpose: Detection of known-malicious infrastructure

Location: Mountain View, California, United States

Data Transfer Mechanism: Certified under the EU-US Data Privacy Framework including the Swiss-US extension; Standard Contractual Clauses as fallback

Privacy Policy: https://policies.google.com/privacy

IP Address Analysis (no external subprocessor)

IP geolocation, VPN/proxy detection and risk assessment are performed against locally hosted databases on our own infrastructure. No IP intelligence vendor receives your data at runtime for these checks.

10. Analytics and Advertising Services

Google LLC (Google Analytics 4)

Service: Website usage analytics (measurement ID G-VLXBKHVENH)

Data Processed: Cookie identifiers, device and browser information, pages visited, session and interaction data, truncated IP information as processed by Google Analytics 4

Purpose: Understand how the website is used and improve it

Location: United States (global operations)

Data Transfer Mechanism: Certified under the EU-US Data Privacy Framework including the Swiss-US extension; Standard Contractual Clauses as fallback

Note: Opt-out: Google Analytics Opt-out Browser Add-on

Privacy Policy: https://policies.google.com/privacy

Playwire LLC

Service: Advertising platform funding the free service

Data Processed: IP addresses, cookies, browser and device information, ad interaction data (views, clicks) on ad-supported pages

Purpose: Display, cap and measure advertisements. Browser.lol is free for everyone and funded by advertising, so ads are shown to all users.

Location: United States

Data Transfer Mechanism: Standard Contractual Clauses and the Swiss FDPIC-recognised equivalent

Privacy Policy: https://www.playwire.com/privacy-policy

11. Logging and Telemetry

Axiom, Inc.

Service: Server-side log aggregation and operational telemetry

Data Processed: Application log events, which can include IP addresses, user IDs, session IDs and workspace IDs

Purpose: Centralized operational logging, troubleshooting and monitoring

Location: United States

Data Transfer Mechanism: Axiom data processing terms; EU Standard Contractual Clauses and the Swiss FDPIC-recognised equivalent

Privacy Policy: https://axiom.co/privacy

12. Summary Table

SubprocessorCategoryLocationTransfer Mechanism
Mollie B.V.Payment processingAmsterdam, Netherlands (EEA)EEA-based
Hetzner Online GmbHDurable hostingHelsinki, Finland (EEA)EEA-based
OVHcloud (Singapore)Edge computeSingaporeSCCs + CH equivalent
FiberState, LLCEdge computeSalt Lake City, USASCCs + CH equivalent
OVHcloud (Canada)Edge computeBeauharnois, CanadaAdequacy + SCCs
Cloudflare, Inc.DNS / delivery / Turnstile / Email RoutingUnited States (global edge)DPF, SCCs fallback
Google LLC (Sign-in)IdentityUnited StatesDPF, SCCs fallback
Microsoft CorporationIdentity (SSO)United StatesDPF, SCCs fallback
Google Ireland Ltd (Workspace)Transactional emailDublin, Ireland (EEA) / USDPA; DPF for US processing
OpenRouter, Inc.AI (mail features)United StatesSCCs + CH equivalent
OpenAI OpCo, LLCAI (log analysis)United StatesDPF, SCCs fallback
ReoonEmail verificationSee providerSCCs where required
Google LLC (Web Risk)SecurityUnited StatesDPF, SCCs fallback
Google LLC (Analytics 4)AnalyticsUnited StatesDPF, SCCs fallback
Playwire LLCAdvertisingUnited StatesSCCs + CH equivalent
Axiom, Inc.LoggingUnited StatesSCCs + CH equivalent

SCCs = EU Standard Contractual Clauses (2021/914) | CH equivalent = Swiss FDPIC-recognised equivalent of the SCCs | DPF = EU-US Data Privacy Framework including the Swiss-US extension

13. Questions and Contact

For questions about our subprocessors or to exercise your right to object:

Data protection contact: [email protected]

Postal Address: Janis Zesiger, Mügeri 340, 5046 Schmiedrued, Switzerland

We have not appointed a data protection officer because none of the thresholds that would require one applies to our processing. For more information about data processing, see our Privacy Policy.

Last Updated: September 12, 2026