Subprocessors List
1. Introduction
This document lists the third-party subprocessors engaged by Browser.lol (operated by Zesiger.net) to process personal data in connection with the Service. Browser.lol and Guard.ch are operated by the same entity and run on a shared platform (one account system, one API, one database), so several vendors below serve both services.
Each subprocessor is assessed before engagement and is contractually bound to protect personal data in accordance with applicable data protection laws, including the GDPR and the Swiss FADP.
Payment processing for the paid Browser.lol subscriptions is performed by Mollie B.V., listed in Section 3. Payment credentials are entered directly with Mollie and do not pass through our servers.
This list is updated whenever we engage new subprocessors or make changes to existing ones. Customers will be notified at least 30 days in advance of changes that affect how personal data is processed, stored or transferred.
2. Change Notification Process
2.1. How We Notify You
When we intend to add or replace a subprocessor in a way that affects how personal data is processed, stored or transferred, we will notify you at least 30 days before the change takes effect through one or more of:
- Email notification to your registered account email address
- A notice in your account dashboard
- An update to this page together with the "Last Updated" date
Changes that do not affect how personal data is processed, stored or transferred (for example a vendor's corporate rename, an address update, or the removal of a vendor) may be reflected by updating this page only.
2.2. Your Right to Object
You may object to the addition or replacement of a subprocessor on reasonable grounds relating to data protection. To object:
- Email [email protected] within 30 days of our notification
- Describe your specific data protection concerns about the subprocessor
- We will discuss your concerns in good faith and seek a resolution
- If no resolution can be reached, you may terminate the affected Services without penalty
3. Payment Processing
Mollie B.V.
Service: Processing payments for Browser.lol subscriptions, including recurring charges and refunds
Data Processed: Name, email address, payment method details (entered directly with Mollie; payment credentials do not pass through our servers), transaction amount, currency and timestamp, and the IP address and device data Mollie collects for fraud prevention
Purpose: Processing subscription payments, renewals and refunds, and payment-related fraud prevention. Mollie is the only payment processor engaged for Browser.lol.
Location: Amsterdam, Netherlands (EEA)
Data Transfer Mechanism: EEA processing (no third-country transfer); Mollie data processing agreement in place
Privacy Policy: https://www.mollie.com/privacy
4. Infrastructure and Hosting Providers
Hetzner Online GmbH
Service: Hosting the primary production database, encrypted database backups, workspace logos and integrated-mail attachments
Data Processed: Account and billing records, session and team Workspace metadata, integrated-mail messages and attachments, workspace logos and database backups
Purpose: Primary database and related object storage. Saved browser profiles use the separate IDrive e2 service listed below
Location: Helsinki, Finland (EEA), for the primary database, backups and workspace logos; Nuremberg, Germany (EEA), for integrated-mail attachments. Entity seat: Gunzenhausen, Germany.
Data Transfer Mechanism: EEA processing (no third-country transfer); Hetzner data processing agreement in place
Privacy Policy: https://www.hetzner.com/legal/privacy-policy
IDrive Inc. (IDrive e2)
Service: IDrive e2 object storage for saved browser profiles
Data Processed: Browser profile data saved between sessions, including logins, cookies, history, settings and site storage
Purpose: Store saved profiles so eligible users can resume them in later sessions. A working copy can remain on the browser node where the profile was last used so that the next session starts faster.
Location: Frankfurt, Germany (EEA). Entity seat: Calabasas, California, United States.
Data Transfer Mechanism: Storage in the EEA; IDrive Inc. is certified under the EU-US Data Privacy Framework including the Swiss-US extension; EU Standard Contractual Clauses and the Swiss equivalent under the IDrive data processing addendum as fallback
Privacy Policy: https://www.idrive.com/privacy-policy
OVHcloud (OVH SAS)
Service: EU compute for sessions and working copies of saved browser profiles
Data Processed: Temporary session compute and streaming traffic; working copies of saved browser profiles (logins, cookies, history, settings and site storage) last used on this node
Purpose: Isolated sessions in the EU and faster starts of saved profiles
Location: Gravelines, France (EEA). Entity seat: Roubaix, France.
Data Transfer Mechanism: EEA processing (no third-country transfer); OVHcloud data processing terms apply
Privacy Policy: https://www.ovhcloud.com/en/personal-data-protection/
OVHcloud (OVH Singapore PTE Ltd)
Service: APAC edge compute for sessions (ephemeral containers; the node where a saved browser profile was last used can keep a working copy of it)
Data Processed: Temporary session compute and streaming traffic, and working copies of saved browser profiles last used on this node. Durable account and mail data, and the saved profiles themselves, are stored separately as described above.
Purpose: Low-latency sessions for users in the Asia-Pacific region
Location: Singapore. Singapore holds no EU or Swiss adequacy decision.
Data Transfer Mechanism: EU Standard Contractual Clauses (2021/914) and the Swiss FDPIC-recognised equivalent; encryption in transit (TLS, DTLS-SRTP)
Privacy Policy: https://www.ovhcloud.com/en/personal-data-protection/
FiberState, LLC
Service: North America edge compute for sessions (ephemeral containers; the node where a saved browser profile was last used can keep a working copy of it)
Data Processed: Temporary session compute and streaming traffic, and working copies of saved browser profiles last used on this node. Durable account and mail data, and the saved profiles themselves, are stored separately as described above.
Purpose: Low-latency sessions for users in North America
Location: Salt Lake City, Utah, United States
Data Transfer Mechanism: FiberState is not certified under the EU-US Data Privacy Framework. EU Standard Contractual Clauses and the Swiss FDPIC-recognised equivalent; encryption in transit
OVHcloud (OVH Hebergement INC)
Service: North America edge compute for sessions (ephemeral containers; the node where a saved browser profile was last used can keep a working copy of it)
Data Processed: Temporary session compute and streaming traffic, and working copies of saved browser profiles last used on this node. Durable account and mail data, and the saved profiles themselves, are stored separately as described above.
Purpose: Low-latency sessions for users in North America
Location: Beauharnois, Quebec, Canada
Data Transfer Mechanism: Canada holds an EU adequacy decision (PIPEDA) recognised by Switzerland; Standard Contractual Clauses and the Swiss equivalent are additionally in place
Privacy Policy: https://www.ovhcloud.com/en/personal-data-protection/
5. Content Delivery, Security and Mail Routing
Cloudflare, Inc.
Service: Authoritative DNS for the website domains, delivery of the web frontend (including TLS termination on those routes), bot protection (Turnstile) on registration, sign-in and similar forms, and Email Routing for inbound messages to the integrated mail service
Data Processed: IP addresses, request metadata, security signals; for Email Routing: inbound email envelopes and content in transit to our infrastructure
Purpose: Website delivery and performance, bot and DDoS protection, inbound mail routing
Location: Entity seat: San Francisco, California, United States. Global anycast edge.
Data Transfer Mechanism: Certified under the EU-US Data Privacy Framework including the Swiss-US extension; EU Standard Contractual Clauses and the Swiss equivalent as fallback
Privacy Policy: https://www.cloudflare.com/privacypolicy/
BunnyWay d.o.o. (bunny.net)
Service: Bunny DNS, the authoritative DNS for our API hostnames, with geo routing and health checks that remove unavailable servers from DNS answers
Data Processed: The IP address of the DNS resolver making the lookup and, where the resolver sends it, a shortened part of the user's IP address (EDNS Client Subnet), the hostname queried and the time of the query. Bunny DNS does not see API requests, session content or account data.
Purpose: Route each user to a nearby, available browser server
Location: Ljubljana, Slovenia (EEA). Global anycast DNS network.
Data Transfer Mechanism: EEA processing; the GDPR applies directly and the EEA is recognised as adequate under Swiss law, so no additional transfer mechanism is required; bunny.net data processing agreement in place
Privacy Policy: https://bunny.net/privacy/
6. Identity Providers
Google LLC (Sign in with Google)
Service: OAuth 2.0 identity assertion when you choose to sign in with Google
Data Processed: Verified email address, name, profile picture URL
Purpose: Optional single sign-on
Location: Mountain View, California, United States
Data Transfer Mechanism: Certified under the EU-US Data Privacy Framework including the Swiss-US extension; Standard Contractual Clauses as fallback
Privacy Policy: https://policies.google.com/privacy
Microsoft Corporation (Sign in with Microsoft)
Service: OAuth 2.0 / OpenID Connect against Microsoft Entra ID for organizations that enable single sign-on
Data Processed: Verified email address, display name, tenant identifier
Purpose: Optional enterprise single sign-on
Location: Redmond, Washington, United States
Data Transfer Mechanism: Certified under the EU-US Data Privacy Framework including the Swiss-US extension; Microsoft data protection terms with Standard Contractual Clauses as fallback
Privacy Policy: https://privacy.microsoft.com/en-us/privacystatement
7. Communication Services
Google Ireland Limited (Google Workspace, Gmail)
Service: Outbound transactional email (account verification, receipts, service notices), sent from [email protected] (the shared transactional mail address of the Browser.lol and Guard.ch platform) through the Google Workspace SMTP relay
Data Processed: Recipient email address, message subject and content of transactional emails
Purpose: Reliable delivery of transactional email
Location: Dublin, Ireland (EEA). Mail data may be processed by Google LLC in the United States.
Data Transfer Mechanism: Google Workspace Data Processing Amendment; for US processing by Google LLC: EU-US Data Privacy Framework including the Swiss-US extension, Standard Contractual Clauses as fallback
Privacy Policy: https://policies.google.com/privacy
8. AI and Machine Learning Services
OpenRouter, Inc.
Service: LLM API gateway for optional integrated-mail features and Guard.ch live analysis; OpenRouter forwards requests to the configured inference provider (for example, Google Gemini for mail summaries)
Data Processed: Mail content submitted for optional summaries or call-to-action detection; page-derived content submitted for optional Guard.ch live analysis
Purpose: Optional AI processing. For the integrated Browser.lol mail feature, OpenRouter is the channel through which message content reaches an AI provider; Guard.ch optional live analysis processes viewed page content separately.
Location: United States (OpenRouter). The location of the routed inference provider depends on the model configured at the time of the request.
Data Transfer Mechanism: OpenRouter is not certified under the EU-US Data Privacy Framework. EU Standard Contractual Clauses (2021/914) and the Swiss FDPIC-recognised equivalent are the applicable transfer mechanism
Privacy Policy: https://openrouter.ai/privacy
OpenAI OpCo, LLC
Service: Inference provider, reached through OpenRouter, for automated anomaly detection over aggregated server-side operational logs
Data Processed: Server-side log excerpts for this operational process. Session and mail content is not submitted for log-anomaly analysis; optional Guard.ch live analysis has a separate processing flow.
Purpose: Operational monitoring and alerting
Location: San Francisco, California, United States
Data Transfer Mechanism: OpenAI data processing agreement; certified under the EU-US Data Privacy Framework, Standard Contractual Clauses as fallback. API traffic is excluded from model training by contract.
Privacy Policy: https://openai.com/privacy/
9. Security and Verification Services
Reoon
Service: Email address verification at account registration
Data Processed: The email address provided during registration
Purpose: Detect invalid or disposable email addresses and prevent fraudulent registrations. Addresses are submitted for verification only and are not retained by the provider beyond verification.
Location: See the provider's privacy policy for its processing locations
Data Transfer Mechanism: EU Standard Contractual Clauses and the Swiss FDPIC-recognised equivalent where required
Privacy Policy: https://www.reoon.com/privacy-policy/
Google LLC (Web Risk)
Service: Hostname reputation lookups against known malware, social engineering and unwanted software infrastructure
Data Processed: Hostnames being checked. No account data is sent with these lookups.
Purpose: Detection of known-malicious infrastructure
Location: Mountain View, California, United States
Data Transfer Mechanism: Certified under the EU-US Data Privacy Framework including the Swiss-US extension; Standard Contractual Clauses as fallback
Privacy Policy: https://policies.google.com/privacy
IP Address Analysis (no external subprocessor)
IP geolocation, VPN/proxy detection and risk assessment are performed against locally hosted databases on our own infrastructure. No IP intelligence vendor receives your data at runtime for these checks.
10. Analytics and Advertising Services
Google LLC (Google Analytics 4)
Service: Website usage analytics (measurement ID G-VLXBKHVENH)
Data Processed: Cookie identifiers, device and browser information, pages visited, session and interaction data, truncated IP information as processed by Google Analytics 4
Purpose: Understand how the website is used and improve it
Location: United States (global operations)
Data Transfer Mechanism: Certified under the EU-US Data Privacy Framework including the Swiss-US extension; Standard Contractual Clauses as fallback
Note: Opt-out: Google Analytics Opt-out Browser Add-on
Privacy Policy: https://policies.google.com/privacy
Playwire LLC
Service: Advertising platform funding the free service
Data Processed: IP addresses, cookies, browser and device information, ad interaction data (views, clicks) on ad-supported pages
Purpose: Display, cap and measure advertisements. Advertising supports free access to Browser.lol; accounts with paid ad-free entitlements do not receive these ads.
Location: United States
Data Transfer Mechanism: Standard Contractual Clauses and the Swiss FDPIC-recognised equivalent
Privacy Policy: https://www.playwire.com/privacy-policy
11. Logging and Telemetry
Axiom, Inc.
Service: Server-side log aggregation and operational telemetry
Data Processed: Application log events, which can include IP addresses, user IDs, session IDs and workspace IDs
Purpose: Centralized operational logging, troubleshooting and monitoring
Location: United States
Data Transfer Mechanism: Axiom data processing terms; EU Standard Contractual Clauses and the Swiss FDPIC-recognised equivalent
Privacy Policy: https://axiom.co/privacy
12. Summary Table
| Subprocessor | Category | Location | Transfer Mechanism |
|---|---|---|---|
| Mollie B.V. | Payment processing | Amsterdam, Netherlands (EEA) | EEA-based |
| Hetzner Online GmbH | Primary database, backups, mail attachments | Helsinki, Finland; Nuremberg, Germany (EEA) | EEA-based |
| IDrive Inc. (IDrive e2) | Saved-profile storage | Frankfurt, Germany (EEA) | EEA storage; DPF, SCCs fallback |
| OVHcloud (France) | Edge compute, saved-profile working copies | Gravelines, France (EEA) | EEA-based |
| OVHcloud (Singapore) | Edge compute | Singapore | SCCs + CH equivalent |
| FiberState, LLC | Edge compute | Salt Lake City, USA | SCCs + CH equivalent |
| OVHcloud (Canada) | Edge compute | Beauharnois, Canada | Adequacy + SCCs |
| Cloudflare, Inc. | DNS / delivery / Turnstile / Email Routing | United States (global edge) | DPF, SCCs fallback |
| BunnyWay d.o.o. (bunny.net) | DNS for API hostnames (geo routing) | Slovenia (EEA) | EEA-based |
| Google LLC (Sign-in) | Identity | United States | DPF, SCCs fallback |
| Microsoft Corporation | Identity (SSO) | United States | DPF, SCCs fallback |
| Google Ireland Ltd (Workspace) | Transactional email | Dublin, Ireland (EEA) / US | DPA; DPF for US processing |
| OpenRouter, Inc. | AI (mail and optional live analysis) | United States | SCCs + CH equivalent |
| OpenAI OpCo, LLC | AI (log analysis) | United States | DPF, SCCs fallback |
| Reoon | Email verification | See provider | SCCs where required |
| Google LLC (Web Risk) | Security | United States | DPF, SCCs fallback |
| Google LLC (Analytics 4) | Analytics | United States | DPF, SCCs fallback |
| Playwire LLC | Advertising | United States | SCCs + CH equivalent |
| Axiom, Inc. | Logging | United States | SCCs + CH equivalent |
SCCs = EU Standard Contractual Clauses (2021/914) | CH equivalent = Swiss FDPIC-recognised equivalent of the SCCs | DPF = EU-US Data Privacy Framework including the Swiss-US extension
13. Questions and Contact
For questions about our subprocessors or to exercise your right to object:
Data protection contact: [email protected]
Postal Address: Janis Zesiger, Mügeri 340, 5046 Schmiedrued, Switzerland
We have not appointed a data protection officer because none of the thresholds that would require one applies to our processing. For more information about data processing, see our Privacy Policy.
Last Updated: September 30, 2026