Sub-processors
Every provider,out in the open.
A sub-processor is a service provider that processes customer or monitoring data on behalf of fastmon (Art. 28 GDPR). This page lists both: every sub-processor in the customer data path and, because transparency should not stop at the data path, the internal business tools that never see customer or monitoring data.
Last updated: 17 July 2026
The customer data path
Every system that processes customer or monitoring data. A small number of carefully chosen sub-processors: every one a company in Germany or the EU, each bound by a data processing agreement. No provider in the customer data path is a US company; access under the US CLOUD Act is therefore not something to expect.
Hosting and infrastructure
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting, storage, backup | Germany, Falkenstein |
| ScaleCommerce GmbH | Hosting | Germany, Berlin |
| smoxy GmbH | Ingress | Germany, Berlin |
| BunnyWay d.o.o. | Authoritative DNS service | Slovenia, Tržič |
Billing, accounting and payments
| Provider | Purpose | Location |
|---|---|---|
| sevdesk GmbH | Accounting and invoicing | Germany, Offenburg |
| Mollie B.V. | Payment processing for online payments in Europe; regulated payment service provider (PSD2) acting as an independent controller, therefore not a sub-processor | Netherlands, Amsterdam |
| Provider | Purpose | Location |
|---|---|---|
| Lettermint B.V. | Transactional emails | Netherlands, Zwolle |
| Soverin B.V. | Business mail | Netherlands, Rotterdam |
Engineering operations
| Provider | Purpose | Location |
|---|---|---|
| All Quiet GmbH | On-call tool for fastmon Engineering | Germany, Berlin |
AI (only if you opt in)
| Provider | Purpose | Location |
|---|---|---|
| Mistral AI SAS | LLM inference, only when the AI chat function is opted in | France, Paris |
Five of the nine sub-processors are in Germany, the rest in the EU (Netherlands, Slovenia, France). Card payments run through Mollie B.V. (Amsterdam), which acts as a regulated payment service provider on its own account and is therefore not a sub-processor.
Internal business tools
We also use the following providers to run our internal business. No customer and no monitoring data is ever sent to them, they process none, and that is why they are not sub-processors under Art. 28 GDPR. We list them anyway, because transparency should not stop at the data path.
| Provider | Purpose | Customer data | Location |
|---|---|---|---|
| GitHub, Inc.Version control | Source code hosting, version control and CI/CD pipelines | None sent | USA |
| Linear Orbit, Inc.Project management | Project and ticket tracking, exclusively for product development | None sent | USA |
| Anthropic, PBCDevelopment | AI-assisted development: coding and code reviews with Claude Code | None sent | USA |
| Wire Swiss GmbHCommunication | Internal team communication and collaboration | None sent | Switzerland, Zug |
Our internal policy is simple: no customer or monitoring data in repositories, tickets, chats or development tools. The entire customer data path stays in Germany and the EU.
International data transfers
For the customer data path there are no third-country transfers: all customer and monitoring data is processed exclusively in Germany and the EU, and every sub-processor is based in the EU. For your data we therefore rely on neither standard contractual clauses nor adequacy decisions; access under the US CLOUD Act is not something to expect.
Among the internal business tools, three providers are based in the USA and one in Switzerland. They process no customer or monitoring data; only internal data arises there, such as accounts of our own staff. For this internal data, the EU standard contractual clauses from the providers' data processing agreements apply (Art. 46 GDPR), GitHub is additionally certified under the EU-US Data Privacy Framework, and Switzerland is covered by an adequacy decision of the EU Commission (Art. 45 GDPR).
Changes to this list
Before we engage a new sub-processor or replace an existing one, we announce it at least 30 days in advance in text form and update this page.
Objecting to sub-processors
As a customer, you can object to an announced new sub-processor within 30 days for important data protection reasons (§ 7 DPA). If the objection is justified, we will not use the new provider for your data until a mutually agreeable solution is found; if none is reached within 30 days, you have an extraordinary right to terminate the main agreement.
The binding version of the sub-processor list is part of the Data Processing Agreement.
Questions about the data path? Write to privacy@fastmon.eu.