Subprocessors List

November 14, 2025Updated September 30, 20268 min read

1. Introduction

This document lists the third-party subprocessors engaged by Browser.lol (operated by Zesiger.net) to process personal data in connection with the Service. Browser.lol and Guard.ch are operated by the same entity and run on a shared platform (one account system, one API, one database), so several vendors below serve both services.

Each subprocessor is assessed before engagement and is contractually bound to protect personal data in accordance with applicable data protection laws, including the GDPR and the Swiss FADP.

Payment processing for the paid Browser.lol subscriptions is performed by Mollie B.V., listed in Section 3. Payment credentials are entered directly with Mollie and do not pass through our servers.

This list is updated whenever we engage new subprocessors or make changes to existing ones. Customers will be notified at least 30 days in advance of changes that affect how personal data is processed, stored or transferred.

2. Change Notification Process

2.1. How We Notify You

When we intend to add or replace a subprocessor in a way that affects how personal data is processed, stored or transferred, we will notify you at least 30 days before the change takes effect through one or more of:

  • Email notification to your registered account email address
  • A notice in your account dashboard
  • An update to this page together with the "Last Updated" date

Changes that do not affect how personal data is processed, stored or transferred (for example a vendor's corporate rename, an address update, or the removal of a vendor) may be reflected by updating this page only.

2.2. Your Right to Object

You may object to the addition or replacement of a subprocessor on reasonable grounds relating to data protection. To object:

  1. Email [email protected] within 30 days of our notification
  2. Describe your specific data protection concerns about the subprocessor
  3. We will discuss your concerns in good faith and seek a resolution
  4. If no resolution can be reached, you may terminate the affected Services without penalty

3. Payment Processing

Mollie B.V.

Service: Processing payments for Browser.lol subscriptions, including recurring charges and refunds

Data Processed: Name, email address, payment method details (entered directly with Mollie; payment credentials do not pass through our servers), transaction amount, currency and timestamp, and the IP address and device data Mollie collects for fraud prevention

Purpose: Processing subscription payments, renewals and refunds, and payment-related fraud prevention. Mollie is the only payment processor engaged for Browser.lol.

Location: Amsterdam, Netherlands (EEA)

Data Transfer Mechanism: EEA processing (no third-country transfer); Mollie data processing agreement in place

Privacy Policy: https://www.mollie.com/privacy

4. Infrastructure and Hosting Providers

Hetzner Online GmbH

Service: Hosting the primary production database, encrypted database backups, workspace logos and integrated-mail attachments

Data Processed: Account and billing records, session and team Workspace metadata, integrated-mail messages and attachments, workspace logos and database backups

Purpose: Primary database and related object storage. Saved browser profiles use the separate IDrive e2 service listed below

Location: Helsinki, Finland (EEA), for the primary database, backups and workspace logos; Nuremberg, Germany (EEA), for integrated-mail attachments. Entity seat: Gunzenhausen, Germany.

Data Transfer Mechanism: EEA processing (no third-country transfer); Hetzner data processing agreement in place

Privacy Policy: https://www.hetzner.com/legal/privacy-policy

IDrive Inc. (IDrive e2)

Service: IDrive e2 object storage for saved browser profiles

Data Processed: Browser profile data saved between sessions, including logins, cookies, history, settings and site storage

Purpose: Store saved profiles so eligible users can resume them in later sessions. A working copy can remain on the browser node where the profile was last used so that the next session starts faster.

Location: Frankfurt, Germany (EEA). Entity seat: Calabasas, California, United States.

Data Transfer Mechanism: Storage in the EEA; IDrive Inc. is certified under the EU-US Data Privacy Framework including the Swiss-US extension; EU Standard Contractual Clauses and the Swiss equivalent under the IDrive data processing addendum as fallback

Privacy Policy: https://www.idrive.com/privacy-policy

OVHcloud (OVH SAS)

Service: EU compute for sessions and working copies of saved browser profiles

Data Processed: Temporary session compute and streaming traffic; working copies of saved browser profiles (logins, cookies, history, settings and site storage) last used on this node

Purpose: Isolated sessions in the EU and faster starts of saved profiles

Location: Gravelines, France (EEA). Entity seat: Roubaix, France.

Data Transfer Mechanism: EEA processing (no third-country transfer); OVHcloud data processing terms apply

Privacy Policy: https://www.ovhcloud.com/en/personal-data-protection/

OVHcloud (OVH Singapore PTE Ltd)

Service: APAC edge compute for sessions (ephemeral containers; the node where a saved browser profile was last used can keep a working copy of it)

Data Processed: Temporary session compute and streaming traffic, and working copies of saved browser profiles last used on this node. Durable account and mail data, and the saved profiles themselves, are stored separately as described above.

Purpose: Low-latency sessions for users in the Asia-Pacific region

Location: Singapore. Singapore holds no EU or Swiss adequacy decision.

Data Transfer Mechanism: EU Standard Contractual Clauses (2021/914) and the Swiss FDPIC-recognised equivalent; encryption in transit (TLS, DTLS-SRTP)

Privacy Policy: https://www.ovhcloud.com/en/personal-data-protection/

FiberState, LLC

Service: North America edge compute for sessions (ephemeral containers; the node where a saved browser profile was last used can keep a working copy of it)

Data Processed: Temporary session compute and streaming traffic, and working copies of saved browser profiles last used on this node. Durable account and mail data, and the saved profiles themselves, are stored separately as described above.

Purpose: Low-latency sessions for users in North America

Location: Salt Lake City, Utah, United States

Data Transfer Mechanism: FiberState is not certified under the EU-US Data Privacy Framework. EU Standard Contractual Clauses and the Swiss FDPIC-recognised equivalent; encryption in transit

OVHcloud (OVH Hebergement INC)

Service: North America edge compute for sessions (ephemeral containers; the node where a saved browser profile was last used can keep a working copy of it)

Data Processed: Temporary session compute and streaming traffic, and working copies of saved browser profiles last used on this node. Durable account and mail data, and the saved profiles themselves, are stored separately as described above.

Purpose: Low-latency sessions for users in North America

Location: Beauharnois, Quebec, Canada

Data Transfer Mechanism: Canada holds an EU adequacy decision (PIPEDA) recognised by Switzerland; Standard Contractual Clauses and the Swiss equivalent are additionally in place

Privacy Policy: https://www.ovhcloud.com/en/personal-data-protection/

5. Content Delivery, Security and Mail Routing

Cloudflare, Inc.

Service: Authoritative DNS for the website domains, delivery of the web frontend (including TLS termination on those routes), bot protection (Turnstile) on registration, sign-in and similar forms, and Email Routing for inbound messages to the integrated mail service

Data Processed: IP addresses, request metadata, security signals; for Email Routing: inbound email envelopes and content in transit to our infrastructure

Purpose: Website delivery and performance, bot and DDoS protection, inbound mail routing

Location: Entity seat: San Francisco, California, United States. Global anycast edge.

Data Transfer Mechanism: Certified under the EU-US Data Privacy Framework including the Swiss-US extension; EU Standard Contractual Clauses and the Swiss equivalent as fallback

Privacy Policy: https://www.cloudflare.com/privacypolicy/

BunnyWay d.o.o. (bunny.net)

Service: Bunny DNS, the authoritative DNS for our API hostnames, with geo routing and health checks that remove unavailable servers from DNS answers

Data Processed: The IP address of the DNS resolver making the lookup and, where the resolver sends it, a shortened part of the user's IP address (EDNS Client Subnet), the hostname queried and the time of the query. Bunny DNS does not see API requests, session content or account data.

Purpose: Route each user to a nearby, available browser server

Location: Ljubljana, Slovenia (EEA). Global anycast DNS network.

Data Transfer Mechanism: EEA processing; the GDPR applies directly and the EEA is recognised as adequate under Swiss law, so no additional transfer mechanism is required; bunny.net data processing agreement in place

Privacy Policy: https://bunny.net/privacy/

6. Identity Providers

Google LLC (Sign in with Google)

Service: OAuth 2.0 identity assertion when you choose to sign in with Google

Data Processed: Verified email address, name, profile picture URL

Purpose: Optional single sign-on

Location: Mountain View, California, United States

Data Transfer Mechanism: Certified under the EU-US Data Privacy Framework including the Swiss-US extension; Standard Contractual Clauses as fallback

Privacy Policy: https://policies.google.com/privacy

Microsoft Corporation (Sign in with Microsoft)

Service: OAuth 2.0 / OpenID Connect against Microsoft Entra ID for organizations that enable single sign-on

Data Processed: Verified email address, display name, tenant identifier

Purpose: Optional enterprise single sign-on

Location: Redmond, Washington, United States

Data Transfer Mechanism: Certified under the EU-US Data Privacy Framework including the Swiss-US extension; Microsoft data protection terms with Standard Contractual Clauses as fallback

Privacy Policy: https://privacy.microsoft.com/en-us/privacystatement

7. Communication Services

Google Ireland Limited (Google Workspace, Gmail)

Service: Outbound transactional email (account verification, receipts, service notices), sent from [email protected] (the shared transactional mail address of the Browser.lol and Guard.ch platform) through the Google Workspace SMTP relay

Data Processed: Recipient email address, message subject and content of transactional emails

Purpose: Reliable delivery of transactional email

Location: Dublin, Ireland (EEA). Mail data may be processed by Google LLC in the United States.

Data Transfer Mechanism: Google Workspace Data Processing Amendment; for US processing by Google LLC: EU-US Data Privacy Framework including the Swiss-US extension, Standard Contractual Clauses as fallback

Privacy Policy: https://policies.google.com/privacy

8. AI and Machine Learning Services

OpenRouter, Inc.

Service: LLM API gateway for optional integrated-mail features and Guard.ch live analysis; OpenRouter forwards requests to the configured inference provider (for example, Google Gemini for mail summaries)

Data Processed: Mail content submitted for optional summaries or call-to-action detection; page-derived content submitted for optional Guard.ch live analysis

Purpose: Optional AI processing. For the integrated Browser.lol mail feature, OpenRouter is the channel through which message content reaches an AI provider; Guard.ch optional live analysis processes viewed page content separately.

Location: United States (OpenRouter). The location of the routed inference provider depends on the model configured at the time of the request.

Data Transfer Mechanism: OpenRouter is not certified under the EU-US Data Privacy Framework. EU Standard Contractual Clauses (2021/914) and the Swiss FDPIC-recognised equivalent are the applicable transfer mechanism

Privacy Policy: https://openrouter.ai/privacy

OpenAI OpCo, LLC

Service: Inference provider, reached through OpenRouter, for automated anomaly detection over aggregated server-side operational logs

Data Processed: Server-side log excerpts for this operational process. Session and mail content is not submitted for log-anomaly analysis; optional Guard.ch live analysis has a separate processing flow.

Purpose: Operational monitoring and alerting

Location: San Francisco, California, United States

Data Transfer Mechanism: OpenAI data processing agreement; certified under the EU-US Data Privacy Framework, Standard Contractual Clauses as fallback. API traffic is excluded from model training by contract.

Privacy Policy: https://openai.com/privacy/

9. Security and Verification Services

Reoon

Service: Email address verification at account registration

Data Processed: The email address provided during registration

Purpose: Detect invalid or disposable email addresses and prevent fraudulent registrations. Addresses are submitted for verification only and are not retained by the provider beyond verification.

Location: See the provider's privacy policy for its processing locations

Data Transfer Mechanism: EU Standard Contractual Clauses and the Swiss FDPIC-recognised equivalent where required

Privacy Policy: https://www.reoon.com/privacy-policy/

Google LLC (Web Risk)

Service: Hostname reputation lookups against known malware, social engineering and unwanted software infrastructure

Data Processed: Hostnames being checked. No account data is sent with these lookups.

Purpose: Detection of known-malicious infrastructure

Location: Mountain View, California, United States

Data Transfer Mechanism: Certified under the EU-US Data Privacy Framework including the Swiss-US extension; Standard Contractual Clauses as fallback

Privacy Policy: https://policies.google.com/privacy

IP Address Analysis (no external subprocessor)

IP geolocation, VPN/proxy detection and risk assessment are performed against locally hosted databases on our own infrastructure. No IP intelligence vendor receives your data at runtime for these checks.

10. Analytics and Advertising Services

Google LLC (Google Analytics 4)

Service: Website usage analytics (measurement ID G-VLXBKHVENH)

Data Processed: Cookie identifiers, device and browser information, pages visited, session and interaction data, truncated IP information as processed by Google Analytics 4

Purpose: Understand how the website is used and improve it

Location: United States (global operations)

Data Transfer Mechanism: Certified under the EU-US Data Privacy Framework including the Swiss-US extension; Standard Contractual Clauses as fallback

Note: Opt-out: Google Analytics Opt-out Browser Add-on

Privacy Policy: https://policies.google.com/privacy

Playwire LLC

Service: Advertising platform funding the free service

Data Processed: IP addresses, cookies, browser and device information, ad interaction data (views, clicks) on ad-supported pages

Purpose: Display, cap and measure advertisements. Advertising supports free access to Browser.lol; accounts with paid ad-free entitlements do not receive these ads.

Location: United States

Data Transfer Mechanism: Standard Contractual Clauses and the Swiss FDPIC-recognised equivalent

Privacy Policy: https://www.playwire.com/privacy-policy

11. Logging and Telemetry

Axiom, Inc.

Service: Server-side log aggregation and operational telemetry

Data Processed: Application log events, which can include IP addresses, user IDs, session IDs and workspace IDs

Purpose: Centralized operational logging, troubleshooting and monitoring

Location: United States

Data Transfer Mechanism: Axiom data processing terms; EU Standard Contractual Clauses and the Swiss FDPIC-recognised equivalent

Privacy Policy: https://axiom.co/privacy

12. Summary Table

SubprocessorCategoryLocationTransfer Mechanism
Mollie B.V.Payment processingAmsterdam, Netherlands (EEA)EEA-based
Hetzner Online GmbHPrimary database, backups, mail attachmentsHelsinki, Finland; Nuremberg, Germany (EEA)EEA-based
IDrive Inc. (IDrive e2)Saved-profile storageFrankfurt, Germany (EEA)EEA storage; DPF, SCCs fallback
OVHcloud (France)Edge compute, saved-profile working copiesGravelines, France (EEA)EEA-based
OVHcloud (Singapore)Edge computeSingaporeSCCs + CH equivalent
FiberState, LLCEdge computeSalt Lake City, USASCCs + CH equivalent
OVHcloud (Canada)Edge computeBeauharnois, CanadaAdequacy + SCCs
Cloudflare, Inc.DNS / delivery / Turnstile / Email RoutingUnited States (global edge)DPF, SCCs fallback
BunnyWay d.o.o. (bunny.net)DNS for API hostnames (geo routing)Slovenia (EEA)EEA-based
Google LLC (Sign-in)IdentityUnited StatesDPF, SCCs fallback
Microsoft CorporationIdentity (SSO)United StatesDPF, SCCs fallback
Google Ireland Ltd (Workspace)Transactional emailDublin, Ireland (EEA) / USDPA; DPF for US processing
OpenRouter, Inc.AI (mail and optional live analysis)United StatesSCCs + CH equivalent
OpenAI OpCo, LLCAI (log analysis)United StatesDPF, SCCs fallback
ReoonEmail verificationSee providerSCCs where required
Google LLC (Web Risk)SecurityUnited StatesDPF, SCCs fallback
Google LLC (Analytics 4)AnalyticsUnited StatesDPF, SCCs fallback
Playwire LLCAdvertisingUnited StatesSCCs + CH equivalent
Axiom, Inc.LoggingUnited StatesSCCs + CH equivalent

SCCs = EU Standard Contractual Clauses (2021/914) | CH equivalent = Swiss FDPIC-recognised equivalent of the SCCs | DPF = EU-US Data Privacy Framework including the Swiss-US extension

13. Questions and Contact

For questions about our subprocessors or to exercise your right to object:

Data protection contact: [email protected]

Postal Address: Janis Zesiger, Mügeri 340, 5046 Schmiedrued, Switzerland

We have not appointed a data protection officer because none of the thresholds that would require one applies to our processing. For more information about data processing, see our Privacy Policy.

Last Updated: September 30, 2026