Subprocessors and Data Locations

Version: 1.0

Effective date: 24 July 2026

Last updated: 24 July 2026

This page supports the Privacy Notice and Data Processing Addendum. A supplier may be a subprocessor for one activity and an independent or joint controller for another.

1. Primary locations and access

  • hionet establishment and administration: United Kingdom.

  • Customer-content hosting: the location selected by the customer before ordering.

  • hionet administrative access: United Kingdom.

  • Authorised individual support-contractor access: Romania.

  • Customer-content backups and residual infrastructure recovery copies: none maintained by hionet.

2. Provider schedule

Provider and service

Purpose and data

Locations

Typical role

Transfer approach

Leaseweb Netherlands B.V.

Hosting infrastructure; customer content, configuration, logs and account/service identifiers

Amsterdam, Netherlands

Subprocessor

UK adequacy regulations for the EEA

Leaseweb Deutschland GmbH

Hosting infrastructure

Frankfurt, Germany

Subprocessor

UK adequacy regulations for the EEA

Leaseweb UK Ltd.

Hosting infrastructure

London, United Kingdom

Subprocessor

No UK restricted transfer

Leaseweb Canada Inc.

Hosting infrastructure

Montreal, Canada

Subprocessor

Applicable Canadian adequacy scope or another valid safeguard

Leaseweb Singapore Pte. Ltd.

Hosting infrastructure

Singapore

Subprocessor

Provider DPA plus UK IDTA or UK Addendum where required

Leaseweb Australia Pty. Ltd.

Hosting infrastructure

Sydney, Australia

Subprocessor

Provider DPA plus UK IDTA or UK Addendum where required

Armany LLC, operating Rabisu

Hosting infrastructure; may engage local data-centre operators

Los Angeles, New York, Miami and Dallas, United States; London, United Kingdom; Dublin, Ireland

Subprocessor

UK adequacy for UK/EEA; UK Extension to the EU-US DPF where applicable, or UK IDTA/UK Addendum for US transfers

Cloudflare, Inc.

DNS, CDN, DDoS mitigation, security and Cloudflare Web Analytics; IP, request and device data

Global network, including United States and locations near the user

Processor/subprocessor for contracted services; controller for limited account or security purposes

UK Extension to EU-US DPF and contractual safeguards in Cloudflare's DPA

Authorised individual support contractors

Ticket support and authorised troubleshooting; account, ticket and limited customer content where necessary

Romania

Subprocessor/person acting under hionet authority

UK adequacy regulations for the EEA and written confidentiality/data-protection terms

hionet-hosted Paymenter

Accounts, invoices, orders, tickets, affiliate attribution and consent records

The hionet-selected hosting location

Internal/self-hosted software, not a separate recipient

Follows the location of the host

hionet-hosted Pterodactyl

Game and bot control panel, files, configuration, console and service data

The customer-selected hosting location and hionet management systems

Internal/self-hosted software, not a separate recipient

Follows the location of the host

Stripe Payments Europe, Limited and Stripe Payments UK Ltd

Invoice payment processing, authentication and fraud prevention

United Kingdom, EEA, United States and provider/subprocessor locations

Independent controller and processor depending on activity

Stripe contractual safeguards, DPF where applicable and SCC/UK Addendum mechanisms

PayPal UK Ltd and PayPal (Europe) S.à r.l. et Cie, S.C.A.

Invoice payment processing, authentication, fraud prevention and disputes

United Kingdom, EEA and global provider locations

Primarily independent controller for payment services

PayPal binding corporate rules, adequacy and contractual safeguards as applicable

Raintank, Inc. dba Grafana Labs (Grafana Cloud)

Reliability and security monitoring; metrics, IPs, logs and diagnostics selected by hionet

Grafana Cloud region selected by hionet and its listed cloud subprocessors, which may include US or EU regions

Subprocessor

UK Extension to EU-US DPF and Grafana contractual safeguards

Google LLC and Google Ireland Limited

Google Analytics and Google Ads; device, usage, campaign and conversion data

Global, including United States and EEA

Processor, independent controller or joint controller depending on product

DPF, SCCs and UK Addendum/contractual terms as applicable

Meta Platforms, Inc. and applicable affiliates

Meta Pixel advertising measurement and audiences

Global, including United States

Independent or joint controller depending on activity

DPF and Meta contractual transfer terms as applicable

TikTok For Business entities applicable to the hionet account

TikTok Pixel advertising measurement and audiences

Global, including United States, United Kingdom and EEA

Independent or joint controller depending on activity

TikTok jurisdiction-specific data terms and applicable transfer safeguards

hionet-hosted mailbox

Incoming and outgoing contact and support email

The location of the listed infrastructure provider used for hionet administrative hosting

Internal/self-hosted mail service; the relevant listed infrastructure provider acts as subprocessor

Follows the safeguards stated for that infrastructure provider

The hionet mailbox is hosted on infrastructure supplied by one of the providers listed above rather than by a separate mailbox SaaS provider. The applicable infrastructure provider and location are recorded internally and this page will be updated if a new external mail provider is introduced.

3. Transfer safeguards

Before enabling a customer location or supplier that involves a UK restricted transfer, hionet determines the applicable mechanism and documents the transfer assessment. Mechanisms may include UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework, the UK International Data Transfer Agreement or the UK Addendum to the 2021 EU Standard Contractual Clauses. Supplementary measures may include encryption in transit, access limitation, minimisation, logging, contractual challenge/notice commitments and customer location choice.

Copies or summaries of applicable safeguards can be requested at [email protected], subject to necessary commercial and security redactions.

4. Changes and objections

Business customers subject to the DPA may subscribe to change notices by emailing [email protected] with the subject “Subprocessor notices”. We aim to provide at least 30 days' advance notice of a new or replacement subprocessor that will process customer content, except where an urgent security, continuity or legal replacement is necessary. Reasonable data-protection objections must be submitted during that period under the DPA.

5. Version history

Date

Change

24 July 2026

Version 1.0 first publication.