Subprocessors and Data Locations
Version: 1.0
Effective date: 24 July 2026
Last updated: 24 July 2026
This page supports the Privacy Notice and Data Processing Addendum. A supplier may be a subprocessor for one activity and an independent or joint controller for another.
1. Primary locations and access
hionet establishment and administration: United Kingdom.
Customer-content hosting: the location selected by the customer before ordering.
hionet administrative access: United Kingdom.
Authorised individual support-contractor access: Romania.
Customer-content backups and residual infrastructure recovery copies: none maintained by hionet.
2. Provider schedule
Provider and service | Purpose and data | Locations | Typical role | Transfer approach |
|---|---|---|---|---|
Leaseweb Netherlands B.V. | Hosting infrastructure; customer content, configuration, logs and account/service identifiers | Amsterdam, Netherlands | Subprocessor | UK adequacy regulations for the EEA |
Leaseweb Deutschland GmbH | Hosting infrastructure | Frankfurt, Germany | Subprocessor | UK adequacy regulations for the EEA |
Leaseweb UK Ltd. | Hosting infrastructure | London, United Kingdom | Subprocessor | No UK restricted transfer |
Leaseweb Canada Inc. | Hosting infrastructure | Montreal, Canada | Subprocessor | Applicable Canadian adequacy scope or another valid safeguard |
Leaseweb Singapore Pte. Ltd. | Hosting infrastructure | Singapore | Subprocessor | Provider DPA plus UK IDTA or UK Addendum where required |
Leaseweb Australia Pty. Ltd. | Hosting infrastructure | Sydney, Australia | Subprocessor | Provider DPA plus UK IDTA or UK Addendum where required |
Armany LLC, operating Rabisu | Hosting infrastructure; may engage local data-centre operators | Los Angeles, New York, Miami and Dallas, United States; London, United Kingdom; Dublin, Ireland | Subprocessor | UK adequacy for UK/EEA; UK Extension to the EU-US DPF where applicable, or UK IDTA/UK Addendum for US transfers |
Cloudflare, Inc. | DNS, CDN, DDoS mitigation, security and Cloudflare Web Analytics; IP, request and device data | Global network, including United States and locations near the user | Processor/subprocessor for contracted services; controller for limited account or security purposes | UK Extension to EU-US DPF and contractual safeguards in Cloudflare's DPA |
Authorised individual support contractors | Ticket support and authorised troubleshooting; account, ticket and limited customer content where necessary | Romania | Subprocessor/person acting under hionet authority | UK adequacy regulations for the EEA and written confidentiality/data-protection terms |
hionet-hosted Paymenter | Accounts, invoices, orders, tickets, affiliate attribution and consent records | The hionet-selected hosting location | Internal/self-hosted software, not a separate recipient | Follows the location of the host |
hionet-hosted Pterodactyl | Game and bot control panel, files, configuration, console and service data | The customer-selected hosting location and hionet management systems | Internal/self-hosted software, not a separate recipient | Follows the location of the host |
Stripe Payments Europe, Limited and Stripe Payments UK Ltd | Invoice payment processing, authentication and fraud prevention | United Kingdom, EEA, United States and provider/subprocessor locations | Independent controller and processor depending on activity | Stripe contractual safeguards, DPF where applicable and SCC/UK Addendum mechanisms |
PayPal UK Ltd and PayPal (Europe) S.à r.l. et Cie, S.C.A. | Invoice payment processing, authentication, fraud prevention and disputes | United Kingdom, EEA and global provider locations | Primarily independent controller for payment services | PayPal binding corporate rules, adequacy and contractual safeguards as applicable |
Raintank, Inc. dba Grafana Labs (Grafana Cloud) | Reliability and security monitoring; metrics, IPs, logs and diagnostics selected by hionet | Grafana Cloud region selected by hionet and its listed cloud subprocessors, which may include US or EU regions | Subprocessor | UK Extension to EU-US DPF and Grafana contractual safeguards |
Google LLC and Google Ireland Limited | Google Analytics and Google Ads; device, usage, campaign and conversion data | Global, including United States and EEA | Processor, independent controller or joint controller depending on product | DPF, SCCs and UK Addendum/contractual terms as applicable |
Meta Platforms, Inc. and applicable affiliates | Meta Pixel advertising measurement and audiences | Global, including United States | Independent or joint controller depending on activity | DPF and Meta contractual transfer terms as applicable |
TikTok For Business entities applicable to the hionet account | TikTok Pixel advertising measurement and audiences | Global, including United States, United Kingdom and EEA | Independent or joint controller depending on activity | TikTok jurisdiction-specific data terms and applicable transfer safeguards |
hionet-hosted mailbox | Incoming and outgoing contact and support email | The location of the listed infrastructure provider used for hionet administrative hosting | Internal/self-hosted mail service; the relevant listed infrastructure provider acts as subprocessor | Follows the safeguards stated for that infrastructure provider |
The hionet mailbox is hosted on infrastructure supplied by one of the providers listed above rather than by a separate mailbox SaaS provider. The applicable infrastructure provider and location are recorded internally and this page will be updated if a new external mail provider is introduced.
3. Transfer safeguards
Before enabling a customer location or supplier that involves a UK restricted transfer, hionet determines the applicable mechanism and documents the transfer assessment. Mechanisms may include UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework, the UK International Data Transfer Agreement or the UK Addendum to the 2021 EU Standard Contractual Clauses. Supplementary measures may include encryption in transit, access limitation, minimisation, logging, contractual challenge/notice commitments and customer location choice.
Copies or summaries of applicable safeguards can be requested at [email protected], subject to necessary commercial and security redactions.
4. Changes and objections
Business customers subject to the DPA may subscribe to change notices by emailing [email protected] with the subject “Subprocessor notices”. We aim to provide at least 30 days' advance notice of a new or replacement subprocessor that will process customer content, except where an urgent security, continuity or legal replacement is necessary. Reasonable data-protection objections must be submitted during that period under the DPA.
5. Version history
Date | Change |
|---|---|
24 July 2026 | Version 1.0 first publication. |