---
doc_id: POL-SUB-001
title: List of Service Providers (processors) — draft with drafting notes
type: policy-public
status: draft
version: 0.3
created: 2026-09-25
last_reviewed: 2026-09-25
next_review: 2026-10-09
law_checked: 2026-09-25 (UK GDPR Art. 28 read by AI reviewer — Reported; other items pending)
owner: Legal Lead (named person TBD) with CTO and Procurement
reviewers: [hidzo-counsel-reviewer (AI), EU/UK privacy counsel, U.S. privacy counsel, OFAC counsel]
counsel_needed: yes
counsel_status: none
jurisdictions: [EU, UK, CH, US-CA, GLOBAL]
related: [POL-PRIV-002, REG-VND, POL-RPRIV-001, BRF-2026-001]
sources: [EV-106, EV-214, EV-233, EV-234, EV-237, EV-301, EV-303]
supersedes: POL-SUB-001 v0.2 (2026-09-25)
print: true
confidentiality: INTERNAL — LEGAL (Part B becomes PUBLIC on publication)
---

# List of Service Providers — draft

> **Prepared for review by licensed counsel. Not legal advice.** Part B is the proposed public text; Parts A and C are internal. **No vendor in
> the vendor register is yet confirmed** (REG-VND). A provider may be listed only after its legal entity, role, data, countries and contract are
> confirmed and it has passed sanctions screening. HidzoVPN is a controller toward its users; its vendors are processors ("service providers"),
> not "subprocessors" — the title reflects that `[COUNSEL]`.

## Part A — Drafting brief (internal)

| Item | Value |
|---|---|
| Question presented | Which third parties process personal data on HidzoVPN's behalf, for what purpose and where — and which act as independent businesses? |
| Legal drivers | GDPR Art. 28(1), (3) (processor contracts); Art. 13(1)(e)–(f) (recipients; transfers); CCPA service-provider contract terms (Cal. Civ. Code §1798.100(d), §1798.140(ag); 11 CCR §7051) if the CCPA applies. A named public list is a business choice beyond what the law requires `[COUNSEL]` |
| Apple 5.4 link | Privacy Policy §2 Alternative A allows disclosure only to service providers processing on HidzoVPN's instructions (EV-106). Which vendors are processors therefore decides Apple 5.4 compliance on iOS |
| Blocking issues | "Zareh": legal name and country unknown; sanctions screening against all OFAC programs required (RSK-033). Hosting accounts may be held by individuals (RSK-036). Whether a third-party DNS resolver is used (EV-202) |

### A.1 Role of platform and payment providers (for counsel)
| Service | Likely role | Label |
|---|---|---|
| Apple App Store distribution and in-app purchase | Independent (Apple acts as agent and commissionaire under DPLA Sch. 2) | Reported |
| Sign in with Apple; Apple Push Notification service | `[COUNSEL]` | Open |
| Google Play distribution and billing | Independent `[VERIFY]` | Open |
| Google Firebase / Crashlytics / Cloud Messaging; Google Analytics via GTM | Processor terms normally available `[VERIFY]` → list in Part B if used | Open |
| Google AdMob and other ad networks | Independent → Privacy Policy §3.5, not this list | Open (D4) |
| Stripe (website payments) | Mixed: processor for payment processing, independent controller for its own fraud and legal purposes (Reported, Level D) `[COUNSEL]` | Open |

## Part B — Proposed public text

# Our Service Providers

**Last updated:** `[OPEN: date]`

The service providers below process personal data on behalf of HidzoVPN, Inc. to provide the Services `[VERIFY: a signed data processing
agreement, or accepted online terms, in the name of HidzoVPN, Inc. for each row — RSK-036]`. Some of them, such as hosting providers, also
process limited information for their own legal and security obligations. For how we protect international transfers, see Section 10 of our
Privacy Policy.

`[PROCUREMENT and CTO: complete one row per confirmed provider. Do not list a provider until the confirmation in Part C.2 is complete. A
provider in use may not be omitted.]`

| Provider (legal entity) | What they do for us | Personal data involved | Where data is processed | Transfer safeguard |
|---|---|---|---|---|
| `[e.g. DigitalOcean — VERIFY entity]` | Hosting of servers and systems `[VERIFY]` | Network traffic passing through servers they host, including IP addresses `[ENGINEERING: whether any connection records are stored on provider systems]` | `[COUNSEL: country only, or city — law-enforcement exposure (RSK-030)]` | `[EU (no transfer) / Data Privacy Framework / Standard Contractual Clauses / UK Addendum / Swiss FADP]` |
| `[e.g. Hetzner Online GmbH — VERIFY]` | Hosting `[VERIFY]` | `[ ]` | `[ ]` | `[ ]` |
| `[OneProvider — VERIFY entity]` | Dedicated servers `[VERIFY]` | `[ ]` | `[ ]` | `[ ]` |
| `[Clouvider — VERIFY entity]` | Hosting / network `[VERIFY]` | `[ ]` | `[ ]` | `[ ]` |
| `[DNS resolution — ENGINEERING: own resolver or third party (EV-202)]` | Resolving domain names | `[ENGINEERING: DNS queries — must be consistent with Privacy Policy §3.3]` | `[ ]` | `[ ]` |
| `[Stripe entity — COUNSEL: role]` | Website payment processing | Payment details, email, billing country | `[ ]` | `[ ]` |
| `[Email / one-time code provider]` | Sending sign-in codes and service emails | Email address | `[ ]` | `[ ]` |
| `[Crash reporting / analytics provider]` | App stability and usage measurement | Device and app data | `[ ]` | `[ ]` |
| `[Consent management provider]` | Recording cookie choices | Consent records, device identifiers | `[ ]` | `[ ]` |
| `[Customer support tool]` | Handling support requests | Messages, email address | `[ ]` | `[ ]` |
| `[OPEN — D7: cryptocurrency payment processor]` | `[ ]` | `[ ]` | `[ ]` | `[ ]` |

**Changes to this list.** We update this list when we add or replace a service provider `[OPEN: advance notice period, if any]`.

## Part C — Drafting notes (internal)

### C.1 Sources
| Element | Basis | Label |
|---|---|---|
| Processor contracts; authorisation of sub-processors and notice of changes; flow-down and liability | GDPR Art. 28(1)–(4) — Art. 28(2) notice-and-objection binds HidzoVPN's processors toward HidzoVPN, and binds HidzoVPN only where it acts as a processor (e.g. B2B/reseller) | Art. 28(2), (4) Verified (A) (EV-248); 28(1), (3) Reported (EV-237) |
| Recipients and transfers in the notice | GDPR Art. 13(1)(e)–(f) | `[VERIFY: EV-233]` |
| Transfer mechanisms; exporter subject to GDPR under Art. 3(2) | GDPR Arts. 44, 46(2)(c); Decision (EU) 2021/914 Art. 1(1) and Clause 9; EU-U.S. Data Privacy Framework; UK Addendum; Swiss FADP | Arts. 44, 46 and 2021/914 Verified (A) (EV-248, EV-249); others `[VERIFY]`; Art. 3(2) exporter point `[COUNSEL]` |
| Hosting DPAs | DigitalOcean DPA effective 6 Feb 2026 (SCCs + DPF; 30-day sub-processor notice) — Reported (B) (EV-250); Hetzner DPA reportedly concluded only by checkbox acceptance in the customer account — Level C (EV-251) `[ENGINEERING: confirm acceptance, account holder and date — RSK-036]` | see left |
| CCPA service-provider terms | Cal. Civ. Code §§1798.100(d), 1798.140(ag); 11 CCR §7051 | `[VERIFY: EV-233]` |
| Vendor sanctions screening | OFAC — all programs (SDN and other lists; 50 Percent Rule; comprehensively sanctioned jurisdictions, including 31 C.F.R. Part 560); historical payments and voluntary self-disclosure analysis — escalate (KB-002 A7) | `[COUNSEL: OFAC]` (RSK-033) |
| Apple 5.4 dependency | Apple Guideline 5.4 | Verified (EV-106) |

### C.2 Confirmation required for each provider (A-INT)
Contract or accepted online terms in the Company's name (RSK-036); legal entity and country; role per service (A.1); personal data processed;
server and support locations; DPA and transfer mechanism; sanctions screening result; deletion and return terms. Each named hosting provider
is either confirmed and listed, or confirmed out of service with no personal data held. Record each as `10-Vendors-SDKs/VND-<NAME>.md`.
Change control: procurement ticket → legal review → page update.

### C.3 Limits of this analysis
(a) Not reviewed: data-protection laws of provider countries; whether a public named list increases law-enforcement exposure (RSK-030) — counsel
to weigh against transparency. (b) Not opened: GDPR Art. 13 and SCC texts (EUR-Lex); Stripe DPA text. (c) Facts unknown: all provider details;
DNS arrangement; contract holders. (d) Counsel required: EU/UK privacy; U.S. privacy; OFAC.

### C.4 Review log
| Date | Reviewer | Verdict | Notes |
|---|---|---|---|
| 2026-09-25 | Drafted | — | v0.1 |
| 2026-09-25 | hidzo-counsel-reviewer (AI) | REVISE (2 Blockers; 8 Majors) | v0.2: contract statement bracketed (Blocker SUB-01); role table per service instead of blanket "independent" (Blocker SUB-02); retitled "Service Providers"; correct legal basis (Art. 28(1), (3); Art. 13); CCPA terms; missing categories (DNS, CMP, Stripe, crypto); "Zareh" may not be omitted while in use; all OFAC programs; transfer options incl. DPF and Swiss; country-only publication question; notice of changes without an unkeepable promise |
| 2026-09-25 | hidzo-counsel-reviewer (AI) — cross-document final audit; research memos EV-232–235 | REVISE (set: 1 Blocker, 8 Majors) | v0.3: cross-document redlines X-01–X-31 applied where they concern this document; authority labels updated from first-hand and research-memo checks (EV-238–264) |
