Vendor transparency
Subprocessors and Service Providers
Draft rules and required fields for the exact providers active in the public GutMask hosted contour.
Pre-publication draft: this document is not an approved public-beta contract. Publication and open registration remain disabled.
Document: subprocessors
Version: 2026-08-29-public-beta-draft-1
Effective date: 2026-08-29
Canonical localized-content SHA-256: ec33c22186a2e011e50dc260c34426352fc269c7406b7fc0dae3c37b07ce16f4
Approved multilingual document SHA-256: 8269c340d94ee9146d1c335c11b437a5a8373527c30989d64fcedf498f5df1b6
Privacy: privacy@gutmask.xyz
Current-list publication gate
Only a provider proved active by current contract, account, deployment, and data-flow evidence is listed as current. Code support, a plan, a trial, or a brand name alone is not evidence that personal data is sent to that provider.
- The first public list must cover hosting, DNS or security edge, identity, mail, backup, monitoring, support, and any human technical-access provider actually used.
- Controller-only vendors and processors are identified by their real role.
- An unknown legal entity, region, backup location, support access, or transfer basis blocks approval rather than becoming a generic placeholder.
Fields for each active provider
Each entry states the legal entity and product, purpose, data categories and people affected, processing and storage countries, backup and support access, subprocessor chain, transfer mechanism, retention and deletion, contract owner, and last verified date.
- A public privacy notice may summarize the facts, while the controlled evidence register retains exact contract and authenticated readback references.
- Secrets, account numbers, private billing details, and unnecessary personal data are excluded from public evidence.
- A global service is not labelled EU-only without exact proof.
Changes and objections
A material new or replacement processor is assessed before activation and announced through the stated channel with a reasonable advance period where the DPA requires it.
- Affected business customers may object on reasonable data-protection grounds during the notice period.
- No new provider receives production personal data until contract, security, location, transfer, retention, and exit checks pass.
- Emergency replacement is documented promptly with the reason and safeguards.
Questions and draft status
Questions and objections go to privacy@gutmask.xyz. The absence of a name in this draft does not prove that a live deployment has no provider; the exact live inventory must be read back before approval.
- This document remains blocked until the deployed vendor register is complete.
- Planned Cloudflare, Google, GitHub, OVHcloud, mail, or other contours are not silently declared active.
- The final list is dated, versioned, and preserved with the accepted legal set.