SOTHURA SAFE
← Back to homepage
EN
DEDeutschFRFrançaisITItalianoENEnglish

Sub-processors

The German version is binding. This translation is provided for information only.

Overview of all sub-processors pursuant to GDPR Art. 28 paras. 2 and 3 and revDSG Art. 9 para. 3 · Stand: 2026-09-03

1. Purpose of this list

To operate the platform, the provider engages sub-processors. This page lists all current sub-processors with purpose, processing region and the status of the data processing agreement (DPA). The list is updated whenever changes occur; pursuant to section 15 of the Terms, customers may raise reasoned objections within 30 days.

In the event of material changes to our sub-processor list, we inform our customers with reasonable advance notice (GDPR Art. 28 para. 2). Notification is sent by email to the compliance contacts on file in the contract; the change is also documented in the internal sub-processor changelog. Until a dedicated RSS feed is available, the "Last change" date per entry is the reference point. Most recently removed: Twilio on 03.09.2026 — SMS as a second factor is no longer used. The second step runs through authenticator apps (TOTP) and, in the client portal, through a one-time code sent by email.

2. Active sub-processors

ProviderPurposeRegionDPA statusLast change
MongoDB AtlasDatabase hosting (operational data, CSFLE-encrypted fields, audit trails)europe-west6 (Zurich)Atlas DPA2026-05-02
Google Cloud EMEA Limited (Cloud Run, Cloud Storage, Cloud KMS, Cloud DLP, Vertex AI)Compute, file storage, key management (key sovereignty remains with SOTHURA SAFE GmbH), AI processing, redaction of personal data before it is filed in the immutable audit traileurope-west6 (Zurich) for operational data and AI processing; EU multi-region endpoint as failover under loadGoogle Cloud Data Processing Addendum (in force)2026-09-03
AWS SESTransactional email delivery (system notifications, login emails, reports)eu-central-1 (Frankfurt)AWS DPA2026-05-02
Cloudflare TurnstileBot protection for public forms (login, registration, contact forms)global (edge network)Cloudflare DPA2026-05-02
Microsoft (Microsoft Entra ID; Microsoft 365 and Microsoft Graph only where the integration is activated)Issuing and validating the sign-in tokens for the Outlook add-in (Entra ID). Where the customer switches the integration on, additionally calendar and mail synchronisation with the customer workplace (appointments, messages and their attachments). For the content of a mail the adviser opens in the add-in, Microsoft is not a sub-processor of the provider: that content sits in the customer own Microsoft 365 tenant, for which the customer holds their own contract with MicrosoftMicrosoft sign-in service, reachable globally; the data location follows the customer tenant. For synchronisation, the data location of the Microsoft 365 environment operated by the customerMicrosoft Products and Services Data Protection Addendum; contracting entity and filing are being recorded2026-09-03

3. Data residency and third-country transfers

Operational platform data (database, file storage, audit logs) remains in Switzerland (region europe-west6, Zurich). AI processing also takes place in Zurich (region europe-west6); under load it fails over to the European multi-region endpoint and then takes place in the EU. The specific AI sub-processor is listed in the table above. Email delivery runs through AWS SES in the EU (eu-central-1, Frankfurt). Cloudflare Turnstile operates as a global edge service but only returns an anonymous bot-protection token and does not process platform data. Calendar and mail synchronisation with Microsoft 365 only runs where the customer switches the integration on. Processing then takes place in the workplace environment the customer operates; the customer determines its data location through their own configuration. For the Outlook add-in, Microsoft issues the sign-in tokens; the content of a mail opened in the add-in stays in the customer Microsoft 365 tenant until the adviser files it in the platform. For any third-country transfers, the Standard Contractual Clauses (SCC) of the European Commission apply.

4. Data processing agreements (DPA)

A data processing agreement is in place with each sub-processor listed above. The DPAs are stored in the internal compliance archive and made available to customers for review on request, to the extent required by contract or by law.

5. Changes and objections

The provider informs customers of planned changes or additions to the sub-processor list. Pursuant to section 15 of the Terms, objections must be submitted in writing to security [at] sothura [dot] com within 30 days. In the case of legitimate data-protection or security-related objections, the customer has a special right of termination if no equivalent alternative can be offered.

The formalities

SOTHURA SAFE GmbH, Wassergasse 5, 4573 Lohn-Ammannsegg, Canton of Solothurn. Registered in the commercial register of the Canton of Solothurn, UID CHE-429.131.582. Management is held by Silvio Siegenthaler and Michel Di Vito, joint signature by two. The full provider identification is set out in the legal notice.

  • Legal notice and provider identification
  • Security and data protection
  • Privacy policy under the revised FADP and GDPR
  • General terms and conditions (B2B)
© 2026 SOTHURA SAFE GmbH. All rights reserved.