Subprocessors
The standard website and form path runs on AWS. Hetzner supports self-hosted internal workflows and agreed service-delivery infrastructure. This page distinguishes core infrastructure from optional or engagement-specific integrations and does not imply that an integration is active merely because a template exists.
Static site origin and storage (S3), global delivery (CloudFront), DNS, regional form API (API Gateway and Lambda), encrypted form storage (S3/KMS), and operational logging (CloudWatch/S3).
Static assets; CDN and API request metadata; contact, quote, booking, and unsubscribe submissions; IP address, user-agent, origin/referrer, timestamps, and operational/security logs.
Origin storage, form execution, and primary logs: Frankfurt (eu-central-1). CloudFront may handle requests at global edge locations.
AWS GDPR DPA and AWS transfer mechanisms. Form objects use KMS-managed encryption; access and operational logs have time-bound retention.
Dedicated servers in Germany for self-hosted internal automation and agreed engagement infrastructure. Hetzner is not the public website host or the primary website-form endpoint. Enabled internal workflows may retrieve records from AWS for follow-up and scheduling.
Contact, quote, booking, or unsubscribe records processed by enabled internal workflows; application and security logs; engagement data only where agreed for the applicable service.
Germany (EU); the specific engagement data flow is recorded in the SoW/DPA.
GDPR Art. 28 DPA and an EU data-centre region selected for relevant workloads.
Website data flow
- The static website is stored in a private S3 origin in Frankfurt and delivered through CloudFront. A visitor's IP address and request metadata may be processed at a global edge location before the request reaches the EU origin.
- Contact, quote, booking, and unsubscribe forms post to AWS API Gateway and Lambda in Frankfurt. Validated records are stored in a private, KMS-encrypted S3 bucket in the same region. CloudWatch and S3 retain operational and access logs.
- Where an internal follow-up workflow is enabled, a dedicated Hetzner-hosted service in Germany may retrieve the record from AWS to create a follow-up or scheduling task.
- Access is limited to authorised personnel. Grilli operates from Tallinn and Buenos Aires, so authorised remote access from Argentina may occur unless EU-only access has been agreed in advance.
Engagement infrastructure
Professional-services data flows are not inferred from the website stack. The SoW and, where applicable, engagement DPA identify the approved systems, storage region, access locations, retention, deletion, and additional providers. Requirements such as EU-only access, client-controlled storage, or an isolated environment must be agreed before sensitive data is transferred.
To review or constrain the proposed data flow, contact privacy@grillisecurity.com for details.
Engagement-specific subprocessors
Where a specific service engagement requires additional subprocessors beyond those listed above (for example, a specialist forensic tooling provider, or a regional legal counsel), they are disclosed in the Statement of Work and handled under the approval and objection process in the signed engagement DPA before personal data is shared with them.
Optional integrations
The codebase includes inactive-by-default templates for optional calendar, notification, email, messaging, and outreach-preference integrations. A template alone does not process data and does not make its provider a subprocessor. Before any optional provider receives personal data, Grilli must complete the applicable security and contractual review, document the legal entity, purpose, data categories, region, and safeguards, and add it to this public list or the engagement subprocessor schedule as appropriate.
Buyers that require deployed-state confirmation can request the current production integration and subprocessor inventory during diligence at privacy@grillisecurity.com.
Change notification
We update this page when the public list changes. Contracted customers receive notice on the timing and channel stated in their signed DPA; this page does not replace contractual notice.
Objection process
Customers with a signed DPA may use the objection process and timeframe in that agreement by contacting privacy@grillisecurity.com. We will work with you in good faith to resolve the objection.
For data-protection enquiries, contact privacy@grillisecurity.com. See also our Privacy Policy and Website Data Processing Notice.
