Subprocessors are documented where they are relevant to the specific engagement.
A public supplier inventory would neither replace the privacy assessment of a specific engagement nor protect operational confidentiality. HTS Europa therefore does not publish a general list containing provider, infrastructure or location details.
What applies to contract-relevant further processors.
The concrete treatment depends on the actual service and agreed roles.
Only where relevant
A supplier does not automatically become a subprocessor simply because HTS Europa uses a service. Actual processing of customer data is what matters.
Contractual obligations
Where a further processor is used, the required data protection obligations are addressed contractually.
Third-country context
Where required, third-country processing and the applicable transfer basis are addressed in the engagement-specific documentation.
Changes
Where general authorisation has been agreed, changes are handled according to the contractual procedure.
The concrete list is not published publicly.
Affected customers receive the version relevant to their engagement in the contractual context or upon a legitimate request. This preserves both privacy transparency and operational confidentiality.
What customers receive
The information actually relevant to their engagement at the required contractual level of detail.
What remains public
Principles for selection, contractual obligations, third-country assessment and change information.
HTS Europa does not publish provider names, contractual relationships, infrastructure locations, technical dependencies or other information from which internal operational architecture could be inferred.
More public information
The overview brings together information about data processing, TOMs, subprocessors, retention and deletion.
