AssetObserve
Sign in Start free
Legal

Subprozessoren

Last updated: 13 August 2026

Important notice

This is the list of subprocessors engaged for the provision of AssetObserve, published under the Data Processing Agreement. It is a draft: it must be completed and reviewed against the contracts actually in place before a customer relies on it. A provider that is not listed here must not process customer personal data.

How changes are announced

Customers are informed of any intended addition or replacement of a subprocessor at least 30 days in advance, and may object on reasonable data protection grounds within that period. Notification is sent to the billing and administrative contacts recorded for the workspace.

Current subprocessors

  • Hosting and infrastructure: [hosting_provider], [hosting_location]. Purpose: operation of the application, database, and backups. Personal data: all workspace data described in the Data Processing Agreement.
  • Payment processing: [payment_provider], [payment_provider_location]. Purpose: subscription checkout, payment, and refunds. Personal data: billing contact, billing address, VAT identification number, and payment metadata. Card data is entered directly with the payment provider and is not stored by AssetObserve.
  • Transactional email delivery: [email_provider], [email_provider_location]. Purpose: account, notification, invoice, and support email. Personal data: recipient name, email address, and message content.
  • Error and performance monitoring: [monitoring_provider], [monitoring_provider_location]. Purpose: detecting and diagnosing application faults. Personal data: technical request metadata and error context, with personal data scrubbed before transmission. This subprocessor is optional and is only engaged when monitoring is enabled for the deployment.

Services that receive no customer personal data

The product downloads public vulnerability and lifecycle data from external sources in order to match it locally against the customer's inventory. These downloads carry no customer data outbound and are therefore not subprocessors:

  • National Vulnerability Database (CVE and CPE dictionaries)
  • CISA Known Exploited Vulnerabilities catalog
  • FIRST.org EPSS exploit probability scores
  • End-of-life product lifecycle data

Hardware warranty lookups and cloud or directory integrations are performed only when the customer configures them, and send data to the vendor the customer has chosen.

Placeholder notice

Replace every bracketed provider, corporate entity, and processing location with the providers actually engaged, add the legal entity name and country for each, and record the transfer mechanism used where a provider processes data outside the European Economic Area.

Contact: contact@assetobserve.com

AssetObserve

AssetObserve helps IT teams and service providers document authorized internal infrastructure, scanner coverage, risk findings and reports from one SaaS workspace.

Platform Platform Capabilities Plans
Compliance NIS2 readiness BSI IT-Grundschutz
Company Help FAQ Contact Support Service status
Legal Impressum Datenschutz AGB Cookie Richtlinie Data processing agreement Security measures Subprocessors Service level agreement Vulnerability disclosure Accessibility
AssetObserve
contact@assetobserve.com