Third-party service providers processing data on our behalf
This page lists all subprocessors (third-party service providers) that AmiSyn B.V. (including its divisions Amisec, Amiphished, and AmiCloud) engages to process personal data on behalf of our customers.
In accordance with Article 28(2) and 28(4) of the GDPR, we maintain this list and notify customers of any changes to our subprocessors. All subprocessors are bound by data processing agreements that ensure GDPR compliance.
The following subprocessors are currently engaged by AmiSyn B.V.:
Infrastructure hosting and VPS services
CDN, DDoS protection, and web security
Analytics and monitoring (Google Analytics)
All subprocessors must enter into a Data Processing Agreement (DPA) that includes:
When subprocessors are located outside the European Economic Area (EEA), we ensure adequate protection through:
We conduct thorough due diligence before engaging any subprocessor, including:
Some subprocessors are used only for specific services or divisions:
Penetration testing and security services primarily use internal infrastructure. Subprocessors listed above are used for hosting reports and client communications only.
Training platforms and phishing simulations use all listed subprocessors for platform hosting, content delivery, and analytics.
Cloud infrastructure and AI solutions primarily rely on Hostinger for hosting. Additional AI-specific subprocessors may be added with prior notification.
For a complete history of subprocessor changes, please refer to our Legal Changelog.
If you wish to object to the addition of a new subprocessor or have concerns about an existing one:
Note: Objections do not apply to general administrative or operational tools that do not process customer personal data (e.g., internal HR systems, accounting software).
For questions about our subprocessors or data processing practices:
Data Protection Officer: dpo@amisyn.com
Privacy Team: privacy@amisyn.com
Company: AmiSyn B.V.
Address: [Complete Address], Utrecht, Netherlands