Last updated: 25 September 2026
This page lists the sub-processors that Nabto ApS ("Nabto", "we") engages to process personal data on behalf of our customers in connection with the Nabto platforms, namely Nabto Edge, Nabto WebRTC and Nabto 4 (the "Service").
We use these sub-processors to deliver, secure and support the Service. Each is engaged under a written agreement that imposes data-protection obligations no less protective than those in our Data Processing Agreement (DPA) and we remain responsible to our customers for their performance. This page forms part of and should be read together with, the DPA.
Each organization is created in the console with either Global or EU-only data residency; the choice cannot be changed afterwards. EU-only organizations run entirely in EU regions (Ireland, Frankfurt and Belgium) for everything that carries device and client traffic. Global organizations also use regions in the United States and Asia-Pacific. The control plane, the database and the telemetry are in the EU for every customer.
These sub-processors run the connectivity of the customer's devices and clients, so the regions they use follow the organization's data residency.
| Sub-processor | What it does for the Service | Regions | Transfer mechanism (if outside EU/EEA) | Privacy / DPA |
|---|---|---|---|---|
| Amazon Web Services (AWS EMEA SARL, Luxembourg) | Cloud hosting of the control plane (Cloud API, database, DNS), signaling, hosted basestations and relay/TURN. | Control plane, database and DNS in eu-west-1 (Ireland) for all customers. Basestations, signaling and relay in eu-west-1 (Ireland) and eu-central-1 (Frankfurt); EU-only organizations use these EU regions only. Global organizations add us-west-2 (Oregon) and ap-south-1 (Mumbai) for Nabto Edge and Nabto WebRTC, the WebRTC region being chosen per product, with connection metadata and relayed traffic processed in the region the device or client attaches to. Monitoring probes run from eu-west-1, us-east-1 and ap-southeast-1 against Nabto's own test devices. | None for EU-only organizations. For Global organizations, the EU Standard Contractual Clauses in the AWS Data Processing Addendum, plus AWS's EU-US Data Privacy Framework certification for the US regions. | https://aws.amazon.com/privacy/ |
| Google Cloud (Google Cloud EMEA Limited, Ireland) | Google Cloud Pub/Sub, which replicates device and connection state (device identifiers, pairing and connection state) between platform regions. | Stored in europe-west1 (Belgium), pinned by message storage policy. Delivered only to the regions the organization uses, so the state of an EU-only organization is never delivered outside the EU. | None for EU-only organizations. For Global organizations, the EU Standard Contractual Clauses in Google's Cloud Data Processing Addendum. | https://cloud.google.com/terms/data-processing-addendum |
These sub-processors support Nabto's operations and customer support. They are never in the path of device or client traffic; the personal data they see is limited to what the table states, regardless of data residency.
| Sub-processor | What it does for the Service | Regions | Transfer mechanism (if outside EU/EEA) | Privacy / DPA |
|---|---|---|---|---|
| Grafana Labs (Grafana Labs, Inc., United States) | Logs and metrics for observability (Grafana Cloud), which may contain IP addresses. | Stored in Frankfurt, AWS eu-central-1. Accessed by Grafana Labs, Inc. from the United States. | The EU Standard Contractual Clauses in Grafana's data processing addendum and Grafana Labs, Inc.'s EU-US Data Privacy Framework certification. | https://grafana.com/legal/privacy-policy/ |
| Shortcut (Shortcut Software Company, Inc., United States) | Support and issue tracking. Only the personal data the Customer includes in a support request, such as End-User identifiers, IP addresses and diagnostic traces. | United States. | The EU Standard Contractual Clauses in Shortcut's data processing addendum and Shortcut's EU-US Data Privacy Framework certification. | https://www.shortcut.com/privacy |
| Google Workspace (Google Ireland Limited) | Email for support and account correspondence. Only the personal data the Customer includes in email to Nabto. | EU, with support and operational access from the United States. | The EU Standard Contractual Clauses in the Google Workspace Data Processing Amendment and Google's EU-US Data Privacy Framework certification. | https://workspace.google.com/terms/dpa_terms.html |
Note: Vendors that process only data for which Nabto is the controller, such as card payments (Stripe), customer communications, internal messaging and IP geolocation, are not sub-processors. They are described in our Platform Privacy Policy at https://downloads.nabto.com/assets/legal/platform-privacy-policy.html.
We provide general authorization for the use of sub-processors under our DPA. Before adding or replacing a sub-processor that processes customer personal data, we will give all customers prior notice by:
Every customer has a registered contact through the console or the Order Form, so there is nothing to subscribe to. We will send this notice at least 14 days before the change takes effect, so you have time to object as set out below. Please keep your account administrator and contact details up to date so you receive these notices.
If you have a reasonable, data-protection-based objection to a new sub-processor, you may notify us at privacy@nabto.com within 14 days of our notice. We will work with you in good faith to address the concern. If we cannot resolve it, you may terminate the affected part of the Service as set out in the DPA.
| Date | Change |
|---|---|
| 19 June 2026 | Initial publication. |
| 15 September 2026 | Generalized for all customers, self-serve and Order Form alike, and for all Nabto platforms (Nabto Edge, Nabto WebRTC and Nabto 4): notice mechanism extended to Order Form contacts, Stripe moved from the table to the controller-side note (it processes customer billing data, not End-User data) and page moved to https://downloads.nabto.com/assets/legal/subprocessors.html. |
| 23 September 2026 | Shortcut and Google Workspace added to the table, scope-limited to the personal data that customers include in support requests and in email to us. Transfer-mechanism column corrected for Amazon Web Services, Google Cloud and Grafana Labs: EU storage does not by itself settle the transfer analysis, so cross-region Pub/Sub delivery and access from the United States to EU-hosted data are now stated as transfers under the applicable Standard Contractual Clauses, with the Data Privacy Framework identified where it applies. Processing locations restated per data residency: the control plane and telemetry are in the EU for all customers, Global organizations use the EU, US and Asia-Pacific data plane regions (Nabto 4 in different US and Asia-Pacific regions than Nabto Edge and Nabto WebRTC), EU-only organizations stay in eu-west-1. |
| 24 September 2026 | Restructured into a service data path section and a tools-around-the-service section so that the data-residency choice is visible at a glance; transfer analyses moved to Annex 4 of the DPA; no sub-processor added or removed. Frankfurt (eu-central-1) added to the EU regions. |