Subprocessors
The third-party providers Eagle Virtual uses to deliver the Service, and how data is protected with each.
Document Version: 2026-08-10
This page is incorporated by reference into our Data Processing Addendum (Annex C).
1. Subprocessors of Customer Personal Data
These providers may process Customer Personal Data (as defined in the DPA) on Eagle Virtual's behalf as part of our hosting and delivery infrastructure.
Cloudflare, Inc. (United States)
- Purpose
- Content delivery network, DNS, DDoS and bot protection (including Turnstile), web application firewall, edge compute, edge storage for the Service's websites, APIs, and application data, Cloudflare Web Analytics for aggregate public-page use and performance reporting, and delivery of transactional customer email (Cloudflare Email Sending) such as welcome, plan-change, and team-invite messages.
- Processing locations
- Primarily the United States and the EEA, on a geographically distributed global edge network.
- Transfer mechanism
- EU–U.S. Data Privacy Framework (plus UK Extension and Swiss–U.S. DPF), with EU Standard Contractual Clauses and supplementary measures as fallback.
- Provider documentation
- Cloudflare Customer DPA · Privacy Policy · GDPR Trust Hub · Cloudflare's own sub-processors
Hetzner Online GmbH (Germany)
- Purpose
- Dedicated server hosting for the Service's API origin and data processing infrastructure.
- Processing locations
- Finland (Data Center Park Helsinki, operated by Hetzner Finland Oy as Hetzner's approved subcontractor). Hetzner's DPA commits to processing exclusively within the EU/EEA for our server location.
- Transfer mechanism
- None required — EU/EEA-only processing under a GDPR Article 28 data processing agreement with Hetzner Online GmbH.
- Provider documentation
- Hetzner DPA (PDF) · Privacy Policy · Data Privacy FAQ
2. Payment and Identity Providers
These providers support sign-in and billing. For parts of that processing (for example, payment fraud prevention, or your Google/Microsoft account itself) they act as independent controllers under their own privacy notices, not as Eagle Virtual's processors.
Stripe, Inc. / Stripe, LLC (United States)
- Purpose
- Payment processing, subscription billing, and invoicing.
- Processing locations
- United States, with Stripe affiliates and service providers in the EU, U.S., and India.
- Transfer mechanism
- EU–U.S. Data Privacy Framework (plus UK Extension and Swiss–U.S. DPF; certifying entity Stripe, LLC), and Standard Contractual Clauses via Stripe's Data Transfers Addendum.
- Provider documentation
- Stripe DPA · Privacy Policy · DPF Policy · Stripe's own sub-processors
Google LLC (United States)
- Purpose
- Sign-in identity provider (Google OAuth). We receive your email address and basic profile data when you choose Google sign-in; our use of that data follows the Google API Services User Data Policy, including its Limited Use requirements.
- Processing locations
- Global (Google maintains servers around the world).
- Transfer mechanism
- EU–U.S. Data Privacy Framework (plus UK Extension and Swiss–U.S. DPF; Google LLC and its wholly-owned U.S. subsidiaries), and Standard Contractual Clauses.
- Provider documentation
- Google Privacy Policy · Data transfer frameworks · API Services User Data Policy
Microsoft Corporation (United States)
- Purpose
- Sign-in identity provider (Microsoft Entra ID / Microsoft identity platform OAuth). We receive your email address and basic profile data when you choose Microsoft sign-in.
- Processing locations
- Global.
- Transfer mechanism
- EU–U.S. Data Privacy Framework (plus UK Extension and Swiss–U.S. DPF), and Standard Contractual Clauses via the Microsoft Products and Services DPA.
- Provider documentation
- Microsoft Privacy Statement · Microsoft Products and Services DPA
3. Public-Website Analytics and Advertising Providers
The providers below receive information when someone visits tagged public pages. This website-visitor and marketing section is separate from Section 1's list of providers that may process Customer Personal Data under our DPA. Eagle Virtual does not send screening submissions, watchlists, or report contents to these tools.
Cloudflare, Inc. — Web Analytics (United States)
- Purpose
- Aggregate page-use, referral, device/browser, approximate-country, and page-performance reporting on selected public website pages. Eagle Virtual uses the reports to understand and improve eaglevirtual.com.
- Information processed
- Public-page and performance information. Cloudflare states that Web Analytics does not use cookies or local storage for usage measurement and does not track individuals across its customers' sites.
- Processing locations
- Cloudflare's geographically distributed global network.
- Provider documentation
- Web Analytics documentation · Privacy Policy · Cloudflare Customer DPA
LinkedIn Corporation (United States)
- Purpose
- LinkedIn advertising measurement, aggregate professional audience insights, website retargeting, and related advertising-service improvement on selected public website pages, including public token pages. Eagle Virtual receives aggregate reports rather than the identities of individual LinkedIn members.
- Information processed
- Tagged-page URL, referrer, IP address, browser and device characteristics, timestamp, and potentially limited page-interaction data. Depending on region, browser settings, LinkedIn settings, and our LinkedIn configuration, LinkedIn may use cookies or other identifiers. Our current site code does not enable enhanced matching or send email addresses through the tag.
- Processing locations
- United States and other locations described in LinkedIn's privacy and data-transfer documentation.
- Transfer mechanism
- LinkedIn's published data-processing and international-transfer terms, including applicable data-transfer frameworks and Standard Contractual Clauses.
- Provider documentation
- Insight Tag FAQ · Privacy Policy · Data Processing Agreement · Ads Agreement
4. What Is Not on This List
- Our own infrastructure. Eagle Virtual operates its own internal systems and a self-hosted mail server for internal and operational email; first-party infrastructure is not a subprocessor. Customer-facing transactional email (for example, welcome, plan-change, and team-invite messages) is delivered through Cloudflare Email Sending, which is covered under Cloudflare in Section 1.
- Customer-configured delivery integrations. Alerts and exports you route to destinations you set up — for example, a custom webhook URL you provide, or a Slack workspace you connect — are sent to destinations you choose and control. For a custom webhook, you are the party sending data to your own endpoint. Where you connect a third-party application such as Slack, that provider processes the delivered notification data under its own terms; we will list any such provider here as a subprocessor if and when it processes Customer Personal Data on our behalf.
- Other analytics and advertising vendors. Other than Cloudflare Web Analytics and the LinkedIn Insight Tag described above, Eagle Virtual does not currently load another third-party analytics or advertising service on its public website.
- Public data sources. Government sanctions list publishers, public blockchains, and public databases are data sources, not processors of Customer Personal Data; see Data We Publish.
5. Change Notice and Objections
We will update this page at least 30 days before a new subprocessor begins processing Customer Personal Data (except emergency replacements needed for security or continuity, which we will post as soon as practicable). Customers can subscribe to change notifications by emailing privacy@eaglevirtual.com with the subject "Subscribe: subprocessor updates". Customers may object to a new subprocessor on reasonable data-protection grounds within 30 days of the update, as described in Section 6 of the Data Processing Addendum.
6. Change Log
- 2026-08-10: Disclosed Cloudflare Web Analytics and the LinkedIn Insight Tag, their public-page purposes and information flows, and clarified that website analytics and advertising providers are separate from the Customer Personal Data subprocessor list in the DPA.
- 2026-06-19: Clarified that Cloudflare also delivers transactional customer email (Cloudflare Email Sending). No new subprocessor was added; the list of providers is unchanged.
- 2026-06-09: Initial list published (Cloudflare, Hetzner, Stripe, Google, Microsoft).
7. Contact
- Privacy: privacy@eaglevirtual.com
- Legal: legal@eaglevirtual.com
- Address: Eagle Virtual LLC, 8586 Potter Park Dr, Sarasota, FL 34238, United States