SubprocessorsWho processes data in the chain.
Hardly any platform works without specialized providers, so the GDPR requires transparency about who processes personal data on your behalf. Here is what that means and how you get the current AirLST subprocessor list.
What the GDPR requires for subprocessors
Only with authorization
A subprocessor needs the controller's authorization; in practice through the DPA.
Source: GDPR Article 28(2)The same obligations
The subprocessor is bound by contract to the same data protection obligations as AirLST.
Source: GDPR Article 28(4)Responsibility stays
AirLST remains responsible to you for the whole chain.
Source: GDPR Article 28(4)The current list comes with the DPA
We do not publish a copy on the website, so your privacy team always works with the binding, current version.
- 01
With the DPA
The list is part of the documents of the data processing agreement; see GDPR.
- 02
On request
Ahead of your vendor review at kontakt@airlst.com.
- 03
Hosting is known
The platform runs on Amazon Web Services in Germany; see data hosting.


