Sub-processor List

GCN.ONE — Encrypted File Transfer & Storage Service

Version: 1.0  |  Effective Date: 2026-07-28  |  Last Updated: 2026-07-28

This page lists every third party that ORBCORE LTD engages to process personal data on our behalf, in line with GDPR Article 28. Each is bound by a data processing agreement, acts only on our documented instructions, and is listed here before it begins processing.

This is not a summary of the list — it is the list. The table below is generated from the same record that produces Annex 2 of the Data Processing Agreement our customers sign, so the two cannot disagree.

Questions about anything on this page: privacy@gcn.one.

Current sub-processors

Sub-processorPurposeLocationContactTheir DPA
Infrastructure hosting provider Physical server hosting, network services, managed MongoDB. BG office@orbcore.com
MaxMind, Inc. (GeoLite2-City database) Local IP-to-city geolocation database. The database is downloaded to our servers; customer IPs are never transmitted to MaxMind at lookup time. US privacy@maxmind.com View
SMTP email relay Transactional email delivery (email verification, notifications). BG office@orbcore.com
Stripe Payments Europe, Ltd. Payment card processing, fraud detection, billing, subscription management. IE privacy@stripe.com View

Where a sub-processor sits outside the EU or UK, the transfer rests on Standard Contractual Clauses supplemented by a Transfer Impact Assessment — see Section 9 of our Privacy Policy. Because file content is encrypted on your device before it reaches us, ciphertext is all any party above could ever hold.


Third parties that are not sub-processors

A short list invites the question of what has been left off it. These are the remaining third parties that appear anywhere in how GCN.ONE is built or served. None is a sub-processor, because none receives personal data — and the reason is given in each case so you can check it rather than take our word for it.

PartyWhat it isWhy it is not a sub-processor
MaxMind — GeoLite2-City IP-to-city database used to show approximate sign-in locations in your security log. The database file is downloaded to our servers and queried locally. Your IP address is never sent to MaxMind — there is no lookup call to make.
Our SMTP relay Sends transactional email: address verification, notifications, delivery receipts. Self-operated on our own domain and our own infrastructure. We do not use a third-party email service, so no third party sees your address or the message.
OpenTimestamps public calendars Independently anchors our audit log so its history can be proven unaltered. What crosses the wire is a 32-byte hash of a Merkle root — no identifiers, filenames, addresses or content. Nothing about it can be traced back to you.
Stripe.js (js.stripe.com) The payment form on our checkout page, loaded from Stripe directly so card details never touch our servers. Stripe is already listed above as a sub-processor for payments. It is named again here because this is a browser-side script: it is the only external resource any page on this site loads, and it loads on the checkout page alone.

Everything else the site needs — fonts, icons, scripts, styles, the CAPTCHA, our databases and our storage nodes — is served from our own infrastructure. There is no CDN, no analytics provider, no advertising network, no social-media pixel and no tag manager. Aside from the payment form noted above, loading any page of GCN.ONE contacts no one but us.


How changes are notified

When we intend to engage a new sub-processor, it is published here before it begins processing, and customers with a signed Data Processing Agreement are notified directly. There is a 30-day window in which you may object, in line with GDPR Article 28(2). Objections are recorded against your account and answered individually; you can raise one from your account or by writing to privacy@gcn.one.

When an engagement ends, the entry is removed from the list above but the record is retained, so it stays possible to establish which sub-processors were engaged during any past period.


Related documents

Business and Enterprise customers can sign a GDPR Article 28 Data Processing Agreement from their account settings once business details are verified. Annex 2 of that agreement reproduces the table at the top of this page.


© 2026 ORBCORE LTD. All rights reserved.