Trust Center

Hosting, Infrastructure, and Sub-Processors

At Mimirio, we are built around privacy, control, and deployment flexibility. We know that infrastructure choices are not just technical decisions — they are often driven by regulatory, contractual, security, and data sovereignty requirements.

For that reason, we support multiple hosting and deployment models. The infrastructure providers involved in a customer environment depend on the setup selected for that specific deployment.

Our approach

We do not operate every customer environment on the same cloud or with the same infrastructure provider.

Instead, the applicable infrastructure and hosting sub-processors depend on factors such as:

  • the deployment model selected by the customer
  • the agreed hosting location or region
  • regulatory or procurement requirements
  • performance, availability, and security needs
  • whether the environment is hosted by us, by a partner, or by the customer

This means that not all providers listed below apply to every customer.

Infrastructure providers that may apply

Depending on the agreed deployment, we may use one or more of the following infrastructure providers:

  • Microsoft Azure
  • Amazon Web Services (AWS)
  • STACKIT / Schwarz Digital
  • OVHcloud
  • Hetzner
  • or others

The exact provider or provider entity relevant to a deployment depends on the selected architecture, region, and contractual setup.

Deployment-specific applicability

The infrastructure providers above are potential hosting sub-processors for Mimirio-hosted environments. Which provider actually applies depends on the customer’s chosen setup.

Examples:

  • If a customer chooses an Azure-based deployment, Microsoft Azure may be the relevant infrastructure provider.
  • If a customer chooses an AWS-based deployment, Amazon Web Services may be the relevant infrastructure provider.
  • If a customer chooses a deployment on STACKIT / Schwarz Digital, OVHcloud, or Hetzner, the respective provider may apply.
  • If a customer uses a self-hosted or customer-managed deployment, the relevant infrastructure may be operated directly by the customer or by providers selected by the customer.

Self-hosted and customer-managed deployments

We support deployment models where customers retain a high degree of control over infrastructure.

In self-hosted or customer-managed setups:

  • the customer may select and operate its own hosting environment
  • customer-selected infrastructure providers may apply instead of Mimirio-selected providers
  • the sub-processor landscape can differ significantly from our standard hosted setup

Where an environment is fully operated within the customer’s own infrastructure, the customer’s own hosting choices may determine which infrastructure providers are involved.


Data Residency and Hosting Choice

We understand that data residency and infrastructure jurisdiction matter.

Where relevant, hosting can be aligned with customer requirements regarding:

  • geographic hosting preferences
  • EU or EEA deployment expectations
  • sovereign or region-specific infrastructure strategies
  • internal governance and procurement policies

The exact hosting model and the relevant infrastructure provider are defined on a deployment-specific basis. If a customer requires a specific hosting setup, this is handled as part of the contractual and technical solution design.


Sub-Processor Transparency

We are committed to transparency regarding the sub-processors relevant to our services.

Because our deployment model is flexible, there is no single universal infrastructure sub-processor configuration that applies to all customers.

Instead:

  • some sub-processors are only relevant for certain hosting models
  • some sub-processors are only relevant for specific regions or architectures
  • some deployments may use customer-controlled infrastructure rather than infrastructure selected by us

For this reason, the most accurate view is always the one that reflects the actual deployment chosen for your environment.

If you need the exact sub-processors applicable to your setup, we can provide deployment-specific information upon request or as part of the contracting process.


Security and Access Principles

Our infrastructure and hosting approach is guided by the principle of minimizing exposure and maintaining control.

We design our services around the following principles:

  • least-privilege access
  • need-to-know access controls
  • separation of customer environments where applicable
  • documented operational processes
  • privacy- and security-conscious system design
  • alignment of hosting choices with customer requirements where feasible

Infrastructure providers are selected and used in a way that supports the agreed deployment architecture and applicable contractual requirements.


Contractual and Compliance Handling

Where required, we put appropriate contractual arrangements in place with relevant providers used in connection with the delivery of our services.

The applicable infrastructure provider for a customer deployment may be reflected in:

  • the commercial agreement
  • the order form or statement of work
  • the data processing agreement
  • a deployment-specific sub-processor list
  • customer-specific technical documentation

This ensures that customers receive information that is accurate for their actual environment, rather than a generic list that may overstate which providers are involved.


Customer-Specific Information

If you are a customer, prospect, auditor, or procurement contact and need the exact hosting and sub-processor information for your deployment, please contact us.

We can provide deployment-specific details for:

  • the hosting model used for your environment
  • the relevant infrastructure provider(s)
  • the applicable sub-processors for your setup
  • the data residency approach agreed for your deployment

Contact: hello@mimirio.com