Hetzner
cloud-infrastructure · hetzner.com · last read 2026-10-07
Identity
No identity observation recorded yet.
Data location
| Region | EU data location | Minimum plan | Source | Observed |
|---|---|---|---|---|
| EU | EU by default | — | docs.hetzner.com | 2026-10-05 |
EU: Non-cloud products are processed and stored exclusively within the EU, and Hetzner's own customer master, contract and billing data stays in the EU. For cloud products, the storage location depends on the product location the customer chooses (e.g. Falkenstein, Nuremberg or Helsinki); no plan or cost is named.
Subprocessor chain
3 third parties · 3 of the vendor's own group companies · 5 with a country outside the EEA · all read 2026-10-05
| Subprocessor | Country | Purpose |
|---|---|---|
| NTT Global Data Centers Americas, Inc. | US | Colocation-Anbieter am Standort USA |
| NTT Global Data Centers SG1 Pte Ltd | SG | Colocation-Anbieter am Standort Singapur |
| QTS Investment Properties Hillsboro, LLC | US | Colocation-Anbieter am Standort USA |
Hetzner's own group companies listed as subprocessors (3)
| Company | Country | Purpose |
|---|---|---|
| Hetzner Finland Oy | FI | Gebäudevermietung; Technischer Support |
| Hetzner Singapore Pte. Ltd. | SG | Vermietung von Servern am Standort Singapur |
| Hetzner US LLC | US | Vermietung von Servern am Standort USA |
The count outside the EEA is arithmetic over the country column, not a judgement about lawfulness. A transfer outside the EEA can be perfectly lawful; whether this one is depends on your use, not on the vendor.
Assurance
| Scheme | Status | Scope | Source | Observed |
|---|---|---|---|---|
| DIN ISO/IEC 27001:2022 · ISO27001 | Claimed | Hetzner Online GmbH and Hetzner Finland Oy; the infrastructure, operation and customer support of the data center parks in all three locations: Nuremberg, Falkenstein, and Helsinki | hetzner.com | 2026-10-05 |
Claimed means the vendor asserts the scheme on its own page and offers nothing further. Available on request means the report or certificate exists but sits behind a request, a login or an NDA. Neither is a certificate we have seen. That is a distinction an auditor makes, so we make it too.
Official registers
- ACN qualified cloud (Italy): checked 2026-10-07, no entry under Hetzner
- Data Privacy Framework List (US): checked 2026-10-07, no entry under Hetzner
- FedRAMP Marketplace (US): checked 2026-10-07, no entry under Hetzner
What the authority publishes, not what the vendor claims. An entry covers the offering it names and nothing else: a FedRAMP authorisation for a government edition says nothing about the commercial service. No entry is not a finding about security - most vendors never apply - and an entry filed under a name not listed above would not have been found.
Support window
Not yet collected. This row will say not declared only once we have read a lifecycle or security page and found no period stated — see support windows.
Documents
| Document | Disclosure | Transcription | HTTP | Observed |
|---|---|---|---|---|
| certifications | Public | full | 200 | 2026-10-05 |
| residency | Public | full | 200 | 2026-10-05 |
| subprocessors | Public | full | 200 | 2026-10-05 |
History
Nothing has moved since we started watching this vendor on 2026-10-05. Changes appear here only after a human has reviewed them.