Document / 03
Subprocessors
The provider categories currently used to host, secure, process and deliver ASAI Labs Auditing System.
This register reflects the provider categories and transfer descriptions in the current privacy notice. A customer-specific executed agreement or vendor change notice controls where it contains more specific terms.
| Provider | Service role | Data involved | Transfer / location note |
|---|---|---|---|
Cloudflare | Pages and application delivery, Containers/Workers, R2 object storage, queues, image sanitisation and approved image-processing infrastructure. | Application records, images, location data, IP addresses and technical logs as needed for the configured service. | EEA R2 storage jurisdiction; US recipient safeguards use the EU–US Data Privacy Framework where applicable, or SCCs with supplementary measures. |
Neon | Managed PostgreSQL database hosting, backups and recovery. | Account, organization, Store, contact, inspection, notification, location and related application records. | Production database region is configured in the EEA; US recipient safeguards use the EU–US Data Privacy Framework where applicable, or SCCs. |
Resend | Organization-directed transactional email delivery. | Recipient email address, Store or location name, inspection link, scheduled time and delivery records. | United States; EU–US Data Privacy Framework where applicable, or SCCs under the provider DPA. |
Twilio | Organization-directed SMS delivery. | Telephone number, Store or location name, inspection link and message delivery status. | United States and, where necessary, the destination associated with the recipient telephone number; BCRs or SCCs may apply. |
Browser Web Push providers | Delivery of notifications to a device after the user enables Web Push. | Push-subscription endpoint and keys, Protocol identifier, location title and inspection link; payloads are encrypted for delivery. | Destination depends on the browser or device selected; EU–US Data Privacy Framework or SCCs where applicable. |
Better Stack or approved telemetry endpoint | Payload-minimized server security and reliability telemetry. | Limited error and operational data; browser identity and session tracking are disabled in the approved baseline. | The active endpoint and applicable safeguard are confirmed in the current vendor register. |
Intercom | Optional customer-support chat after the user enables it. | Account or Store identifier, name, role, email when available, browser-session details and chat messages. | United States; EU–US Data Privacy Framework where applicable, with SCCs as a fallback. |
OpenStreetMap / Nominatim | Administrator-requested Store-address geocoding. | The address query, IP address and referrer may be disclosed to the geocoding provider by the current browser request. | Used only for requested geocoding; the provider's own terms and privacy notice apply to that external request. |
Change management
Provider updates
ASAI Labs will keep the active provider register versioned and make material changes available through the trust center or a customer channel as appropriate.
Questions
Need a transfer detail?
Ask for the applicable legal entity, processing country or transfer safeguard at privacy@asailabs.com.