Skip to content
Legal review document

Service providers & subprocessors

A review register for the providers used in your deployment. This is not a finalized contractual list.

Status: legal and operator review required

AI processing

The application supports an AI provider configuration, including OpenRouter. Confirm the provider and model actually enabled, the information sent, retention settings and contractual terms. Do not publish a blanket no-training promise without verifying the configured providers.

Billing and communication

The code includes Stripe billing and Resend email integrations. Confirm which services are enabled in production, their processing purpose, entity, location and agreement before adding them to an approved register.

Hosting, storage and background work

Confirm the actual hosting provider, PostgreSQL service, object storage, background-job infrastructure and monitoring services. A code dependency is evidence of a possible integration, not proof of production use.

Customer-selected integrations

CRMs, scheduling providers, Slack and commerce connections are enabled by workspace administrators. Review each connection’s permissions and data flow and determine the appropriate contractual treatment.

Required register fields

The final register should identify each approved provider, service purpose, information processed, processing location, safeguards and change-notification process.

Ask about this document ↗