{"subprocessors":[{"active":true,"env_var":"","gating":"always","key":"neon","location":"UK (aws-eu-west-2, London)","name":"Neon (Databricks, Inc.)","note":"","personal_data":"All CRM data: stakeholders, projects, documents, user accounts","purpose":"Managed PostgreSQL database \u2014 the primary data store","transfer_basis":"Data is stored in aws-eu-west-2 (London). The contracting party is Databricks, Inc. (US), parent of Neon, LLC, under the Databricks Master Cloud Services Agreement; the DPA is incorporated rather than separately signed. Databricks, Inc. is certified under the EU-US Data Privacy Framework, its UK Extension and the Swiss-US DPF, with Neon, LLC named as a covered entity \u2014 confirmed against the Data Privacy Framework register on 2026-08-23; due for recertification 2027-08-10."},{"active":true,"env_var":"","gating":"always","key":"fly","location":"London (lhr)","name":"Fly.io","note":"","personal_data":"All data in transit, plus uploaded documents at rest","purpose":"Application hosting and the encrypted document volume","transfer_basis":"Data is stored and processed in the UK (lhr). Fly.io is US-established (Chicago, Illinois), so the arrangement is a restricted transfer: it is covered by Standard Contractual Clauses executed 2026-08-22, under which Fly.io acts as processor. Fly.io retains data for 90 days following termination."},{"active":true,"env_var":"","gating":"always","key":"clerk","location":"United States","name":"Clerk","note":"","personal_data":"Email address, name, authentication events","purpose":"Authentication and organisation membership","transfer_basis":"UK/EU Standard Contractual Clauses"},{"active":true,"env_var":"RATELIMIT_STORAGE_URI","gating":"deployment","key":"upstash","location":"London (lhr), provisioned via Fly.io","name":"Upstash (Redis, provisioned via Fly.io)","note":"Falls back to per-process in-memory counting when unset, in which case no data leaves the application.","personal_data":"A rate-limit key only \u2014 the signed-in user id, or, for requests made before signing in, an irreversible hash of the client IP address. The IP itself is never sent. No CRM content. Counters expire automatically with the rate-limit window.","purpose":"Shared rate-limit counters across application workers","transfer_basis":"Processed in the UK and not replicated outside it. Instance selvatai-ratelimit is primary in lhr with no read regions configured, verified against `fly redis list` on 2026-08-13. Covered by the Fly.io data-processing addendum executed 2026-08-22, Fly being the contracting party for this Fly-managed instance."},{"active":false,"env_var":"","gating":"org","key":"anthropic","location":"United States","name":"Anthropic","note":"Pre-selected in Settings, but used only once your organisation saves its own Anthropic API key. Requests are made on that key and billed to your organisation's Anthropic account.","personal_data":"The text of documents and records included in the request","purpose":"AI features you invoke: email drafting, document Q&A, project insights","transfer_basis":"Your organisation's own agreement with Anthropic \u2014 the account its API key belongs to \u2014 and Anthropic's data processing terms"},{"active":false,"env_var":"","gating":"org","key":"openai","location":"United States","name":"OpenAI","note":"Requests are made on your organisation's own OpenAI API key and billed to that account.","personal_data":"The text of documents and records included in the request","purpose":"AI features you invoke, where an organisation chooses OpenAI (the models behind ChatGPT) as its provider","transfer_basis":"Your organisation's own agreement with OpenAI \u2014 the account its API key belongs to \u2014 and OpenAI's data processing terms"},{"active":false,"env_var":"","gating":"org","key":"bedrock","location":"The AWS region that organisation selects","name":"Amazon Web Services (Bedrock)","note":"","personal_data":"The text of documents and records included in the request","purpose":"AI features, where an organisation chooses AWS as its provider","transfer_basis":"Determined by the selected region; eu-west-2 keeps processing in the UK"},{"active":false,"env_var":"","gating":"org","key":"azure_openai","location":"The Azure region that organisation selects","name":"Microsoft Azure OpenAI","note":"","personal_data":"The text of documents and records included in the request","purpose":"AI features, where an organisation chooses Azure as its provider","transfer_basis":"Determined by the selected deployment"},{"active":false,"env_var":"","gating":"org","key":"openai_compatible","location":"Wherever that organisation hosts it \u2014 including on-premises","name":"Self-hosted or third-party OpenAI-compatible endpoint","note":"Selected by organisations that require inference inside their own boundary.","personal_data":"The text of documents and records included in the request","purpose":"AI features, where an organisation supplies its own endpoint","transfer_basis":"Determined by that organisation"},{"active":true,"env_var":"POSTHOG_KEY","gating":"deployment","key":"posthog","location":"EU host by default (eu.i.posthog.com)","name":"PostHog","note":"","personal_data":"A pseudonymous user identifier and plan/role attributes. Email addresses are deliberately not sent.","purpose":"Product analytics, only after consent is given","transfer_basis":"Processed in the EEA under the default host"},{"active":true,"env_var":"SENTRY_DSN","gating":"deployment","key":"sentry","location":"United States","name":"Sentry","note":"","personal_data":"Stack traces and request metadata; no direct identifiers are sent deliberately","purpose":"Error reporting and diagnostics","transfer_basis":"UK/EU Standard Contractual Clauses"}]}
