Providers, roles, and data locations
This organisation-level register identifies provider categories in the current estate and the limits of the available public evidence. It is not a promise that every provider processes every client's data. The signed build-specific schedule controls for an assessed service.
Neon
Managed PostgreSQL database service when selected for a build
Application and operational records defined by the build
Verified for the referenced Pulse production project: AWS Asia Pacific Singapore
Project-specific. Other builds require separate verification.
Vercel
Web application hosting and delivery when selected for a build
Web requests, application content, deployment and service logs as configured
Build-specific and provider-managed. Exact processing and log locations must be confirmed in the build annex.
Active provider review and build-specific role assessment required.
Railway
Application and worker workloads when selected for a build
Service traffic, application records, configuration metadata, and logs as configured
Build-specific. Exact service region and transfer paths must be confirmed in the build annex.
Active provider review and build-specific role assessment required.
SiteGround
Corporate website and email services
Website, contact, account, and email data associated with the selected service
Provider-managed. Exact mailbox and service locations are not yet confirmed for a universal public claim.
Corporate service. A current authentication limitation for business email remains recorded as an open exception.
Dropbox
Controlled business document storage and collaboration
Business and engagement records placed in the service
Provider-managed. Exact storage and support-access geography is not yet confirmed for a universal public claim.
Applicability and disclosed data depend on the engagement.
Meta
Messaging and channel services when selected by a client
Channel identifiers, messages, media, and interaction metadata as configured
Provider-managed and service-dependent
Exact product, role, purpose, transfer, and retention require build-specific confirmation.
Payment service providers
Payment collection and payment-service administration when selected
Payment, account, transaction, and anti-fraud data determined by the payment flow
Provider and merchant arrangement dependent
The provider may act as an independent controller rather than a subprocessor. The role is assessed per flow and contract.
Specialised processing providers
Media, language, automation, or other advanced functions only when included in a build
Only the data categories and instructions approved for the specific function
Provider, account, and feature dependent
The exact provider, data use, retention, training setting, and transfer path must be disclosed in the build-specific schedule.
A provider is not automatically a subprocessor. Payment providers and other services may act as independent controllers. Each production schedule records the legal role, service, data, purpose, location, safeguards, review status, and open evidence before client approval.