UK Pilot · Providers
Service Providers & Data Recipients
These providers may receive or process personal data when needed to provide the Business AI Pilot. Depending on the feature and the applicable provider terms, a provider may act as a processor/sub-processor for Business AI or may act separately as a controller for some processing. The data sent depends on the features a business enables.
| Provider | Purpose | Typical data | Transfer note |
|---|---|---|---|
| Supabase | Database, authentication and private file storage. | Account identifiers, business/customer records, configuration and approved knowledge files. | The Pilot project is configured in an EU region. Provider support or infrastructure may involve other locations; restricted-transfer rules are assessed where applicable. |
| Resend | Transactional authentication email, including signup confirmation, password recovery and account-security messages. | Recipient email address, message content and delivery metadata needed to send the authentication email. | Resend may use infrastructure and sub-processors in multiple locations. Restricted-transfer requirements and contractual safeguards are reviewed where applicable. |
| Vercel | Application hosting, serverless execution, deployment and delivery. | HTTP request metadata and data handled by Business AI server routes. | Provider infrastructure may involve processing outside the UK; appropriate safeguards are required where a restricted transfer occurs. |
| OpenAI | AI processing for customer-enquiry responses and other configured AI features. | Customer messages and relevant approved business context needed to produce a response. | Processing may involve locations outside the UK. Appropriate UK transfer safeguards must be maintained where required. |
| OpenRouter | AI Marketing text generation and model routing. | Marketing requests and trusted business facts needed to create draft social content. | Requests may be routed to underlying model providers. Downstream provider and transfer arrangements must be reviewed as part of the provider configuration. |
| Cloudflare | Workers AI image generation for optional AI Marketing images. | Marketing image prompts based on approved business facts and generated image output. | Cloudflare operates global infrastructure. Restricted-transfer requirements must be assessed and appropriate safeguards maintained where applicable. |
| Stripe | Checkout, subscription and billing management. | Business/account billing identifiers and subscription/payment metadata. Stripe handles payment-card data in its own payment flow. | Stripe's current terms recognise that it may act as processor and/or controller depending on the processing. International transfers are governed by its applicable contractual transfer safeguards. |
| Meta Platforms | Optional Facebook Page connection and publishing. | OAuth/account identifiers, selected Page details, access tokens and approved post content/images. | Only used when the business connects Meta. Meta’s legal role depends on the connected feature and applicable platform terms; those terms must be kept under review. |
Changes
Business AI may add or replace providers as the service changes. Material changes affecting personal data processing will be reflected here and, where appropriate, notified to business owners so they can raise a reasonable data-protection objection.