Subprocessor List
Last updated: July 2026
Nexolve uses the following third-party services (subprocessors) that may process personal data on our behalf. We have Data Processing Agreements in place with each vendor. This list is updated when we add or remove a subprocessor.
| Vendor | Purpose | Data processed | Location | Compliance |
|---|---|---|---|---|
| Supabase | Database and authentication | All structured assessment data, responses, reports, and user records | EU (West Europe) | SOC 2 Type II, GDPR-compliant, ISO 27001 |
| Vercel | Application hosting, serverless functions, and AI Gateway (LLM routing) | All application traffic; assessment data passed through AI Gateway to LLM providers | Global (CDN); primary compute in nearest region | SOC 2 Type II, GDPR-compliant, ISO 27001 |
| Stripe | Payment processing | Billing information, payment card details. Nexolve does not receive or store card data. | US / EU | PCI DSS Level 1, SOC 1 Type II, GDPR-compliant |
| Resend | Transactional email delivery | Email address, email content (report delivery, audit reminders) | US / EU | SOC 2 Type II, GDPR-compliant |
| Anthropic (via Vercel AI Gateway) | AI model inference — report generation and chat | Assessment responses, agency context passed to claude-sonnet-4-6 for report writing | US | SOC 2 Type II, GDPR-compliant. Data not used for model training under enterprise terms. |
| OpenRouter | AI model routing (used in questionnaire chat endpoint) | Chat messages and assessment context | US | Zero data retention option enabled. See OpenRouter privacy policy. |
| Google (Sheets API) | Personalised action plan delivery | Agency name and recommended actions written to a client-specific Google Sheet | EU (data residency configured) | ISO 27001, SOC 2, GDPR-compliant |
Questions about this list or our data processing practices? Email vincent@nexolve.co.uk.