SUBPROCESSORS

Subprocessors.

To deliver our managed hosting and related services, Schwen Scalability uses a small set of trusted third-party providers ("subprocessors") that may process personal data on our clients' behalf. This page discloses who they are and what each does. It supports our Privacy Policy and any Data Processing Addendum (DPA).

Template — not legal advice. This is a template for review by qualified counsel, not legal advice. Verify the list against your live stack before relying on it.

Provider Register

The specific providers that apply depend on the services you use. "Current" means the provider is used by the live platform, "Consent-dependent" means it is used only after a visitor opts in, "Conditional" means it is used only when configured and selected, and "Planned" means code exists but the integration is not activated.

SubprocessorStatusPurposeData processed
VercelCurrentApplication & website hosting; serverless API hostingHosted site/app content, request logs, and end-user data passing through hosted applications
SupabaseCurrentManaged database & authenticationIntake contact details, transcripts, extracted document text or image descriptions, portal project data, and authentication records
ResendCurrentTransactional email deliveryRecipient email addresses and the content of transactional emails sent on your behalf
GitHubCurrentPrivate project-context and source-code repository hostingAfter verified intake completion: project summary, full intake transcript, extracted uploaded-document text or image descriptions, Project Brain/Graphify seed artifacts, source code, configuration, and repository metadata
AnthropicCurrentAI intake, portal assistant, image description, and pre-call preparationRelevant conversation and project details; extracted text from uploaded text/PDF files; original uploaded images for a one-time description pass; resulting image descriptions
Google Analytics (Google LLC)Consent-dependentPublic-site traffic, engagement, and conversion measurement after visitor consentPublic-page URLs, referral/campaign data, approximate location, device/browser data, and non-content interaction events; no client-portal activity, intake answers, account details, or uploaded files
GoogleConditionalGoogle Sign-In and identity-token verification when configured and selectedIdentity token and verified email; intake may also store the name and profile-image URL returned by Google
CloudflarePlannedDNS & domain management after Stack Factory activationDNS records, domain configuration, and network-level request metadata
StripeCurrentHosted checkout, recurring billing, invoices, and customer billing managementBilling contact details, payment-method metadata, subscription and invoice records, and payment status (we do not receive full card or bank-account numbers)

Notice of Changes

We may add or replace subprocessors as services evolve, and this page is the current public list. There is not yet an automated subprocessor-change notification workflow. If a signed DPA requires advance notice or an objection period, those terms and the notification method must be agreed with the client for that engagement.

Data Processing Addendum

Clients who need a signed DPA governing our processing of end-user personal data can request one at matthew@schwen.me. The DPA incorporates this subprocessor list.

Schwen Scalability · Last updated: July 31, 2026 · schwenscalability.com