This register reflects the provider categories and transfer descriptions in the current privacy notice. A customer-specific executed agreement or vendor change notice controls where it contains more specific terms.
ProviderService roleData involvedTransfer / location note
Cloudflare
Pages and application delivery, Containers/Workers, R2 object storage, queues, image sanitisation and approved image-processing infrastructure.Application records, images, location data, IP addresses and technical logs as needed for the configured service.EEA R2 storage jurisdiction; US recipient safeguards use the EU–US Data Privacy Framework where applicable, or SCCs with supplementary measures.
Neon
Managed PostgreSQL database hosting, backups and recovery.Account, organization, Store, contact, inspection, notification, location and related application records.Production database region is configured in the EEA; US recipient safeguards use the EU–US Data Privacy Framework where applicable, or SCCs.
Resend
Organization-directed transactional email delivery.Recipient email address, Store or location name, inspection link, scheduled time and delivery records.United States; EU–US Data Privacy Framework where applicable, or SCCs under the provider DPA.
Twilio
Organization-directed SMS delivery.Telephone number, Store or location name, inspection link and message delivery status.United States and, where necessary, the destination associated with the recipient telephone number; BCRs or SCCs may apply.
Browser Web Push providers
Delivery of notifications to a device after the user enables Web Push.Push-subscription endpoint and keys, Protocol identifier, location title and inspection link; payloads are encrypted for delivery.Destination depends on the browser or device selected; EU–US Data Privacy Framework or SCCs where applicable.
Better Stack or approved telemetry endpoint
Payload-minimized server security and reliability telemetry.Limited error and operational data; browser identity and session tracking are disabled in the approved baseline.The active endpoint and applicable safeguard are confirmed in the current vendor register.
Intercom
Optional customer-support chat after the user enables it.Account or Store identifier, name, role, email when available, browser-session details and chat messages.United States; EU–US Data Privacy Framework where applicable, with SCCs as a fallback.
OpenStreetMap / Nominatim
Administrator-requested Store-address geocoding.The address query, IP address and referrer may be disclosed to the geocoding provider by the current browser request.Used only for requested geocoding; the provider's own terms and privacy notice apply to that external request.
Change management

Provider updates

ASAI Labs will keep the active provider register versioned and make material changes available through the trust center or a customer channel as appropriate.

Questions

Need a transfer detail?

Ask for the applicable legal entity, processing country or transfer safeguard at [email protected].