Last updated: 25 September 2026
Draft for review. This document is not yet in force. Details marked "to confirm" have not been checked against the provider's own terms.
When a store uses Supportify, the store is the controller of its customers' personal data and Supportify AS is its processor. These are the companies we engage to process that data on the store's behalf, what each receives, where, and on what basis it leaves the EEA when it does. This list is Annex 3 of our Data Processing Agreement.
Our servers, database and cache run in Amsterdam, in the EU. The AI models that read and write messages mostly run in the United States, so conversation content is processed there, under the safeguards listed for each provider.
Hosting and storage
- Purpose
- Runs our servers and our PostgreSQL databases (Fly Managed Postgres), where all conversations, tickets and settings are stored.
- Personal data
- Everything the Service stores: messages, emails and attachments, contact details, order data looked up in conversations, and merchant users.
- Where
- Amsterdam, Netherlands (EU)
- Transfer safeguard
- Stored in the EU. Fly.io is a US company; its DPA incorporates the Standard Contractual Clauses.to confirm
- Used
- For every store
Upstash (Redis)
Upstash, Inc. (USA)- Purpose
- Cache and message bus: rate limiting, whether a shopper still has the chat open, and passing live chat events between our servers.
- Personal data
- IP addresses (rate-limit counters, kept for minutes), session identifiers, and chat messages in transit (passed through, not stored).
- Where
- Amsterdam, Netherlands (EU)
- Transfer safeguard
- Processed in the EU. Upstash is a US company; its DPA incorporates the Standard Contractual Clauses.to confirm
- Used
- For every store
Tigris
Tigris Data, Inc. (USA)- Purpose
- Object storage for files: attachments to conversations and tickets, return-label PDFs, knowledge-base uploads, and virtual try-on images.
- Personal data
- Files customers send (images, documents), labels with name, address and phone, and photos uploaded for virtual try-on (deleted after 24 hours).
- Where
- Tigris replicates data to the regions it is read from; the region restriction on our buckets is being confirmed.to confirm
- Transfer safeguard
- Standard Contractual Clauses (Tigris DPA).to confirm
- Used
- For every store
- Purpose
- Hosts the merchant dashboard and our website, including the page where a customer follows their support ticket.
- Personal data
- Conversations, tickets and contact details as they are shown to the merchant's team or to the customer; IP addresses in request logs.
- Where
- Server functions in Stockholm, Sweden (EU); static content from Vercel's global edge network.
- Transfer safeguard
- EU-U.S. Data Privacy Framework and Standard Contractual Clauses (Vercel DPA).to confirm
- Used
- For every store
AI models
Anthropic
Anthropic, PBC (USA)- Purpose
- The main AI model (Claude). Writes replies and drafts on every channel, filters spam from social messages, detects language, summarises and analyses conversations, and suggests tags.
- Personal data
- Message content including images and PDFs customers send, email sender and subject, order and customer details looked up during the conversation, and phone call transcripts.
- Where
- United States
- Transfer safeguard
- Standard Contractual Clauses (Anthropic DPA). Anthropic does not train models on API data.to confirm
- Used
- For every store
OpenAI
OpenAI Ireland Ltd (contracting entity) / OpenAI, L.L.C. (USA)to confirm- Purpose
- Turns knowledge-base searches into embeddings; stands in for the main model when it is unavailable; transcribes recorded phone calls; generates virtual try-on images where the store has chosen OpenAI for it.
- Personal data
- Search queries formed from the customer's question; during an outage, the conversation and looked-up order details; call recordings; try-on photos.
- Where
- United States
- Transfer safeguard
- Standard Contractual Clauses (OpenAI DPA). OpenAI does not train models on API data by default.to confirm
- Used
- For every store
TypeSafe AI (Jev)
TypeSafe AI, Inc. (USA)- Purpose
- A classification model. Decides whether an incoming email is from a customer or is spam, and which of the store's tags a case should carry.
- Personal data
- Email sender, subject and body; the text of a conversation or ticket, up to 12,000 characters.
- Where
- United States (TypeSafe runs on Amazon Web Services, Modal, Nebius and CoreWeave)
- Transfer safeguard
- Standard Contractual Clauses, Modules 2 and 3 (TypeSafe DPA, Irish law). TypeSafe does not train models on inputs.
- Used
- Only when the store receives email through a connected mailbox, or uses tags classified by AI
Mistral AI
Mistral AI SAS (France)- Purpose
- The first standby model for the chat widget when the main model is unavailable, and the main model for stores configured to use it.
- Personal data
- The chat conversation, including images customers send and order details looked up during it.
- Where
- European Unionto confirm
- Transfer safeguard
- Processed in the EEA; no transfer
- Used
- For every store
Google Gemini API
Google LLC (USA)to confirm- Purpose
- Generates virtual try-on images, and answers chats for stores that have chosen a Gemini model.
- Personal data
- The photo a customer uploads for try-on and the product it is combined with; for Gemini chat, the conversation and looked-up order details.
- Where
- United States and other Google regionsto confirm
- Transfer safeguard
- EU-U.S. Data Privacy Framework and Standard Contractual Clauses (Google's data processing terms).to confirm
- Used
- Only when the store switches on virtual try-on, or chooses a Gemini model
- Purpose
- Answers chats for stores whose assistant Supportify has set up on a Grok model at the store's request.
- Personal data
- The chat conversation, including images customers send and order details looked up during it.
- Where
- United States
- Transfer safeguard
- Standard Contractual Clauses (xAI DPA).to confirm
- Used
- Only when the store's assistant is set up on a Grok model
Email, phone and notifications
Resend
Plus Five Five, Inc. (Resend) (USA)to confirm- Purpose
- Sends email: ticket updates and verification codes to customers when the store has no connected mailbox, return labels, and notifications to the store's team. Receives email for forwarding addresses and replies to tickets.
- Personal data
- Recipient and sender addresses, names, subject and body of the email and its attachments.
- Where
- Ireland (EU) and United Statesto confirm
- Transfer safeguard
- Standard Contractual Clauses (Resend DPA).to confirm
- Used
- For every store
- Purpose
- The phone channel: phone numbers, calls, voicemail, call forwarding and text messages. For AI-answered calls Twilio uses Google for speech recognition and Amazon, Google or ElevenLabs for the voice. Also sends SMS alerts to the store's team where switched on.
- Personal data
- Caller phone numbers, call audio and recordings (deleted from Twilio once transcribed), the text of spoken replies, and SMS content, which for alerts includes the customer's name and the ticket subject.
- Where
- United States
- Transfer safeguard
- Binding Corporate Rules and Standard Contractual Clauses (Twilio DPA).to confirm
- Used
- Only when the store connects a phone channel, or switches on SMS alerts
Apple Push Notification service
Apple Inc. (USA)to confirm- Purpose
- Delivers push notifications to the Supportify iPhone app used by the store's team.
- Personal data
- Notification text, which can include a customer's name or email address and a ticket subject.
- Where
- United States
- Transfer safeguard
- EU-U.S. Data Privacy Framework and Standard Contractual Clauses.to confirm
- Used
- Only when someone on the store's team signs in to the iPhone app
Google Cloud Pub/Sub
Google LLC (USA)- Purpose
- Tells us that new mail has arrived in a connected Gmail inbox. The mail itself is fetched from the store's own Gmail account.
- Personal data
- The address of the connected mailbox and a change counter. No message content.
- Where
- Google Cloud (region being confirmed)to confirm
- Transfer safeguard
- EU-U.S. Data Privacy Framework and Standard Contractual Clauses (Google Cloud DPA).
- Used
- Only when the store connects a Gmail inbox
Slack
Slack Technologies, LLC (USA)- Purpose
- Supportify's own internal alerts: when several customers of one store report the same problem, and when a store asks us for help.
- Personal data
- Ticket numbers and titles, a summary of the reported problem, and the store's contact email. No full conversations.
- Where
- United States
- Transfer safeguard
- EU-U.S. Data Privacy Framework and Standard Contractual Clauses (Slack DPA).to confirm
- Used
- For every store
Error monitoring and internal tools
Sentry
Functional Software, Inc. (USA)- Purpose
- Error monitoring for our servers, the dashboard and the iPhone app, so faults are found and fixed.
- Personal data
- Error reports, which can contain fragments of a request or of an error message from a connected system (for example an IP address, an order number or an email address), and the name and email of the team member who was signed in.
- Where
- United States
- Transfer safeguard
- EU-U.S. Data Privacy Framework and Standard Contractual Clauses (Sentry DPA).to confirm
- Used
- For every store
- Purpose
- Bug reports recorded by Supportify's own team while investigating a problem a store has reported.
- Personal data
- Screen recordings and screenshots of the dashboard, which can show conversations and customer details.to confirm
- Where
- United States
- Transfer safeguard
- Standard Contractual Clauses (Jam DPA).to confirm
- Used
- Only when our team investigates a reported problem
Return labels on our shipping account
Shipmondo
Shipmondo ApS (Denmark)- Purpose
- Books return labels on Supportify's own carrier account for stores that have returns switched on and no carrier account of their own.
- Personal data
- The customer's name, address, phone number and email, the order number, and the parcel's weight and size.
- Where
- Denmark (EU)
- Transfer safeguard
- Processed in the EEA; no transfer
- Used
- Only when the store uses returns without its own carrier account
ShipEngine
ShipEngine, Inc. (Auctane) (USA)- Purpose
- Books return labels on Supportify's own carrier account for stores that have returns switched on and no carrier account of their own.
- Personal data
- The customer's name, address and phone number, the order number, the first words of the return reason, and the parcel's weight and size.
- Where
- United States
- Transfer safeguard
- Standard Contractual Clauses (ShipEngine DPA).to confirm
- Used
- Only when the store uses returns without its own carrier account
Services a store connects itself
These are not our sub-processors. When a store connects one of them with its own account, we send and receive data through it on the store's instruction, and the store's own agreement with that provider governs how the provider handles it (DPA section 5.5). They are listed so a store can see everything the Service can be connected to.
- E-commerce platforms: Shopify, WooCommerce, Centra, MyStore / Acendy
- Mailboxes and messaging: Google Gmail, Microsoft Outlook / Microsoft 365, Meta (Instagram, Messenger, WhatsApp)
- Team notifications: Slack, Discord, Microsoft Teams, Webhooks to an address the store chooses
- Carriers and shipping: Bring / Mybring, Cargonizer (Logistra), nShift (Delivery, Ship, Returns), Profrakt, Proteria, ShipEngine, Shipmondo, Webshipper
- Warehouses: Ongoing WMS (including warehouses such as Colliflow that run on it), Mintsoft
- Subscriptions, loyalty and marketing: Appstle Subscriptions, Appstle Loyalty, Seal Subscriptions, Klaviyo, Mailchimp, Lipscore
- Helpdesk imports: Kundo (including ongoing sync), Gorgias, Zendesk
- AI assistants the store authorises: Any MCP client the store connects, such as Claude, ChatGPT or Cursor
Changes to this list
We give at least 30 days' notice before a new sub-processor starts processing customer data, by email to each store's account owner and by updating this page. A store may object on reasonable data protection grounds within 14 days of the notice, as set out in section 5 of the Data Processing Agreement. Questions: support@supportify.no.