Provider and Subprocessor Register – GardenPilot
Version: provider-register-2026-09-v5
Date: 14 September 2026
This register must remain aligned with the actual production data flow.
A. Processors / technical providers
On the “paid tier” statements for Anthropic, OpenAI and Google: they rest on the operator's declaration regarding its own contractual relationship (3 September 2026) and are supported by our own measured production usage. Re-measured for the period 31 August to 14 September 2026: 1,713 calls (Anthropic), 1,130 (OpenAI), 3,497 (Google) — with not a single quota or billing rejection. The internally maintained cost column is not evidence of the tier: it is computed from our own price table and would be above zero on a free tier as well. Direct evidence would be the respective provider's billing overview alone.
Cloudflare
Purpose: hosting/delivery, CDN, Workers, security/bot protection and Cloudflare Turnstile in invisible mode, protecting the support chat on the contact page
Data: IP/request data, technical browser/device data and function-specific technical content
Role: processor where acting on GardenPilot's instructions; certain independent security/compliance processing may have a different role
Region: global network
Transfers: adequacy decision and/or SCCs as applicable under verified contract terms
Supabase
Purpose: database, authentication, file storage/backend services
Data: account, project, file, authentication and technical data
Role: processor
Region: production project region Frankfurt, Germany; additional support/subprocessor processing under the applicable contract terms
Transfers: verified DPA mechanisms
Amazon Web Services (AWS)
Purpose: cloud infrastructure, Lambda/image processing, technical storage
Data: customer images, generated images, technical payloads and required project data
Role: processor
Region: current GardenPilot production workload in Stockholm, Sweden, where the relevant AWS service is region-bound
Transfers: AWS DPA/applicable mechanisms
Anthropic
Purpose: AI text, chat and vision functions
Data: required text/prompts/project data and, where needed, customer images
Role: processor within the contracted business/API service
Transfers: documented Article 44+ GDPR mechanism
Training/retention: the access used in production is a paid API tier (not a free tier); the training and retention conditions agreed for that tier apply. For the origin of the tier statement see the note at the start of this section.
OpenAI
Purpose: structured AI output, planning/concept text, text embeddings for the agent memory and image generation in the social-media path
Data: required inputs/project data; for image-related functions, where applicable, a signed GardenPilot URL from which OpenAI retrieves the required customer image; depending on URL structure, technical project/user identifiers may form part of the path
Role: processor within the contracted business/API service
Image generation (measured 14 September 2026): image jobs run through our AWS Lambda to the OpenAI image API; the model used in production during the measurement period was gpt-image-2.5-sunburst (2 runs on 11 September 2026 in the social-media path). Two further OpenAI image models are configured as live fallback stages and were not drawn on during the measurement period.
Transfers: verified contract/transfer terms
Training/retention: the access used in production is a paid API tier (not a free tier); the training and retention conditions agreed for that tier apply. For the origin of the tier statement see the note at the start of this section.
Google / Gemini API (AI Studio)
Purpose: AI text, vision, image and planning functions; image generation is by far the largest image path by volume (measured 31 August to 14 September 2026: 740 image runs via Gemini image models, against 2 via OpenAI)
Data: required prompts/project information and, where needed, customer images
Role: according to the terms applicable to the productive Gemini API access; the current production integration uses Gemini API / AI Studio and not Vertex AI
Transfers: verified Google data-processing/transfer terms
Training/retention: the Gemini API access used in production is a paid tier (not a free tier); the training and retention conditions agreed for that tier apply. For the origin of the tier statement see the note at the start of this section.
Resend
Purpose: transactional and lawful marketing email delivery
Data: email address, email content, delivery data
Role: processor
Transfers: DPA/applicable transfer mechanism
Svix (subprocessor of Resend)
Purpose: delivery of Resend event notifications (webhooks) to GardenPilot
Data: recipient email address per delivery event, event type (delivered, opened, bounced), timestamp
Role: subprocessor of Resend, not a processor engaged by GardenPilot. GardenPilot has no separate contractual relationship with Svix; the involvement follows from the Resend contract and its subprocessor list.
Direction of transfer: GardenPilot transmits no data to Svix. Svix delivers Resend's event notifications to GardenPilot; the recipient address forms part of that notification and therefore passes through Svix.
Transfers: via Resend's subprocessor chain
B. Payment provider
Stripe
Purpose: payment processing, fraud prevention, payment/tax compliance
Data: contact, billing, transaction/payment data
Role: depending on the processing step, processor and/or separate controller for Stripe's payment/legal obligations
Transfers: Stripe privacy/transfer terms
C. Marketing providers – only after required consent
Google Ads
Purpose: conversion measurement and, where enabled, remarketing
Data: browser/device data, IP, page/referrer, cookie/click identifiers, conversion events
Activation: only after required consent
Meta Pixel
Provider: Meta Platforms Ireland Limited
Purpose: Facebook/Instagram conversion/reach measurement
Data: browser/device data, IP, page/referrer, _fbp, where applicable fbclid, conversion events
Activation: only after required consent
Role: under applicable Meta Business Tools/joint-controller terms
Microsoft Advertising / Bing UET
Provider: Microsoft Ireland Operations Limited / relevant affiliates
Purpose: Microsoft/Bing conversion measurement
Data: browser/device data, IP, page/referrer, UET identifiers, where applicable msclkid, conversion events
Activation: only after required consent
Role: under applicable Microsoft Advertising terms
D. Not currently listed as active standard subprocessors
Replicate
Not listed as an active standard customer-data recipient while the isolated CAD-plan prototype is outside the normal production customer flow. If activated for real customer data, the DPA/transfer position, Privacy Policy and this Register must be updated before production use.
Re-measured on 14 September 2026: 0 calls in the past 14 days, the last call to the function concerned on 18 August 2026; the two associated usage records are flagged as tests and carry no user reference. The CAD path used in production calls Google only. The access key remains configured — the function is therefore configured but unused.
n8n
Not listed as an active subprocessor while there is no actual production data flow to an n8n service. Historic function/variable/file naming alone is not an active external data transfer.
Re-measured on 14 September 2026: no n8n call in the runtime code, and across all database functions the stored addresses point exclusively to our own Supabase instance and our own domain. What remains are comments.
Google Search Console
Not listed as a processor of customer data. This access is used solely to retrieve aggregated search statistics about our own pages — the request contains the date range, the requested reporting dimension and our own site address, but no customer or user data. It is a retrieval by us, not a transfer to Google. The access is technically separate from the Gemini API access and is listed here only so that “Google” does not conceal two different access paths under one name. Re-measured on 14 September 2026: last retrieval on 11 August 2026, so none at all within the current measurement period.
Meta / Instagram Graph API
Not listed as a recipient of customer data. Through this access GardenPilot publishes and measures its own marketing content in its own Instagram account only; what is transmitted are the image addresses, captions and alternative texts of those own posts, together with metrics retrieved for the own account. The access is in production (measured 14 September 2026: last publication on 11 September 2026, last synchronisation on 13 September 2026). It is technically and contractually separate from the Meta Pixel integration in section C and is listed here so that “Meta” in this register does not conceal two different accesses under one name.
Google Cloud Storage (third-party storage area)
Finding of 14 September 2026, not yet remedied. The application's preview image references (og:image, twitter:image) point to a file in a third-party Google storage area dating back to the application's origins. That file is retrieved by services generating a preview (search engines, social networks, messengers), whose address thereby becomes visible to Google. It is not retrieved by signed-in users during a normal visit to the application. The reference is not an intended data flow and is to be replaced by a file of our own; until then it is listed here, because a measured external retrieval must not go unmentioned.
E. Public-authority recipients – no processing on our behalf
European Commission (VIES / TAXUD)
Purpose: legally required verification of the VAT identification number of business customers
Data transmitted: country code and VAT identification number. For sole traders the VAT identification number is personal data; this is why the recipient appears in this register.
Response stored: validity, reachability, country code, time of the request and the number queried. Company name and address are not stored.
Role: the European Commission acts as a public authority in its own right. It is not a processor; a data processing agreement is neither possible nor required here.
Transfers: none, processing within the EU