Subprocessor and Data Flow Register
Last updated: 30 August 2026
Register date: 30 August 2026
1. Publication principles
This register distinguishes BoardCue production facts from supplier-published facts and from items that remain unverified. A generic supplier capability is not presented as though it were the actual BoardCue configuration.
2. Current supplier register
| Supplier | Purpose | Data | BoardCue status | Published/assurance position | Open action |
|---|---|---|---|---|---|
| Supabase | Authentication, database and document storage | Account data, Customer Content, audit/security data | Production Supabase primary database and document storage: United Kingdom. Enterprise go-live: Pro or higher. | Supabase DPA/transfer controls; Pro daily database backups with current published 7-day access window. | Verify Pro upgrade and Backups screen at enterprise go-live. |
| Google Cloud Vertex AI | Primary cloud AI and embeddings for selected governance tasks | Prompts, retrieved source context, outputs, embeddings and associated request metadata | Direct ADEPTABLE-controlled Google Cloud project, with no intermediary AI gateway. | Google Cloud enterprise DPA/Cloud Data Processing Addendum and applicable transfer safeguards. Configure supported regional processing/data location and do not enable optional customer-data sharing for model improvement. | Account configuration and applicable provider controls are maintained as part of BoardCue supplier assurance. |
| OpenAI API | Selected AI analysis and/or cloud transcription where used | Prompts, retrieved source context, outputs; audio only where cloud transcription is deliberately used | Direct ADEPTABLE-controlled API account, with no intermediary AI gateway. | OpenAI business/API data is not used to train models by default. Applicable DPA and UK transfer provisions must be retained. Standard endpoint retention or approved Zero Data Retention status must be documented accurately. | Account configuration and endpoint retention/ZDR eligibility are maintained as part of BoardCue supplier assurance. |
| Resend | Outbound transactional email | Recipient email, message content, delivery metadata | Production use confirmed. | Supplier DPA and international-transfer safeguards apply. | Maintain annual supplier evidence. |
| Postmark / ActiveCampaign | Inbound intelligence email | Sender/recipient, body, headers, attachments, delivery metadata | Production use confirmed. | Supplier DPA and international-transfer safeguards apply. | Maintain annual supplier evidence. |
| Stripe | Payments/subscriptions | Payer/account identifiers, billing/transaction data | Production use confirmed. Governance Customer Content is not intentionally sent to Stripe. | Stripe DPA/data-transfer arrangements apply. | Maintain annual supplier evidence. |
| Malware-scanning provider | Inbound attachment malware scan, if configured | Attachment bytes | Fail-closed integration exists, but no production provider is verified. | No provider named until configuration evidence exists. | Verify deployed provider before enabling relevant inbound attachment flow. |
3. Browser or operating-system speech recognition
Browser/OS speech recognition is not automatically a BoardCue subprocessor. In the managed Live Board route, BoardCue invokes the speech-recognition capability available in the user's browser/device environment and receives transcript text.
The organisation is responsible for approving and configuring the browsers, operating systems and devices its users may use. ADEPTABLE does not warrant where or how a third-party browser/OS provider processes speech data.
4. Core data flows
1. User -> BoardCue -> Supabase authentication/database/storage (United Kingdom).
2. Authorised AI request -> BoardCue server -> direct Google Cloud Vertex AI and/or OpenAI API under ADEPTABLE-controlled accounts -> response -> BoardCue.
3. Meeting audio -> customer-selected browser/OS speech service -> transcript text -> BoardCue.
4. BoardCue notification -> Resend -> recipient.
5. Sender -> Postmark -> BoardCue inbound route -> quarantine -> configured malware scanner if present -> workspace.
6. Customer -> Stripe -> subscription/payment status -> BoardCue.
5. Public wording rules
Do not state that all BoardCue data stays in the UK. BoardCue's primary Supabase database and document storage are hosted in the United Kingdom. Other suppliers may still process data outside the UK, so BoardCue does not claim that all processing is UK-only.
Do not state zero retention or no model training by downstream AI providers until the direct AI provider route is confirmed end to end.
Do not name a malware scanner as an active subprocessor until production configuration proves it.
Do not present supplier certifications as ADEPTABLE certifications.
6. Source basis
Supabase regions: https://supabase.com/docs/guides/platform/regions
Supabase backups: https://supabase.com/docs/guides/platform/backups
Resend GDPR/DPA: https://resend.com/security/gdpr and https://resend.com/legal/dpa
Postmark EU privacy/DPA: https://postmarkapp.com/eu-privacy and https://postmarkapp.com/dpa
Stripe DPA: https://stripe.com/legal/dpa and Stripe Privacy Center
BoardCue production facts: repository audit dated 30 August 2026 and Supabase production dashboard evidence supplied by ADEPTABLE.
Meeting Effectiveness data flow
Eligible meeting participant -> seven-dimension ratings and optional comments -> organisation-scoped Supabase records -> minimum-three-response suppression and anonymous aggregation -> authorised organisation reporting. Protected participant identifiers enforce eligibility, one response per participant and the seven-day response window.

