Roster review version 2026-10-03. Conditional entries are not a claim of active Customer Content processing. Stripe’s separate billing role is identified below.
Provider roster
Microsoft Azure
- Entity
- Microsoft Ireland Operations Limited, with Microsoft Corporation and applicable affiliates
- Purpose
- API, workers, database, queues, storage, secrets and monitoring
- Data
- Customer Content and operational metadata; shared account, directory and billing metadata
- Location
- Assigned production data plane: Central US or North Europe (Ireland), including regional database backups, storage, queues and telemetry. Shared identity and billing control plane and the single staging environment: Central US.
- Status
- Business account and accepted Microsoft Customer Agreement verified. Production Ireland is a permanent regional environment; workspace access requires its active immutable pin and accepted readiness checks.
- Safeguards
- Incorporated Microsoft DPA, private regional database, encryption and applicable transfer provisions. Regional storage does not imply EU-only processing by every provider.
Cloudflare
- Entity
- Cloudflare, Inc.
- Purpose
- Edge routing, CDN, WAF, website hosting, forms and spam protection
- Data
- Traffic and request metadata; website lead submissions in D1
- Location
- Global edge network; website lead storage has separate configuration
- Status
- Business account acceptance and current DPA reviewed; staging routing and access controls verified.
- Safeguards
- Edge access controls, incorporated provider DPA and applicable Data Privacy Framework or contractual transfer provisions.
Stripe
- Entity
- Stripe Payments Europe, Limited and Stripe Technology Europe, Limited, as applicable
- Purpose
- Separate billing, checkout and subscriptions processing
- Data
- Billing contact, account and transaction metadata; not general delivery evidence
- Location
- Provider processing locations vary with the contracted service
- Status
- Business account acceptance and service terms reviewed. Production billing and Managed Payments depend on their separate commercial activation.
- Safeguards
- Service-specific controller/processor roles, Stripe DPA and data-transfer terms. Stripe is not a universal Customer Content subprocessor.
Resend
- Entity
- Plus Five Five, Inc. (Resend)
- Purpose
- Transactional email, lifecycle notices and report delivery
- Data
- Recipient addresses, message content and delivery metadata
- Location
- Primarily United States
- Status
- Business account and account-signed DPA verified. Controlled Gmail and Outlook delivery and signed callbacks tested on staging.
- Safeguards
- Provider DPA and applicable contractual transfer provisions; signed callbacks and bounded encrypted mail queues. Account-termination deletion is separate from individual-message retention.
PostHog EU
- Entity
- PostHog, Inc.
- Purpose
- Analytics where configured; website analytics is separate from Customer Content
- Data
- Usage events, identifiers and opted-in contact profiles
- Location
- European Union service endpoint; support and onward processing have separate provider terms
- Status
- Signed business DPA verified. Product analytics depend on feature configuration.
- Safeguards
- Event minimization, IP discard in the reviewed project, website consent controls and signed DPA. The configured 30-day replay retention is not a retention limit for every analytics event.
OpenAI
- Entity
- OpenAI Ireland Ltd. for the reviewed EEA business customer
- Purpose
- Optional AI-assisted report narratives and estimate review
- Data
- Feature inputs, validated report facts and prompts
- Location
- Reviewed staging project uses Global residency and Standard Retention
- Status
- Business service terms and incorporated DPA reviewed. Staging credential and disabled sharing verified; production AI is unconfigured.
- Safeguards
- No general-purpose model training without explicit opt-in; reviewed sharing settings disabled; Responses callers set store: false. Standard provider retention is not zero retention or EU-only processing.
Anthropic
- Entity
- Applicable Anthropic contracting entity must be verified before activation
- Purpose
- Optional AI Q&A, grouping and narratives
- Data
- Feature inputs and prompts
- Location
- Provider location and transfer safeguards must be established before activation
- Status
- Conditional and unconfigured in staging and production. Account terms and settings must be verified before Customer Content processing.
- Safeguards
- No activation until processing, training, retention and transfer requirements are verified.
Changes and objections
The published DPA requires at least 30 calendar days’ direct notice to organization owners and administrators before a new or replacement provider processes Customer Content. Notices identify purpose, data, locations, safeguards and the proposed effective date. Owners and admins can record reasonable data-protection objections in organization settings or write to privacy@scopeworth.app. Unresolved objections require mitigation before disputed processing; the applicable agreement addresses termination of the affected service and proportionate refunds.
Website marketing and customer-selected vendors
LinkedIn advertising measurement is website marketing processing described in the Privacy Policy; it is not used for Customer Content. Source systems a customer connects and report recipients it chooses are customer-selected parties, rather than ScopeWorth’s subprocessors.
Last reviewed: 3 October 2026