1. Core providers
| Provider | Service | Data in scope |
|---|---|---|
| Vercel Inc. | Public-site hosting, server functions, edge delivery, workload identity, and bot protection. | Website requests, public intake in transit, administrator requests, and bounded operational data. |
| Turso / ChiselStrike, Inc. | Managed libSQL database for the marketing intake and review workflow. | Encrypted access and consultation records, workflow state, audit copies, and non-secret outbox records. |
| Amazon Web Services, Inc. and relevant affiliates | DNS, identity, compute, private APIs, encrypted storage, keys, audit and security infrastructure for buyer and seller portals. | Portal identity, customer workspace content, controlled releases, audit evidence, and operational metadata according to the configured AWS region. |
2. Scope
A provider is a subprocessor only where it processes personal data for the INSUJA provider on a customer's behalf. DNS and network routing may not involve stored customer content. Communications, support, or other optional integrations may be added under an order form and will be disclosed before they process customer personal data.
3. Controls
We assess providers for relevant security and privacy capabilities, limit access to the service purpose, require appropriate contractual protection, and use transfer safeguards where needed. Infrastructure access does not grant a provider authority to use customer content for its own advertising or generalized model training.
4. Changes and objections
We may replace or add a provider as the service changes. Where a customer agreement requires advance notice or an objection process, that agreement controls. Customers may ask for the current list, configured region, and transfer mechanism at hi@insuja.com.