iAdvize

Sub-processors

Version 2026-09-30

This page lists every third party that processes data on our behalf to provide the AI Shopping Assistant. It covers the assistant, its dashboard and its APIs.

Each entry names what the provider does for the service, what it actually sees, and where. Where a provider processes data outside the European Union, this page says so.

How we change this list

  • Notice. We tell you before a new provider starts processing your data, at least ⚠ TODO legal: notice period.
  • Objection. You can object during that period on reasonable data protection grounds. We then look for a solution with you, and if we cannot find one you can terminate the affected part of the contract.
  • This page is the record. When the list changes, this page changes and its version date at the top moves.

Infrastructure and hosting

ProviderWhat it does for the assistantWhat it processesWhere
Vercel Inc.Runs the application: the shopper chat surface, the merchant dashboard and the APIs. Stores the images uploaded to it: organisation and site logos, favicons, assistant avatars, and the profile picture a member of your staff uploads. Routes model calls through its AI Gateway. Measures the audience of our website and dashboard, and the real-user performance of every page the application serves, the shopper chat surfaces included. It measures no audience on the shopper chat surfaces, and nothing at all on the shopper privacy notice.Everything the application handles in the course of a request, including conversation content in transit, and the uploaded images above. For the measurement: the page address without its query string (on a shopper chat surface, only the route, with no site key), the referring site, approximate location, device and browser type, and page-performance timings. No cookie, and no identifier kept beyond 24 hours.Application compute is pinned to Frankfurt. Five parts of the platform are not confined to it: the routing middleware that runs on every request, the control plane, backups, the image CDN, and the audience and performance measurement. See "Where data leaves the European Union".
Neon, LLCThe database. Everything the product stores durably lives here.Organisations, sites, agents and their versions, conversations and their messages, measurement events, audit log entries, and the encrypted credentials for any commerce connector you configure.Frankfurt.

AI model providers

Model calls leave our infrastructure through Vercel's AI Gateway, which routes them to the provider serving the model in use. Two providers serve models today.

ProviderWhat it does for the assistantWhat it processesWhere
Anthropic PBCGenerates the assistant's replies on every engine tier but the lightest. Also runs the product's own text-generation work: the site analysis at onboarding, the assistant-instruction generator, the evaluation judge, and the composition of our product newsletter.For a shopper turn: the messages, the assistant's previous replies, the configured instructions, and the results of any tool the agent used. For the other work: your site name and address, the instructions you are authoring, your evaluation scenarios, and our own changelog entries.We pin no region on our model calls, so the Gateway chooses the endpoint and we do not record which one it used. Vercel documents a European inference zone and per-provider overrides, so this is a setting we have not yet made rather than an option we lack. ⚠ TODO legal: the region to require, and whether to record the one each call actually used.
OpenAI OpCo, LLCGenerates replies on the lightest engine tier. Also reads conversations after the fact to label their quality: whether the shopper's need was met, and whether the replies stayed accurate, on brand and within the agent's instructions. This covers shopper conversations and the test conversations your team has in the Playground, except a conversation whose shopper objected to measurement, which is not labeled. The labels are stored with each conversation and are shown in the dashboard, on the conversation page and as filters on the conversations list. They are also readable over the REST API.For replies: the same shopper conversation content, for agents configured on that tier. For quality labeling: the conversation's messages and the results of the tools the agent used, and the configuration of the agent that answered: its instructions, the tools it had, and your site information and tone of voice.Replies: no region is pinned and none is recorded, as above. Quality labeling: pinned to the Gateway's European inference zone. A call no European endpoint can serve fails rather than moving to another region, and the region that served each call is recorded. This provider was also added after our residency baseline was written and has not yet been recorded in it.

What we can state about retention and training, and what we cannot. Zero data retention and a no-training instruction are enabled on the Gateway and asserted in our own code on every model call we make, which we can demonstrate. Whether the corresponding contractual commitment runs through our agreement with each provider or through Vercel's is ⚠ TODO legal: contracting party and data-processing terms for model inference. We would rather say that than imply a contract nobody has produced. One limit is OpenAI's own: under zero data retention it still keeps requests its abuse-detection systems flag, under its own policies, and possibly outside the region we pin.

Supporting services

ProviderWhat it does for the assistantWhat it processesWhere
WorkOS Inc.Identity for the people who use the dashboard: sign-in, multi-factor authentication, organisation membership, invitations.Your staff's email address, name, profile picture, chosen language and time zone, and which organisation and role they hold. No shopper data.United States.
ParallelResearches your brand on the web during the site analysis we run at onboarding, and when you ask the dashboard to regenerate your site information. This runs for every merchant and is not something you switch on.Your site name and address, and the search queries the model derives from them. Never conversation content.⚠ TODO legal: processing location, and the data-processing terms. We reach this provider through the Gateway's built-in web-search tool rather than an account of our own, so the contracting party is itself part of the question.
Upstash Inc.Runs our scheduled and background work: the site analysis at onboarding, agent evaluations, the daily retention purge, the product newsletters.Job payloads, which carry identifiers and pointers rather than conversation content.eu-central-1.
Resend Inc.Sends email to your staff: sign-in emails, notifications, and the product newsletters they opt into.The recipient list, each contact's per-topic subscription state and consent record, and the account data, email metadata, logs and API records of every message.Mail can be dispatched from Ireland; all account data, metadata, logs and API records are held in the United States regardless.
LinkupAnswers a web search or fetches a single page, only for agents where you have enabled that capability. Both capabilities are off by default on every agent.A search query derived from the conversation, or one target address.⚠ TODO legal: this provider's EU-processing claim did not survive a check against its own primary sources, and it offers no zero-data-retention arrangement we hold today.
Google LLCMeasures how much our tag costs your storefront's performance, through the PageSpeed Insights and CrUX APIs.The public address of a storefront page. No personal data of yours or your shoppers'.No European endpoint exists for either API.

Where data leaves the European Union

Everything the product stores durably about your shoppers and your business is stored in Frankfurt, in the database. Outside that, these are processed or held elsewhere:

  1. Model inference. We pin no region on the assistant's replies or on the product's other text-generation work, so the Gateway picks the endpoint and we do not record which one it picked. Until we require a region, assume the content of a conversation may be processed outside the European Union. The quality labeling of conversations, shopper conversations included, is the exception: it is pinned to the European zone (see the OpenAI row).
  2. Web research at onboarding. The search provider above receives your site name, address and derived queries.
  3. The identity of your staff. WorkOS holds it in the United States.
  4. Email. Resend holds the recipient list, the subscription state, the consent record, and the metadata and logs of every message in the United States.
  5. Session and authentication processing on every request. Our routing middleware runs in every region of Vercel's network regardless of where the application's compute is pinned.
  6. The platform control plane, backups, and request logging. Vercel operates these globally. There is no regional setting for them: the region we pin governs where the application's own compute runs, and nothing else. ⚠ TODO legal: their location, which is answered by Vercel's own data processing agreement and sub-processor list rather than by anything we can configure or observe.
  7. Uploaded images. The images listed in the Vercel row are served from a global CDN and cached at its edges, so an organisation logo or a staff profile picture is delivered from wherever the reader is.
  8. Audience and performance measurement of our own pages. Vercel processes it outside the region we pin, ⚠ TODO legal: in the United States according to its data processing agreement, to confirm with Vercel. It is used for aggregate statistics only and carries no cookie and no identifier kept beyond 24 hours. The page address is sent without its query string, a shopper chat page is reduced to its route with no site key, and the shopper chat surfaces send performance timings only, never audience. The shopper privacy notice sends nothing at all. Nothing is sent once a shopper has objected to measurement. An objection your consent tool signals after the assistant panel was first opened on a page takes effect on the shopper's next page load, whether the panel is open or closed at the time: until then, the panel already loaded on that page can keep sending performance timings.
  9. Storefront performance measurement. A public page address goes to Google. No personal data.
  10. Web search or page fetch during a conversation, where you have enabled it on an agent version. A derived query or a single target address goes to the search provider, never the conversation. Off unless you switch it on, and the provider's European-processing claim is the one the table above could not corroborate.

"Pinned to Frankfurt" describes where the application's own compute runs. It is not a guarantee that nothing about a request ever crosses a border, and the list above is what crosses.

The legal basis for each of these transfers is ⚠ TODO legal: transfer mechanism per provider, to be confirmed alongside the current status of the EU-US Data Privacy Framework.

What this list does not cover

Systems you bring. If you connect your own commerce platform so the assistant can read your catalogue or check an order, that platform is yours and processes your data under your own arrangements with it. The same goes for your consent management tool. They are not our sub-processors.

Anything you have not enabled. Where the table above says a capability is off by default, a merchant who never turns it on sends that provider nothing. The one provider that runs without being switched on is the web research at onboarding, and its row says so.