Subprocessors
Version 1.0 · Effective 22 July 2026
The subprocessors below help us operate Muster. We review this list periodically and will update the version and date if it changes materially. See our DPA for the terms under which we use them.
| Subprocessor | Purpose | Data category | Region |
|---|---|---|---|
| Vercel | Application hosting & compute | None persisted — requests transit; functions pinned EU | US / EU (EU-pinned functions) |
| Supabase | Database & file storage | All personal data: accounts, enrolments, progress, completions, attestations, uploaded documents | EU |
| Cloudflare | Video hosting & playback (Stream) | Training video content only — no personal data. The record of who watched what lives in Supabase, not Cloudflare. | Global (content delivery network) |
| Resend | Transactional email delivery | Recipient email address, name, and email content (invitations, reminders, digests) | US / EU |
| Stripe | Billing & payment processing | Organisation billing contact and payment details — Stripe is PCI-compliant; we never see full card numbers | US / EU |
Questions about a specific subprocessor, or notice of a proposed change: privacy@example.com.