INSIGHTS closed operational beta
Subprocessor Register
Version beta-1 · Effective/offered 18 August 2026
This register is presented with the Processor Terms before installation. Installing or directing installation of the property-specific tag accepts general authorisation for this exact version.
| Supplier/service | Purpose | Configured location | DPA |
|---|---|---|---|
| Cloudflare — Workers, KV and Queues | Collection edge, exact-origin configuration and separate operational/security queues | Global edge; dedicated beta resources | Provider DPA |
| Cloudflare — private R2 recovery bucket | Encrypted PostgreSQL/OpenBao recovery retention; no plaintext database or recovery keys | Dedicated EU-jurisdiction bucket | Provider DPA |
| Render — services, PostgreSQL and persistent disk | Runtime services, control/audit database and OpenBao host | Frankfurt; protected, network-isolated beta environment | Provider DPA |
| ClickHouse Cloud | Operational aggregates and physically separated security/model stores | AWS Frankfurt; one replica | Provider DPA |
| Clerk | Administrator authentication, organisation membership and sessions | Provider-managed service; global support access may apply | Provider DPA |
| Vercel | Dashboard hosting, server functions and evidence download | Provider edge and configured project functions; global support access may apply | Provider DPA |
| Microsoft Azure — Key Vault | RSA wrapping operations used to unseal the dedicated beta OpenBao instance | Germany West Central | Provider DPA |
Data and recovery boundary
Operational suppliers receive only the data needed for their stated role. The operational lane retains aggregates rather than visitor or session rows. The separated security lane may process full IP address and bounded request metadata, which expire within seven days. The R2 recovery bucket contains only encrypted recovery artefacts, redacted reports and checksums.
ClickHouse external backup retention does not exist in the closed beta; recovery is provider-managed only. No consented-lane, modelling or partner-OAuth processing is authorised by this register.
Changes and objections
PROVENANCE365 will provide at least 30 days’ notice before adding or replacing an in-scope supplier, except for a documented emergency security change. A Controller may object on reasonable data-protection grounds. If the objection cannot be resolved, either party may terminate the affected INSIGHTS processing and the property will be suspended and offboarded.
Contact
Questions, objections and data-protection enquiries: support@hyceangroup.com