Snapshot 44977
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Data processing Sub-processors Last updated: October 2026 This page lists the vendors that may process Morphed customer data on our behalf. We give 30 days' notice before adding or replacing a public sub-processor. Partner-specific notice periods, including 14 days for BEE where signed, can be set in a DPA addendum. Customer enabled external MCP providers are controlled by the customer through their own account with that vendor. Morphed governs access, approvals, and audit logs between the agent and the customer enabled provider. Infrastructure Hosting, networking, and storage providers that run the Morphed application. Vendor Purpose Region Transfer mechanism Supabase Postgres database, authentication, file storage, and pgvector retrieval where enabled Frankfurt, Germany or selected EU region EU hosted, no transfer required for primary storage Render Backend application hosting for the Morphed API and worker services Frankfurt, Germany for the EU deployment profile EU hosted for EU profile, SCCs where applicable Vercel Frontend hosting, static assets, and edge delivery EU primary region with global edge delivery SCCs, EU-US Data Privacy Framework Cloudflare CDN, DDoS protection, DNS, and network security Global network with EU controls where available SCCs, EU-US Data Privacy Framework AI and model providers Models are called only with the minimum context required for the approved task. Customer credentials, OAuth tokens, bearer tokens, and API keys are never sent to a model. API data is not used for model training under the applicable provider terms. Vendor Purpose Region Transfer mechanism OpenAI OpenAI EU data residency ↗ LLM inference for governed agent reasoning and document generation where selected EU routing where enabled, including Amazon Bedrock EU geo inference for the BEE workspace; otherwise United States with minimised payloads SCCs, EU-US Data Privacy Framework, no training use for API data Amazon Web Services Bedrock AWS Bedrock EU geo inference ↗ Claude and OpenAI model inference for the BEE workspace where the Bedrock route is enabled EU geo inference profile, starting from Frankfurt EU geo inference route under AWS terms, with no training use of customer data Anthropic Claude model provider behind Amazon Bedrock for the BEE EU route, or direct inference where selected BEE route uses Amazon Bedrock EU geo inference; United States for direct inference unless an approved EU path is selected AWS Bedrock EU route for BEE; SCCs and EU-US Data Privacy Framework where direct Pinecone Vector database for embeddings and retrieval where selected instead of Supabase pgvector EU region where selected EU hosted where selected, SCCs where applicable Supporting services Transactional email and customer authorised integration services. Vendor Purpose Region Transfer mechanism Resend Transactional email for approvals, alerts, sign-in, and service notifications European Union EU hosted, no transfer required for primary email processing HubSpot Customer-facing CRM integration, UI extension surface, and customer authorised CRM operations United States or EU depending on the customer portal SCCs, EU-US Data Privacy Framework Customer-connected MCP providers When a customer connects an external MCP server such as Salesforce, n8n, Slack, Stripe, Gong, Gainsight, Aircall, WhatsApp, SMS, or another provider, that vendor processes data through the customer's own account and contract. Morphed records connector metadata, approval events, tool calls, and verification outcomes. Notification and objection To receive notice of sub-processor changes or to request the DPA, SCCs, AI routing posture, connector list, or Article 30 extract, email [email protected].