Effective Date: August 12, 2026 Version: subprocessors-2026-08-12
This list identifies material third-party service providers that may process Customer Personal Data on behalf of FINA1 in connection with the FINA1 Service. It forms part of the FINA1 Data Processing Addendum.
The exact provider used for a particular Customer may depend on the enabled product features and the applicable Order Form.
| Provider | Purpose | Customer Personal Data potentially processed | Primary processing location / region where configured |
|---|---|---|---|
| Vercel | Web and application hosting, serverless/edge execution, deployment infrastructure, protected Preview and application delivery | Account/session request data, device/network metadata, application requests, request metadata, transient Customer Data necessary to serve requests | United States; FINA1 application compute is configured in iad1 where applicable |
| Supabase | Authentication, PostgreSQL database, tenant data, row-level authorization, Vault-backed secret storage, Edge Functions/control-plane processing | Account and organization data, authentication data, consent records, usage/request metadata, customer-bound Source credentials where configured, audit/security records | United States; FINA1 project is configured in us-east-1 |
| Resend | Transactional account and authentication email delivery | Business email address, recipient name where provided, message-delivery metadata, authentication/transactional message content | United States; FINA1 sending configuration uses us-east-1 where supported |
| Stripe | Payment processing, subscription management, customer portal, invoices, and payment-event delivery when billing is enabled for the Customer | Billing contact information, customer/subscription identifiers, transaction and payment status, payment method information collected directly by Stripe | As provided by Stripe under the applicable Stripe data-processing and regional configuration |
Source providers are not FINA1 subprocessors merely because Customer directs access
Independent third-party Sources selected by Customer are not automatically FINA1 Subprocessors. When Customer directs Zenith to transmit a request to an independent Source, that Source ordinarily acts under its own terms and privacy practices. FINA1’s transmission to the Source is governed by the FINA1 Terms of Service and Customer-Directed Source Access Terms.
If FINA1 separately engages a provider to process Customer Personal Data on FINA1’s behalf as part of the Service, FINA1 will classify the provider according to its actual role and update this list as required.
Changes
FINA1 may add or replace a material Subprocessor in accordance with the notification and objection process in the Data Processing Addendum. The current version of this list will identify its effective date.
A change to a provider’s corporate name that does not materially change processing, or an infrastructure-region change that does not materially reduce data protection, does not by itself create a new Subprocessor.