# VenturePath Subprocessor Register: Owner and Counsel Review Copy

**Version:** 0.3 · **Review date:** 16 August 2026

The production register must identify the contracting entity, service, purpose, data, processing location, transfer safeguard, status, and change date. Vendor branding alone is not enough.

| Provider | Purpose | Data | Location/transfer | Status |
|---|---|---|---|---|
| OpenAI Sites / associated hosting infrastructure | Public early-access hosting and delivery | Public interface assets; ordinary technical/security logs | `[CONFIRM CONTRACTING ENTITY, LOCATIONS, TERMS]` | Active for public delivery; complete vendor record before broader public launch |
| Supabase | Authentication, Postgres database, authorization and private profile-image storage | Accounts, workspace records, profile images, consent receipts, preferences and audit metadata | Singapore (`ap-southeast-1`); complete current DPA/transfer review | Active for controlled account access |
| Transactional email provider | Verification, recovery, invitations, service notices | Name/email, message metadata, template fields | `[SELECT/CONFIRM]` | Not selected |
| AI provider(s) | User-invoked research/challenge/synthesis | Minimum approved/pseudonymized context and output | `[SELECT/CONFIRM TERMS, RETENTION, TRAINING, REGION]` | Not connected |
| Sentry | Browser error monitoring and incident investigation | Scrubbed exception, stack, browser and route metadata; no session replay, request body or account identity by configuration | US ingestion endpoint; confirm contracting entity, DPA, retention and transfers | Configured for controlled release |
| PostHog | Optional consented feature-adoption analytics | Allow-listed event and limited browser/device metadata plus opaque account ID; excludes venture answers, interview content, email, display name, IP enrichment and session replay | PostHog Cloud US; confirm DPA, retention and transfers | Configured; capture remains off until individual opt-in |

Before activation: due diligence, written processor terms, security review, least data, region/transfer assessment, deletion/return, breach obligations, subprocessor controls, and privacy-notice update. Material additions require advance notice and a reasonable objection/termination mechanism for business customers.
