Skip to main content

Rootsly Trust · v1.0.0

Subprocessor register

A versioned register of platform providers, their bounded purposes, review state, processing information, safeguards and exit or deletion plan.

Not yet effective for a genuine public pilot

This current staging record is visible for review. It does not turn unresolved legal, privacy, retention, provider or consumer wording into an approval.

01

How to read the register

The structured provider records below distinguish staging use, test-only use and production approval. An integration being present in code or staging does not make its privacy, contract, transfer, location or deletion review complete.

Rootsly will not send production personal data to a provider until the register records approval and an effective date. New providers use fixtures or synthetic data while review is pending.

02

Changes and client notice

A material provider addition, replacement, purpose change, processing-location change or safeguard change creates a new register version rather than overwriting the earlier record.

Rootsly will notify client owners before a material subprocessor change where the agreement or applicable requirement calls for notice, allowing the required review or objection route before the effective date.

03

Provider evidence is not Rootsly approval

Provider DPAs, security pages and subprocessor lists are source evidence for Rootsly's review. They do not by themselves settle Rootsly's configuration, subscription eligibility, international-transfer assessment, contractual coverage or fitness for a particular production purpose.

Each approval must identify the exact feature, data categories, account or region configuration, agreement, safeguards, owner, review date and exit process.

Structured provider records

Current staging and test services

Every provider below is still awaiting a recorded Rootsly production review. An external provider statement is evidence for review, not a substitute for approval of the exact Rootsly account and use.

Active in stagingProduction review pending

Vercel

Hosts the Next.js application and runs server-rendering, functions, deployment and delivery infrastructure for the Rootsly web service.

Evidence reviewed
18 July 2026
Next review
18 October 2026
Production effective date
Not approved

Features

  • Application hosting, deployment previews and server functions.
  • Application delivery, request routing and deployment telemetry.

Data categories

  • Application requests and bounded infrastructure metadata.
  • Data handled transiently by Rootsly server functions for the requested feature.

Processing-location information

  • Vercel uses global infrastructure and subprocessors; exact Rootsly region, log and transfer configuration remains part of production review.

Safeguards

  • Published DPA includes technical and organisational measures and UK/EU transfer mechanisms.
  • Rootsly excludes personal answers, report contents, tokens and secrets from routine application logs.

Exit and deletion

  • Remove the Vercel project and environment secrets after a controlled migration to a replacement host.
  • Request or verify deletion under the applicable agreement and retain only justified Rootsly audit evidence.

Agreement status

Vercel publishes a DPA for eligible Pro and Enterprise services; Rootsly account-plan coverage, execution and configuration evidence remain pending.

Material client notice required: Yes

Active in stagingProduction review pending

Supabase

Provides the managed Postgres database, staff authentication and private object storage used by Rootsly.

Evidence reviewed
18 July 2026
Next review
18 October 2026
Production effective date
Not approved

Features

  • Postgres database and row-level security.
  • Six-digit email-code authentication, optional authenticator security and private object storage.

Data categories

  • Tenant, staff, assessment, result, report, consent, support and referral records required by the feature.
  • Private generated reports, permitted photos and temporary exports.

Processing-location information

  • The selected project region stores and primarily processes covered data; support and subprocessors may use other locations under the applicable terms. Exact Rootsly region and transfer review remains pending.

Safeguards

  • Postgres row-level security and server authorisation protect tenant and privileged boundaries.
  • Private buckets, bounded signed access, service-role isolation and provider security controls are part of the shared-responsibility design.

Exit and deletion

  • Export permitted database and private-object data through a controlled migration with checksum and access review.
  • Delete the Supabase project after migration and verify provider deletion or contractual retention handling.

Agreement status

A current Supabase DPA has been identified; Rootsly subscription coverage, account acceptance and final regional configuration evidence remain pending.

Material client notice required: Yes

Active in stagingProduction review pending

Resend

Sends transactional six-digit codes, reports, support updates and controlled operational notifications generated by Rootsly.

Evidence reviewed
18 July 2026
Next review
18 October 2026
Production effective date
Not approved

Features

  • Transactional email delivery and provider delivery-event processing.
  • Suppression and complaint handling required to stop unsafe repeat sends.

Data categories

  • Recipient email address, bounded transactional subject and template content.
  • Provider message identity, delivery, bounce, complaint and suppression status.

Processing-location information

  • Resend states that primary processing operations take place in the United States; exact Rootsly transfer assessment and account safeguards remain pending.

Safeguards

  • Transactional templates minimise content and do not place raw assessment answers or detailed financial data in routine provider metadata.
  • Stable idempotency, suppression checks, webhook verification and bounded retry reduce duplicate or unsafe contact.

Exit and deletion

  • Disable sending credentials and webhooks, migrate required transactional delivery, then close the provider account when safe.
  • Request or verify deletion of customer data and retain only justified suppression and Rootsly audit evidence.

Agreement status

Resend publishes a DPA with transfer safeguards and a subprocessor list; Rootsly account acceptance, plan coverage and production review remain pending.

Material client notice required: Yes

Active in stagingProduction review pending

Cloudflare

Provides DNS and bounded edge or risk controls, including privacy-conscious bot-risk verification before abuse-sensitive operations.

Evidence reviewed
18 July 2026
Next review
18 October 2026
Production effective date
Not approved

Features

  • Domain Name System and edge delivery controls.
  • Risk-only Turnstile verification before selected paid, email or security-sensitive effects.

Data categories

  • DNS and request metadata handled by the configured Cloudflare service.
  • Risk-verification token and provider response; the adapter does not use the response as homeowner identity or marketing data.

Processing-location information

  • Cloudflare operates a global network and publishes its subprocessor locations; exact Rootsly product configuration and transfer assessment remain pending.

Safeguards

  • Only the bounded provider risk response is retained for the abuse decision; no advertising profile or session replay is introduced.
  • Provider secrets and verification calls stay server-side.

Exit and deletion

  • Migrate DNS and any enabled edge or risk functions before removing Cloudflare configuration and credentials.
  • Verify provider data deletion or expiry for the services actually enabled under the applicable agreement.

Agreement status

Cloudflare publishes a current customer DPA and subprocessor list; Rootsly account acceptance, service scope and production review remain pending.

Material client notice required: Yes

Test or fixture use onlyProduction review pending

Chimnie

Supplies property facts, address selection and automated valuation evidence for a bounded assessment lookup.

Evidence reviewed
18 July 2026
Next review
18 August 2026
Production effective date
Not approved

Features

  • Property search and report data used as sourced, dated evidence.
  • Automated valuation range or estimate where the approved product and licence allow it.

Data categories

  • Selected address or provider property identity needed for the lookup.
  • Provider-returned property facts, valuation evidence and transaction metadata required for cost control.

Processing-location information

  • Provider processing location and any international-transfer mechanism have not yet been approved for Rootsly production use.

Safeguards

  • Only the free sample postcode, fixtures or synthetic data may be used while approval is pending.
  • Paid calls are server-side, rate-limited, cached, cost-attributed and kept out of preview or fixture effects.

Exit and deletion

  • Disable the API credential and paid-call capability, preserve only licensed and justified derived evidence, and remove raw cache according to the approved agreement.
  • Replace provider facts with homeowner-entered or alternate approved evidence without rewriting historical source identity.

Agreement status

API terms have been identified, but the exact website/business licence, DPA or processor role, derived-data rights, public display permissions and production safeguards require written review.

Material client notice required: Yes

Current and replaced versions are retained as separate records. A replacement never silently rewrites the version previously shown or accepted.

See all Trust versions