Effective date: 29 September 2026
Schedule version: 2026-09-23-searchapi · recorded with the Customer’s acceptance of the Terms and Schedule A
1. What this schedule covers
1.1 Customer data
This schedule identifies providers engaged by RMVG TECH, LDA, trading as aiwrness, that may receive personal data to deliver the Service. For Customer-controlled workspace data, the authorised subprocessors below form Annex 3 to the Data Processing Agreement in the Terms. A provider receives only data needed for its function; listing it does not mean it can access every workspace.
1.2 Other recipients
Some suppliers process data for their own legal or direct-customer purposes. They are identified separately below and are not appointed as subprocessors for those purposes. The Privacy Policy explains our controller activities and the rights of affected people.
2. Authorised subprocessors
| Provider and contracting entity | Function and data involved | Main location and transfer safeguard |
|---|---|---|
| Supabase Pte. Ltd. | Database, authentication and backend; account, workspace, prompts, answers and service records | Primary project in Ireland; Singapore contracting entity and possible support access. EU Standard Contractual Clauses (SCCs), processor-to-processor. Transfer assessment pending |
| Cloudflare, Inc. | Hosting, delivery and edge functions; IP addresses, request metadata and domains submitted to our favicon endpoint | United States; EU-U.S. Data Privacy Framework (DPF), with SCC fallback |
| Microsoft Ireland Operations Limited | Business and support email; contacts, messages and attachments | Ireland; EU/EFTA tenant data location, with safeguards for onward transfers under Microsoft’s DPA |
| Plus Five Five, Inc. (Resend) | Transactional and service email; addresses, message content and delivery records | United States; EU-U.S. DPF, with SCC fallback |
| OpenAI Ireland Limited | Supported AI answers, suggestions and classification; prompts, context, answers and batch files | Ireland; onward transfers under its DPA |
| Google Cloud EMEA Limited | Paid Gemini Developer API, configured through Google AI Studio; prompts, context, answers and search-supported source metadata | Ireland contracting entity; processing may occur elsewhere. Google DPA for Products Where Google is a Data Processor, including Appendix 3A transfer safeguards |
| Anthropic, PBC | Claude answers and supported batch/search functions; prompts, context and results | United States; processor-to-processor SCCs. Transfer assessment pending |
| Perplexity AI, Inc. | AI answers and search/fetch functions; prompts, context, results and source metadata | United States; EU-U.S. DPF, with SCC fallback |
| SpaceXAI LLC | Grok answers and supported batch/search functions; prompts, context and results | United States; processor-to-processor SCCs. Transfer assessment pending |
| SearchApi, LLC | Google AI Overview retrieval; prompts/queries, market and language parameters, returned answers and source links | United States; DPA applies automatically and incorporates EU SCCs, Module Three for Customer-controlled data and Module Two for our controller data. Transfer assessment pending |
| Ordem dos Contabilistas Certificados (TOConline) | Certified invoicing; billing identity, tax identifiers and transaction records | Portugal; no third-country transfer for our disclosure |
2.1 Google API qualification
The paid Gemini Developer API is governed by the Gemini API Additional Terms and the processor DPA named above. Google may retain prompts, context and output from search-supported requests for 30 days under the product terms; this is distinct from our workspace retention.
2.2 Supplier changes
We give the account contact 30 days’ prior notice of a new or replacement subprocessor, identify its function, location and transfer safeguard, and publish an updated schedule. The Customer’s objection rights and urgent-change process are in Schedule A, Section D5. A later schedule version does not silently amend the version accepted with the Terms.
3. Payments and other recipients
Stripe Payments Europe, Limited receives billing and transaction data in Ireland. It is a processor for specified functions such as tax calculation and an independent controller for payment, fraud and regulatory duties. Onward transfers are governed by its data protection terms. Our certified accountant and competent authorities receive fiscal records under their professional or statutory duties.
Customers may choose Google or GitHub sign-in or connect an external AI assistant. Those services may process data under the user’s separate account relationship; selecting one does not automatically appoint it as our subprocessor.
Some application assets may still load from Simple Icons, flagcdn and jsDelivr, which can receive visitor connection data. Website fonts are served locally. The website does not send domains typed into its free-report form to an external favicon service; application favicon requests are made by our server. Browser storage is summarised in the Privacy Policy, pending a separate production inventory.
4. Transfers and requests
Where we disclose data outside the EEA, the applicable safeguard is an in-scope EU adequacy decision (including the DPF for a certified recipient) or the EU SCCs with any required assessment and supplementary measures. A provider’s EEA contracting address does not guarantee EEA-only processing. We keep the underlying supplier agreements, scope checks and transfer assessments internally; you may request information or available copies of safeguards at [email protected], subject to appropriate protection of confidential information.
This schedule is reviewed when a provider is added or replaced, when a provider notifies us of a material change, and at least annually.