1. Primary hosting
The application runs on an operator-managed VM physically hosted in Scotland, United Kingdom. The database, document originals, search index and local operational backups are stored there. This is the primary storage location; it does not constrain processing by the external providers below. No separate external application-hosting provider is represented as contracted by this register.
2. Provider register
| Provider | Purpose and data | Location and role |
|---|---|---|
| OpenAI | AI generation and search embeddings: questions, relevant document passages, text being indexed, replies and request metadata. Data-use and retention information. | External AI processor. International processing, including the United States, may occur. No UK-only or zero-retention configuration is promised. The applicable contracting entity is the entity in the operator's OpenAI agreement. |
| Cloudflare | DNS, reverse-proxy traffic delivery, TLS and network security: network identifiers, request metadata and traffic content passing through its services. Cloudflare DPA. | International network and security provider with global infrastructure, including the US. Processor for relevant Customer traffic; some security/account processing may have a separate legal role under its terms. |
| Purelymail / Add Rabbit LLC | Transactional and correspondence email: recipient addresses, email bodies, verification/invitation/recovery links and delivery information. Privacy policy and hosting information. | Email processor. Purelymail identifies its server location as AWS US-East-1 in northern Virginia, USA. Its underlying infrastructure providers form part of its own processing chain. |
| Stripe — when payment services are enabled | Card checkout, subscriptions, invoices, payment identifiers and fraud checks. Company documents are not sent for payment processing. Stripe privacy information. | International payment provider. May act as an independent controller for regulated payment/fraud duties and as processor for other functions under the applicable Stripe agreement. Listed conditionally; this does not mean card checkout is currently enabled. |
Provider identity, actual contracting entities and applicable downstream processing must be confirmed in the relevant agreements. This page does not assert that a provider has a particular certification, that every country is adequate, or that linking its policy executes a DPA or transfer agreement.
3. Changes, safeguards and enquiries
The authorisation, advance-notice and objection rules in DPA section 4 apply to additional or replacement subprocessors. Required international-transfer instruments and assessments must cover the actual processing. Where additional documentation is needed for your use, arrange it before submitting the affected information.
Ask privacy@mycompaniesai.com for processing, location or safeguard information. Send contractual questions to legal@mycompaniesai.com and ordinary service questions to help@mycompaniesai.com. External provider policies explain their services; they do not replace our obligations to you.
You can use your browser's Print or Save as PDF option to keep a copy. For an earlier accepted version, contact legal@mycompaniesai.com.
