Formius

Subprocessors

Third parties Formius uses to operate the platform. Locked list for design-partner disclosure.

Version 1.1 · Effective 5 August 2026

Last reviewed 5 August 2026 (C2 locked). Formius may update this list as the stack changes; material additions for design partners will be notified where practical. Source of truth: lib/legal/subprocessors.ts. Related: Privacy Policy · Platform Terms.

Core platform

ProviderPurposeTypical dataHosting
SupabaseDatabase, authentication, storage, realtimeAccount, organisation, and application data; auth sessionsProvider-hosted (project region as configured)
VercelApplication hosting, edge/network deliveryRequest logs, deployment artefacts; app trafficGlobal edge + selected compute regions
ResendTransactional email deliveryRecipient email, message metadata, template contentProvider-hosted
SentryError monitoring and performance diagnosticsStack traces, limited request context (secrets scrubbed where configured)Provider-hosted
UpstashDistributed rate limiting (Redis)Rate-limit keys (IP / org / route identifiers) — not document bodiesProvider-hosted

Optional (when enabled)

These process data only when Formius or an organisation enables the integration or feature.

ProviderPurposeTypical dataHosting
StripePayments / Connect / SaaS billing (when enabled)Billing and payment metadata as configuredProvider-hosted
XeroAccounting sync (optional org integration)Invoices, contacts, and sync payloads authorised by the orgProvider-hosted
FormodusOptional constitutional / estimate runtime bridge (per-org)Payloads an organisation authorises for Formodus featuresProvider-hosted (api.formodus.io as configured)
SanityOptional CMS / structured content (when enabled)Published content and related CMS records — not primary customer job vaultProvider-hosted
OpenAIOptional AI assist features (when OPENAI_API_KEY configured)Prompts/content submitted to AI features onlyProvider-hosted
AnthropicOptional AI assist features (when ANTHROPIC_API_KEY configured)Prompts/content submitted to AI features onlyProvider-hosted
Google AnalyticsOptional marketing / product analytics (when measurement ID set)Pseudonymous usage identifiers and page/event metricsProvider-hosted
Meta (Facebook Lead Ads)Optional lead ingest webhook (when Meta credentials configured)Lead form fields submitted via connected Meta assetsProvider-hosted

Notes

  • Customer-facing portal and quote links are served by Formius on Vercel; document content is stored in Supabase as configured for the tenant.
  • AI features send only the prompts/content you submit for that feature — not a bulk export of your organisation vault.
  • Questions or DPA schedule requests: support@formius.io.
Subprocessors