Skip to main content

Processor and data-purpose register

What each evidenced integration may do and what needs production verification.

Source code can show that an integration exists; it does not prove production activation or establish legal entity, role, region, contract, retention, training, or transfer safeguards.

Document status

Effective 27 August 2026

This is an implementation-evidence register, not a final GDPR processor list. Only providers verified in the production data flow may appear in an operative version.

Current evidence and verification state

ServicePurpose and dataOperational note
ClerkAuthentication, account identity, organisations, sessions, and security.Used for account access and security. Configuration details may vary by released authentication feature.
ConvexApplication data, workflows, permissions, search metadata, billing state, and audits.Used for FurDrive application data and workflows.
Cloudflare R2Source files, previews, and file-lifecycle operations.Used for eligible stored files and lifecycle operations.
Autumn and StripeEntitlements, checkout, subscriptions, purchases, invoices, and payments.Used when the related billing or entitlement feature is active.
Resend and TwilioEmail or SMS, inbound material, notifications, and delivery events when enabled.Used only when the related communication feature is enabled.
Approved OCR or AI providerSelected files or text, prompts, outputs, model metadata, and errors when eligible.Used only for eligible processing. The active provider and model may change as service arrangements are updated.

Controller and processor obligations

Where a provider processes personal data for FurDrive, the Article 28 assessment must confirm sufficient guarantees and a binding agreement covering documented instructions, confidentiality, security, subprocessors, rights assistance, breach and DPIA support, deletion or return, and audit information. Independent-controller relationships must be identified separately.

International transfers

Where GDPR applies, sending personal data from the EEA to a third country requires a documented Chapter V basis. Depending on the destination and mechanism, FurDrive may need standard contractual clauses, a transfer impact assessment, supplementary measures, and transparent notice. Mere global availability or a provider's marketing statement is not enough.

Details required before publication

  • Legal entity, service, and controller or processor role.
  • Purpose, data categories, and lawful instructions.
  • Processing and storage locations.
  • Article 28 terms, subprocessor process, Chapter V mechanism, and safeguards.
  • Retention, training use, human access, security, incident support, rights support, and deletion.

Keeping the register current

Provider changes must be checked against the data map, Article 30 record, contracts, transfer assessment, DPIA, Privacy Policy, cookie register, store declarations, notices, and consent before activation.

FurDrive keeps this information separate from veterinary records. These pages describe the service; they do not interpret a pet's health information.

Effective 27 August 2026

Service providers | FurDrive