Current evidence and verification state
| Service | Purpose and data | Operational note |
|---|---|---|
| Clerk | Authentication, account identity, organisations, sessions, and security. | Used for account access and security. Configuration details may vary by released authentication feature. |
| Convex | Application data, workflows, permissions, search metadata, billing state, and audits. | Used for FurDrive application data and workflows. |
| Cloudflare R2 | Source files, previews, and file-lifecycle operations. | Used for eligible stored files and lifecycle operations. |
| Autumn and Stripe | Entitlements, checkout, subscriptions, purchases, invoices, and payments. | Used when the related billing or entitlement feature is active. |
| Resend and Twilio | Email or SMS, inbound material, notifications, and delivery events when enabled. | Used only when the related communication feature is enabled. |
| Approved OCR or AI provider | Selected files or text, prompts, outputs, model metadata, and errors when eligible. | Used only for eligible processing. The active provider and model may change as service arrangements are updated. |
Controller and processor obligations
Where a provider processes personal data for FurDrive, the Article 28 assessment must confirm sufficient guarantees and a binding agreement covering documented instructions, confidentiality, security, subprocessors, rights assistance, breach and DPIA support, deletion or return, and audit information. Independent-controller relationships must be identified separately.
International transfers
Where GDPR applies, sending personal data from the EEA to a third country requires a documented Chapter V basis. Depending on the destination and mechanism, FurDrive may need standard contractual clauses, a transfer impact assessment, supplementary measures, and transparent notice. Mere global availability or a provider's marketing statement is not enough.
Details required before publication
- Legal entity, service, and controller or processor role.
- Purpose, data categories, and lawful instructions.
- Processing and storage locations.
- Article 28 terms, subprocessor process, Chapter V mechanism, and safeguards.
- Retention, training use, human access, security, incident support, rights support, and deletion.
Keeping the register current
Provider changes must be checked against the data map, Article 30 record, contracts, transfer assessment, DPIA, Privacy Policy, cookie register, store declarations, notices, and consent before activation.