SUBPROCESSOR REGISTER
Infrastructure providers that may process customer personal data for RYTHM.
Effective 14 August 2026. This register reflects the current Public Beta architecture verified in the RYTHM application and deployment stack. It is updated when a material processor is added, removed, or its role materially changes.
SUPABASE
Production database, authentication, tenant-scoped application data, and related backend infrastructure.
- Data involved: Account identifiers, authentication data, organization/workspace data, application records, and service metadata as required by the enabled feature.
- International transfers: Processing location and transfer safeguards depend on the contracted Supabase service configuration and applicable provider terms.
- Only the data reasonably necessary for the enabled service capability should be sent to this provider.
VERCEL
Web application hosting, deployment, delivery, runtime execution, and platform infrastructure.
- Data involved: HTTP/request metadata, application runtime data, deployment logs, and content required to deliver the service.
- International transfers: Processing location and transfer safeguards depend on the contracted Vercel service configuration and applicable provider terms.
- Only the data reasonably necessary for the enabled service capability should be sent to this provider.
OPENAI
AI model inference for features that explicitly invoke an AI model, including governed meeting and agent workflows.
- Data involved: Prompts, instructions, relevant workspace context, meeting transcript excerpts, and generated outputs required for the invoked feature.
- International transfers: Processing and transfer safeguards are governed by the applicable OpenAI business/service terms and the deployment configuration used by RYTHM.
- Only the data reasonably necessary for the enabled service capability should be sent to this provider.
CLOUDFLARE
Domain, DNS, routing, security, and email-routing infrastructure used for RYTHM public domains and operational email routing.
- Data involved: Network/DNS metadata and email-routing metadata or message data where the configured routing service handles it.
- International transfers: Processing location and transfer safeguards depend on the Cloudflare services enabled for the RYTHM domain and applicable provider terms.
- Only the data reasonably necessary for the enabled service capability should be sent to this provider.
CHANGES
How subprocessor changes are handled.
- RYTHM will maintain this page as the current public register for the Public Beta.
- Where an executed customer agreement or DPA requires advance notice of a new subprocessor, that contractual notice process controls.
- Customers with a documented objection right should raise a data-protection concern promptly through the Privacy contact so the parties can assess the specific processing risk.
SCOPE
Not every provider receives every customer record.
- Provider access depends on the feature invoked and the data required to operate it.
- The public Demo is synthetic and read-only and is not intended for real customer personal data.
- Customer-authorized integrations may introduce additional processors; those should be reviewed before production activation.
PRIVACY CONTACT
Need a processor or transfer review?
Enterprise customers can request the current processor architecture, DPA terms, and deployment-specific review before submitting sensitive data.