Governing policy · POL-09

Supplier & Third-Party Management Policy

Version 1.0 · effective 13 July 2026 · owner: Jonny Allum

OwnerJonny Allum
Version1.0 · Effective 13/07/2026 · Review annually (July) and before any new subprocessor
Applies toAll vendors in the service path, and the subprocessor register below

1. Subprocessor register (customer-facing)

This is the authoritative list of parties that may process tenant personal data. It changes only by deliberate decision, recorded here first.

VendorPurposeData touchedRegion / transfer basis
SupabaseDatabase, auth, RLSAll tenant workspace dataProject region (UK/EU pinned); provider DPA
Google CloudThe production VMData in transit through the appVM region (UK/EU); provider DPA
StripePlatform billing + tenant customer paymentsBilling contacts, payment tokens (no PANs held by BizOS)Stripe DPA + SCC/UK addendum
ResendOutbound email (digests, invoices, chases, alerts)Recipient names/emails, message contentProvider DPA + SCC/UK addendum
AnthropicJonnyAI model backendCompact structured signals (POL-05 §3) — no row dumps; not used for trainingProvider DPA + SCC/UK addendum
Twilio (where enabled)SMS/WhatsApp outreach (K-series)Recipient phone numbers, message contentProvider DPA + SCC/UK addendum

Adding a vendor to this table requires: a real need, a DPA reviewed, MFA on the account, the key stored per SOP-09, and — for anything touching tenant data — notice to tenants per the DPA's subprocessor-change clause.

2. Non-processor vendors

Registrar/DNS, GitHub (source code — no tenant data), analytics (must be cookie-light and anonymised), Capacitor/app stores. Same account hygiene, lighter review.

3. Selection and exit rules

  1. No sole hostage. Every store is pluggable behind one contract (local/Supabase today); data must always be exportable in a usable format. A vendor whose exit would strand data fails selection.
  2. Fail-open where customers would be hurt, fail-closed where money or security would leak: billing enforcement fails open (a Stripe outage never locks a paying tenant out); auth and webhook verification fail closed.
  3. Annual review: pricing, security posture (status pages, breach history), and whether each vendor still earns its place.

4. Agency-side suppliers

Contractors, stock-asset licences, fonts, plugins used in client work must be properly licensed for commercial/client use; licences are kept with the engagement record (SOP-11).

← All documents & policiesQuestions? hello@jonnyai.co.uk