Legal
Subprocessors and service providers
The third-party services integrated into the Expandus platform, and the narrow purpose each one serves.
What this page is, and is not
This page lists the third-party services integrated into the Expandus platform. Listing a service here tells you it can be involved in processing — it does not by itself mean a data processing agreement, transfer safeguard or internal approval has been completed for that service. Contractual and approval status is controlled in our internal subprocessor and DPA register, and we will confirm the position that applies to your engagement on request.
We do not publish processing locations, contractual safeguards or certification claims that we cannot evidence. Where a detail is not stated here, it has not been confirmed for publication rather than being omitted for any other reason.
Always used
These services are part of running the platform, so they can be involved whenever you use it.
Supabase
Always usedHosts the application database, authentication and file storage that the platform runs on.
Data involved: Account and sign-in data, assessment and Blueprint inputs, coordination records, and documents you upload.
Lovable
Always usedProvides the hosting and application runtime that serves the website and the server-side application logic.
Data involved: Request and delivery data needed to serve the application, including technical and log information generated while you use the service.
Used only when a feature or configuration is enabled
These services are not involved in every session. Each entry states the condition under which it is used.
Lovable AI Gateway
Used only when enabledGenerates AI-assisted explanatory narrative for parts of an assessment output. Scores, rankings and eligibility remain deterministic and are not produced by this service.
When: Only when an AI-assisted narrative section is generated.
Data involved: The specific assessment content passed into that explanation request. It is not used for account authentication or document storage.
Cloudflare (Turnstile)
Used only when enabledBot protection on sign-in and other public form submissions.
When: Only when Turnstile bot protection is configured for the environment.
Data involved: Technical and challenge-verification signals from your browser. It does not receive your account content, assessment answers or documents.
Cal.com
Used only when enabledScheduling for consultation bookings, reached through a booking link.
When: Only when you follow a booking link and schedule a consultation.
Data involved: The booking details you choose to provide when you schedule a call, such as name, email address and the selected time.
Resend
Used only when enabledDelivery of transactional email such as service notifications.
When: Only when transactional email delivery is configured for the environment.
Data involved: Recipient email address and the content of the transactional message sent to you.
Better Stack
Used only when enabledExternal availability monitoring. It checks whether public pages respond from outside our infrastructure.
When: Only when external uptime monitoring is configured for the environment.
Data involved: Availability and response data from automated checks of public endpoints. It does not receive customer account content, assessment answers or documents.
Questions and changes
This list changes as the platform changes. If you need the position that applies to your engagement — including which services are enabled for your environment — ask us through the privacy request route or the Contact page. See the Privacy notice for how we handle personal data more generally.