Data protection

Subprocessors and service providers

Welbeo uses a limited set of third-party providers to operate the platform. A provider is a GDPR subprocessor only to the extent it processes personal data on Welbeo's behalf.

Last updated: 25 September 2026

Provider register

Vercel

Purpose: Application hosting, delivery and infrastructure logs
Data: Request metadata and application data processed by server functions as required
Role note: Core hosting provider

Supabase

Purpose: Authentication, PostgreSQL database and storage
Data: Accounts, practitioner/business data, bookings and feature-specific application data
Role note: Core data processor

Cloudflare R2

Purpose: Object storage and delivery for practitioner-approved media and Welbeo content
Data: Published media and related object metadata
Role note: Storage provider

Resend

Purpose: Transactional email delivery
Data: Recipient address, message content required for the notification and delivery metadata
Role note: Email processor

Google

Purpose: Calendar, Maps/Places and Search Console integrations when enabled by the user
Data: Feature-specific OAuth, calendar, place or search data
Role note: Integration provider; role depends on service

Microsoft

Purpose: Outlook Calendar integration when enabled
Data: Feature-specific OAuth and calendar data
Role note: Optional integration provider

OpenRouter and selected model provider

Purpose: AI-assisted features when invoked
Data: Purpose-limited prompts and outputs; private-vault plaintext is excluded
Role note: AI service provider

Meta

Purpose: WhatsApp Cloud API messaging when the feature is enabled and applicable consent exists
Data: Phone number, template/message content and delivery metadata needed for the communication
Role note: Optional messaging provider

Stripe

Purpose: Payment processing and Stripe Connect when enabled
Data: Payment and connected-account information; full card details are handled by Stripe
Role note: Payment provider; role may include independent-controller activities

International transfers

Provider hosting and support locations may vary by service configuration. Where GDPR restrictions on international transfers apply, Welbeo requires an applicable transfer mechanism and documents the relevant safeguards in its processor and transfer register. Welbeo does not infer that a provider is EU-only merely from a selected product region.

Changes to this list

Welbeo may add, replace or remove providers as the service evolves. Where a new subprocessor materially affects Customer Personal Data and notice is required under the applicable DPA, Welbeo will provide reasonable advance notice through the service, email or an equivalent channel.

Questions or objections

Contact [email protected] with a data-protection question or a reasonable objection concerning a new subprocessor.