Data residency
EU-first infrastructure with explicit transfer visibility.
Corelyx does not make a blanket claim that all data remains in the EU. EU-only mode can restrict storage, logs, model providers, and workflow execution to approved EU/EEA infrastructure for eligible workflows. Some connected services, model providers, email providers, analytics tools, or customer-selected integrations may process data outside the EEA. Corelyx shows this before activation.
Standard mode
Allows customer-selected providers and integrations subject to the workflow checklist, DPA, SCC, and transfer-basis warnings.
EU-only mode
Blocks providers that are not marked as EU-supported with DPA, SCC or transfer-basis evidence, and verified regional controls.
Customer-configured services
Regional eligibility may depend on the customer account for Google, Microsoft, Slack, model-provider, or cloud-provider account.
Residency matrix
Reviewed provider entries used by the public subprocessor registry and in-app compliance checks.
| Provider | Purpose | Default region | EU-only support | Leaves EEA | Transfer basis | Retention |
|---|---|---|---|---|---|---|
Supabase database | Database, authentication, realtime APIs, and Vault-backed secret references. | Configured Supabase project region, expected EU for Corelyx production. | Eligible | No obvious transfer | DPA and SCCs where the configured project or subprocessors involve third-country processing. | Controlled by Corelyx database retention settings and Supabase backup rotation. |
Vercel hosting | Hosts the Next.js web app, API routes, static assets, and deployment logs. | Global CDN; server compute depends on project region configuration. | Eligible | Possible | DPA and transfer addendum; EU-only support depends on project routing and log configuration. | Deployment and request logs follow Vercel account retention and Corelyx log minimisation settings. |
Railway hosting | Hosts the Python workflow runtime used for execution steps. | Configured Railway service region. | Eligible | No obvious transfer | DPA and SCCs where the runtime or subprocessors involve third-country processing. | Runtime logs are minimised and governed by workspace retention settings where technically available. |
Inngest orchestration | Schedules, retries, event dispatch, and asynchronous workflow orchestration. | Provider-managed cloud location based on the configured Inngest account. | Not eligible / needs review | Possible | DPA and SCCs required if personal data is sent through orchestration events. | Event retention depends on the Inngest account and should not include secrets or full payloads in EU-only mode. |
Cloudflare (Turnstile) security | Bot, spam, and abuse protection (CAPTCHA challenge) on public forms such as signup. Only active when Turnstile is enabled via the NEXT_PUBLIC_TURNSTILE_SITE_KEY / TURNSTILE_SECRET_KEY configuration. | Provider-managed global edge network. | Not eligible / needs review | Possible | Processed on Cloudflare's global edge as a bot/abuse safeguard under Art. 6(1)(f) GDPR (legitimate interest in security). Cloudflare DPA and SCCs cover any third-country processing. | Cloudflare states Turnstile does not use the data for cross-site tracking or advertising; challenge data is retained only briefly for abuse prevention per Cloudflare's retention schedule. |
Resend | Transactional email for approvals, failures, account, and billing notices. | United States for account data, email metadata, logs, and API records. | Not eligible / needs review | Possible | DPA and SCCs required for EEA personal data. | Provider email logs follow Resend retention; Corelyx avoids sending secrets in notifications. |
Stripe payments | Checkout, subscriptions, invoices, payment processing, and fraud prevention. | Provider-managed financial infrastructure. | Not eligible / needs review | Possible | DPA, SCCs, adequacy mechanisms, and payment-law processing roles depending on account setup. | Billing and tax data is retained as required by law. |
OpenAI llm | Optional model inference for workflow agent nodes and model operations. Also provides text embeddings for agent knowledge retrieval via the platform key; knowledge content and queries are PII-redacted before embedding, and EU-only workspaces are excluded unless the platform project is verified EU-resident (OPENAI_EU_RESIDENCY). | United States by default unless eligible European data residency is configured in the customer or platform account. | Eligible | Possible | DPA and SCCs unless an eligible EU-resident project is verified for the workspace. | Retention depends on account, API project, abuse monitoring, and zero-data-retention settings. |
Anthropic llm | Optional model inference for workflow agent nodes. | United States for customer data unless otherwise agreed. | Not eligible / needs review | Possible | DPA and SCCs required for EEA personal data. | Commercial API retention is provider-controlled and subject to policy and abuse-monitoring exceptions. |
OpenRouter llm | LLM routing layer used by the Corelyx platform key to execute agent nodes. Also optionally used when a customer configures their own OpenRouter API key. | Provider-managed global infrastructure. EU routing available on enterprise OpenRouter accounts. | Not eligible / needs review | Possible | No signed DPA or SCCs currently in place. Corelyx is pursuing an enterprise DPA with OpenRouter. Until completed, customers should treat OpenRouter as a third-country transfer risk and avoid routing special-category or high-risk personal data through the Corelyx platform key. | OpenRouter states prompts are not used for training and are not retained beyond request processing by default. Verify current policy at openrouter.ai/privacy. |
connector | Google Sign-In (OAuth authentication available to all users). Optionally also used for Gmail, Calendar, Docs, Drive, and Sheets workflow actions when explicitly connected. | Provider-managed; depends on Google account, Workspace region, and service. | Eligible | Possible | Google terms, DPA, SCCs, and customer tenant controls. | Sign-In profile data retained for the life of the account. Connector data retention is controlled by the connected Google account or tenant. |
Notion connector | Optional Notion workflow actions (pages, databases, search) when explicitly connected. | United States by default; EU data residency available for eligible Notion Enterprise workspaces. | Not eligible / needs review | Possible | Notion Data Processing Addendum incorporating SCCs for EEA personal data. | Connector data retention is controlled by the connected Notion workspace; Corelyx stores only workflow payloads per its retention settings. |
Slack connector | Optional Slack workflow actions (read messages, post messages, channel and webhook events) when explicitly connected. | United States by default; Slack offers EU data residency for eligible Enterprise Grid plans. | Not eligible / needs review | Possible | Salesforce/Slack Data Processing Addendum incorporating SCCs for EEA personal data; customer-configured connector. | Connector data retention is controlled by the connected Slack workspace; Corelyx stores only workflow payloads per its retention settings. |
GitHub connector | Optional GitHub workflow actions (read repositories, create issues, pull requests, comments, webhooks) when explicitly connected. | Provider-managed global infrastructure (United States). | Not eligible / needs review | Possible | GitHub (Microsoft) Data Protection Addendum incorporating SCCs for EEA personal data; customer-configured connector. | Retention is controlled by the connected GitHub account or organization; Corelyx stores only workflow payloads per its retention settings. |
Airtable connector | Optional Airtable workflow actions (read or write bases, records, and schemas) when explicitly connected. | Provider-managed infrastructure (United States). | Not eligible / needs review | Possible | Airtable Data Processing Addendum incorporating SCCs for EEA personal data; customer-configured connector. | Retention is controlled by the connected Airtable account; Corelyx stores only workflow payloads per its retention settings. |
Asana connector | Optional Asana workflow actions (read or create projects, tasks, and related events) when explicitly connected. | Provider-managed infrastructure (United States). | Not eligible / needs review | Possible | Asana Data Processing Addendum incorporating SCCs for EEA personal data; customer-configured connector. | Retention is controlled by the connected Asana workspace; Corelyx stores only workflow payloads per its retention settings. |
HubSpot connector | Optional HubSpot workflow actions (read or update contacts and related CRM information) when explicitly connected. | United States by default; HubSpot offers EU data hosting for eligible accounts. | Not eligible / needs review | Possible | HubSpot Data Processing Agreement incorporating SCCs for EEA personal data; customer-configured connector. | Retention is controlled by the connected HubSpot account; Corelyx stores only workflow payloads per its retention settings. |
Typeform connector | Optional Typeform workflow triggers and reads (form definitions, submissions, webhook responses) when explicitly connected. | European Union by default; provider-managed subprocessors may process data outside the EEA. | Not eligible / needs review | Possible | Typeform Data Processing Agreement incorporating SCCs where subprocessors process EEA personal data; customer-configured connector. | Retention is controlled by the connected Typeform account; Corelyx stores only workflow payloads per its retention settings. |
Microsoft (Outlook, Microsoft 365 / Graph) connector | Optional Microsoft 365 / Outlook workflow actions (read and send email and related Microsoft Graph data) when explicitly connected. | Provider-managed; depends on the connected Microsoft 365 tenant region and the Microsoft EU Data Boundary. | Eligible | Possible | Microsoft Products and Services Data Protection Addendum incorporating SCCs and the EU Data Boundary; regional controls depend on the customer tenant. | Retention is controlled by the connected Microsoft 365 tenant; Corelyx stores only workflow payloads per its retention settings. |
Customer-configured HTTP endpoint connector | Customer-configured webhook or HTTP connector calls to arbitrary public endpoints. | Customer-configured destination. | Not eligible / needs review | Possible | Customer must document recipient, DPA, SCCs, and transfer basis before personal-data use. | Retention is controlled by the customer-configured endpoint. |
For processor terms and subprocessor change notice, see the DPA and Subprocessors pages.
