Legal & Trust

Subprocessors.

Effective date: 19 August 2026Last updated: 19 August 2026Version 1.0.0

To run BLEUN we rely on a small number of providers. Only providers actually configured in the product are listed — nothing aspirational.

1.Current subprocessors

ProviderPurposeCategoryRegionStatus
SupabaseApplication database, authentication and document storageDatabase & backendSee project configuration (EU/US region as provisioned)In use
CloudflareApplication hosting, edge delivery and server-side renderingHostingGlobal edge networkIn use
Alibaba Cloud (Model Studio)Objective reasoning and planning model inferenceAI infrastructureInternational (Singapore) endpointIn use
PaddleMerchant of Record: checkout, payment processing, invoicing, taxPaymentsUK / EU / USIn use
Supabase Auth email deliveryTransactional email such as sign-in links and confirmationsEmailSee project configurationIn use
ElevenLabsSpeech synthesis for spoken briefingsVoiceEU / USOptional — only when enabled

2.How we contract with them

Each subprocessor is engaged under terms that require it to process data only on our instructions, keep it confidential, apply appropriate security measures and support data subject requests. Where a provider processes data outside the UK or EEA, we rely on appropriate transfer safeguards as described in the Privacy Policy.

3.AI infrastructure

BLEUN uses a provider abstraction for AI, so the reasoning provider behind a feature can change as models improve. Any provider actually in use appears in the table above, and we update this page when the list changes.

4.Changes and notification

This page is the canonical list. Professional and Enterprise customers with a signed DPA can request notification of new subprocessors by writing to privacy@bleun.ai.

Questions about this document? Write to legal@bleun.ai or visit the Legal & Trust centre.