MySafeSigns

Sub-processors

Last updated: 2026-04-28Owner: SymbioTeK Pty Ltd

This page is the canonical list of sub-processors that receive personal information from MySafeSigns. We commit to notifying customers under signed Data Processing Agreement (DPA) of any change with at least 30 days' written notice. To subscribe to change notifications, email symbiotek@symbio-tek.com.

Reminder: by design, the App does not transmit GPS coordinates, site/client/auditor names, compliance findings, or notes to any sub-processor. Audit content stays on the auditor's device. The transmissions described below are limited to account credentials, billing metadata, and (only when AI detection is invoked) the captured sign photograph.

Current sub-processors

Sub-processor Country / region Role Data they receive Their security page
Anthropic, PBC United States AI vision model (Claude) for sign detection Captured sign photograph only — transmitted in API request body, not stored by SymbioTeK trust.anthropic.com
Supabase, Inc. Database: AWS Singapore (ap-southeast-1)
Compute: AWS Sydney (ap-southeast-2)
Authentication, database, edge function runtime Account email, hashed password, credit balance, immutable transaction log supabase.com/security
Stripe Payments Australia Pty Ltd Australia Payment processing (credit purchases) Card details, billing email, customer/session IDs stripe.com/au/legal/pci-dss
Netlify, Inc. Global edge CDN Static asset delivery (HTML, JS, CSS, images) HTTP request metadata only (URL path, IP, user-agent) netlify.com/security

Sub-processors of our sub-processors

Each of the sub-processors above maintains its own list of upstream infrastructure providers. The most consequential are:

Change history

DateChange
2026-04-28Initial publication.

Data processing agreement

A customer DPA template is available at /security/MySafeSigns-DPA-Template-v1.md. The template references this sub-processor list. To execute a DPA, contact symbiotek@symbio-tek.com.