Trust

Subprocessors

Last updated: 1 August 2026

Lateral Vision Pty Ltd (ABN 71 624 831 223) trading as Swyvl uses the third-party service providers below ("subprocessors") to help deliver the Swyvl platform. Each is bound by contractual data-protection obligations. This list reflects the subprocessors engaged as of the date above.

Subprocessor Purpose Data processed Location Certifications
Supabase Application database & authentication Account details, file metadata, application data AWS (managed) SOC 2 Type II
Wasabi Object storage (file contents) Uploaded files, thumbnails, processing output Customer-selected region (8 available) SOC 2 Type II, ISO 27001
Google Cloud Compute (file processing) File contents during processing (transient) Customer-selected region SOC 2, ISO 27001
Firebase Hosting Web hosting & CDN Static application assets (no customer data) Google global edge SOC 2
Paddle Billing (Merchant of Record) Billing contact, subscription status EU / global PCI-DSS Level 1
Resend Transactional email Recipient email address, message content US SOC 2 Type II
MapTiler Map tiles Tile requests only (no personal data) EU / global CDN
Anthropic AI file classification File names & metadata for classification US SOC 2 Type II

Changes to this list

We will provide advance notice of any new or replacement subprocessor that processes personal data before it begins processing, so customers have the opportunity to review the change. To request notification of changes, or for a Data Processing Agreement, contact support@swyvl.io.

Data residency

File contents are stored and processed in the region each organisation selects, across eight available regions, and do not leave that region. Application metadata is held in Swyvl's managed database. See data regions for detail.