Legal
Subprocessors and Third-Party Providers
This register identifies Avut-engaged subprocessors, controller-side providers, customer-directed integrations, and external MCP clients.
Last updated: July 26, 2026
This register identifies:
- subprocessors that may process Customer Personal Data on Avut’s behalf when Avut provides Avut PIM as a processor;
- third-party providers used by Avut in its own controller capacity for account administration, billing, security, support, or service operations; and
- customer-directed integrations and external MCP clients that a customer may independently connect to Avut.
Unless otherwise stated, “Customer Personal Data” means personal data contained in customer workspaces, catalogs, media, imports, exports, integrations, MCP tool use, AI workflows, and related operational records for which Avut acts as a processor.
For account administration, billing, support, security, and certain service operations, Avut may act as an independent controller as described in the Privacy Policy.
Compatibility with a standards-based client does not mean Avut selects, controls, endorses, or contracts with every compatible client provider. External MCP clients are listed here only where doing so helps explain the processing relationship.
The maintained public register is published at: https://avut.io/privacy/subprocessors
Avut-engaged subprocessors
| Provider | Service or feature | Role and purpose | Typical personal data | Region or regional note | International transfer note |
|---|---|---|---|---|---|
| Clerk | Authentication and user management | Subprocessor for workspace user and membership data; also used in Avut’s controller context for account administration and security | User identifiers, names, email addresses, organization or workspace membership, authentication metadata, session metadata, related security events | Provider-managed and account-dependent | Chapter V transfer mechanism where applicable under provider terms |
| Neon | Managed PostgreSQL database | Subprocessor hosting the primary application database | User and membership records, audit records, import and export records, operational job data, configuration data, and any personal data a customer stores in catalog, product, or workflow records | Frankfurt, Germany; production uses a 24-hour point-in-time restore window and daily snapshots scheduled for automatic deletion after 30 days; no separate read-replica endpoint | Not expected for in-region database hosting; Chapter V mechanism where applicable for support, backups, or remote access |
| Cloudflare | R2 object storage and related media delivery functions | Subprocessor storing tenant media objects, generated assets, and storage-backed files | Media files, object keys, object metadata, generated assets, and any personal data contained in customer-uploaded media or storage-backed files | Automatic location setting; exact country not guaranteed | Chapter V transfer mechanism where applicable under provider terms |
| Upstash | Redis, cache, and coordination | Subprocessor providing queue signaling, worker coordination, and cache support | Job identifiers, queue keys, operational metadata, cache keys, and limited personal data that may be embedded in queued payload fragments or cache metadata | Provider-managed and deployment-dependent | Chapter V transfer mechanism where applicable under provider terms |
| OpenAI | Avut-operated AI features | Subprocessor for Avut-operated AI workflows, including translation, inline product content generation, assistant workflows, alt text, image generation, tariff suggestions, and import mapping suggestions | Selected product fields, customer prompts or instructions, workflow context, selected import or mapping samples, image inputs or URLs where applicable, and generated responses | Provider-managed and service-dependent; OpenAI’s default API abuse-monitoring retention for the endpoints used by Avut is up to 30 days unless different approved controls apply | Chapter V transfer mechanism where applicable under provider terms |
| Fly.io | Application and worker hosting | Subprocessor hosting the Avut web application, background workers, and scheduled operational processes | Application traffic, IP addresses and request metadata, operational logs, worker telemetry, and any personal data contained in transient service processing or logs | Frankfurt, Germany; Fly currently provides a seven-day searchable application-log window | Chapter V transfer mechanism where applicable under provider terms |
Controller-side and dual-role providers
| Provider | Service or feature | Role and purpose | Typical personal data | Region or regional note | International transfer note |
|---|---|---|---|---|---|
| Stripe | Subscription billing, hosted checkout, customer portal | Controller-side billing provider used for subscription checkout, invoicing, payment processing, fraud prevention, refunds, customer portal access, and billing synchronization. Stripe may act in different roles under its own terms for regulated payment services | Company name, billing contact details, billing and tax address, subscription and invoice data, payment method metadata, transaction data, fraud or risk data, refund records, customer portal activity | Stripe-managed | Chapter V transfer mechanism where applicable under provider terms |
| Shopify | Shopify Billing for eligible Shopify-originated workspaces | Controller-side billing and commerce-platform provider for app-subscription approval, billing status, and related payment operations. Shopify’s precise role also follows its terms with the merchant | Merchant and store identifiers, company and billing context, selected plan, app-subscription identifiers, billing status, and related transaction metadata | Shopify-managed | Chapter V transfer mechanism where applicable under provider terms |
| Microsoft | Microsoft Graph email delivery | Controller-side communications provider used to send service, support, operational, product, and legal communications | Recipient and sender email addresses, subject, message content, inline attachments, delivery request metadata, and provider message identifiers | Microsoft-managed and tenant-dependent | Chapter V transfer mechanism where applicable under provider terms |
| Cloudflare | Turnstile and related protected-form security services | Processor when handling signals to provide Turnstile protection on Avut’s instructions, and controller when Cloudflare uses signals to improve its bot-detection capabilities | IP address, browser and device signals, user-agent information, origin or hostname context, challenge results, and related security metadata | Cloudflare-managed | Chapter V transfer mechanism where applicable under provider terms |
Customer-directed integrations and external MCP clients
| Provider or category | Service or feature | Role and purpose | Typical personal data | Region or regional note | International transfer note |
|---|---|---|---|---|---|
| Shopify | Commerce integration and app distribution | Customer-directed integration used when a customer connects a Shopify store; separate from Shopify’s billing role for eligible Shopify-originated workspaces | Merchant and store metadata, product data, inventory data, media metadata, metafields, and webhook payloads within approved scopes | Shopify-managed | Governed by the customer’s Shopify relationship and applicable Chapter V mechanism where required |
| OpenAI | ChatGPT or Codex connected through MCP | Customer-directed external MCP client or recipient when the customer independently connects its own OpenAI client to Avut’s MCP endpoint | Prompts, conversation context, tool requests, and returned Avut data resulting from authorized tool usage | Depends on the customer’s own account and provider settings | Governed by the customer’s OpenAI relationship and applicable Chapter V mechanism where required |
| Anthropic | Claude connected through MCP | Customer-directed external MCP client or recipient when the customer independently connects its own Anthropic client to Avut’s MCP endpoint | Prompts, conversation context, tool requests, and returned Avut data resulting from authorized tool usage | Depends on the customer’s own account and provider settings | Governed by the customer’s Anthropic relationship and applicable Chapter V mechanism where required |
| Other customer-selected standards-compatible MCP clients | External MCP client | Customer-directed client or recipient connected independently by the customer | Prompts, conversation context, tool requests, and returned Avut data resulting from authorized tool usage | Depends on the customer’s own provider settings | Governed by the customer’s relationship with the selected provider and applicable Chapter V mechanism where required |
Notes on interpretation
A provider may appear in different sections because the role can differ by feature. For example, OpenAI is an Avut-engaged provider for Avut-operated AI features, but an OpenAI product selected and connected directly by a customer through MCP is customer-directed and is not automatically classified as Avut’s subprocessor solely because Avut provides an MCP endpoint. Shopify is a customer-directed commerce integration and can also provide billing for eligible Shopify-originated workspaces. Cloudflare describes itself as a processor when providing Turnstile protection and as a controller when using Turnstile signals to improve bot detection.
Not every third-party provider used by a customer is necessarily a subprocessor engaged by Avut. Where the customer independently chooses, authorizes, and configures an external client or integration, the legal role may differ from an Avut-engaged subprocessor relationship.
New Avut-engaged subprocessors are handled under the notice and objection process described in the DPA. Customer-directed integrations and external MCP clients are instead governed primarily by the customer’s own selection and the applicable external provider relationship.