Avut PIM
PrivacyAI privacySubprocessorsTermsDPACookiesSupportOpen app

Legal

Subprocessors and Third-Party Providers

This register identifies Avut-engaged subprocessors, controller-side providers, customer-directed integrations, and external MCP clients.

Last updated: July 26, 2026

This register identifies:

  • subprocessors that may process Customer Personal Data on Avut’s behalf when Avut provides Avut PIM as a processor;
  • third-party providers used by Avut in its own controller capacity for account administration, billing, security, support, or service operations; and
  • customer-directed integrations and external MCP clients that a customer may independently connect to Avut.

Unless otherwise stated, “Customer Personal Data” means personal data contained in customer workspaces, catalogs, media, imports, exports, integrations, MCP tool use, AI workflows, and related operational records for which Avut acts as a processor.

For account administration, billing, support, security, and certain service operations, Avut may act as an independent controller as described in the Privacy Policy.

Compatibility with a standards-based client does not mean Avut selects, controls, endorses, or contracts with every compatible client provider. External MCP clients are listed here only where doing so helps explain the processing relationship.

The maintained public register is published at: https://avut.io/privacy/subprocessors

Avut-engaged subprocessors

ProviderService or featureRole and purposeTypical personal dataRegion or regional noteInternational transfer note
ClerkAuthentication and user managementSubprocessor for workspace user and membership data; also used in Avut’s controller context for account administration and securityUser identifiers, names, email addresses, organization or workspace membership, authentication metadata, session metadata, related security eventsProvider-managed and account-dependentChapter V transfer mechanism where applicable under provider terms
NeonManaged PostgreSQL databaseSubprocessor hosting the primary application databaseUser and membership records, audit records, import and export records, operational job data, configuration data, and any personal data a customer stores in catalog, product, or workflow recordsFrankfurt, Germany; production uses a 24-hour point-in-time restore window and daily snapshots scheduled for automatic deletion after 30 days; no separate read-replica endpointNot expected for in-region database hosting; Chapter V mechanism where applicable for support, backups, or remote access
CloudflareR2 object storage and related media delivery functionsSubprocessor storing tenant media objects, generated assets, and storage-backed filesMedia files, object keys, object metadata, generated assets, and any personal data contained in customer-uploaded media or storage-backed filesAutomatic location setting; exact country not guaranteedChapter V transfer mechanism where applicable under provider terms
UpstashRedis, cache, and coordinationSubprocessor providing queue signaling, worker coordination, and cache supportJob identifiers, queue keys, operational metadata, cache keys, and limited personal data that may be embedded in queued payload fragments or cache metadataProvider-managed and deployment-dependentChapter V transfer mechanism where applicable under provider terms
OpenAIAvut-operated AI featuresSubprocessor for Avut-operated AI workflows, including translation, inline product content generation, assistant workflows, alt text, image generation, tariff suggestions, and import mapping suggestionsSelected product fields, customer prompts or instructions, workflow context, selected import or mapping samples, image inputs or URLs where applicable, and generated responsesProvider-managed and service-dependent; OpenAI’s default API abuse-monitoring retention for the endpoints used by Avut is up to 30 days unless different approved controls applyChapter V transfer mechanism where applicable under provider terms
Fly.ioApplication and worker hostingSubprocessor hosting the Avut web application, background workers, and scheduled operational processesApplication traffic, IP addresses and request metadata, operational logs, worker telemetry, and any personal data contained in transient service processing or logsFrankfurt, Germany; Fly currently provides a seven-day searchable application-log windowChapter V transfer mechanism where applicable under provider terms

Controller-side and dual-role providers

ProviderService or featureRole and purposeTypical personal dataRegion or regional noteInternational transfer note
StripeSubscription billing, hosted checkout, customer portalController-side billing provider used for subscription checkout, invoicing, payment processing, fraud prevention, refunds, customer portal access, and billing synchronization. Stripe may act in different roles under its own terms for regulated payment servicesCompany name, billing contact details, billing and tax address, subscription and invoice data, payment method metadata, transaction data, fraud or risk data, refund records, customer portal activityStripe-managedChapter V transfer mechanism where applicable under provider terms
ShopifyShopify Billing for eligible Shopify-originated workspacesController-side billing and commerce-platform provider for app-subscription approval, billing status, and related payment operations. Shopify’s precise role also follows its terms with the merchantMerchant and store identifiers, company and billing context, selected plan, app-subscription identifiers, billing status, and related transaction metadataShopify-managedChapter V transfer mechanism where applicable under provider terms
MicrosoftMicrosoft Graph email deliveryController-side communications provider used to send service, support, operational, product, and legal communicationsRecipient and sender email addresses, subject, message content, inline attachments, delivery request metadata, and provider message identifiersMicrosoft-managed and tenant-dependentChapter V transfer mechanism where applicable under provider terms
CloudflareTurnstile and related protected-form security servicesProcessor when handling signals to provide Turnstile protection on Avut’s instructions, and controller when Cloudflare uses signals to improve its bot-detection capabilitiesIP address, browser and device signals, user-agent information, origin or hostname context, challenge results, and related security metadataCloudflare-managedChapter V transfer mechanism where applicable under provider terms

Customer-directed integrations and external MCP clients

Provider or categoryService or featureRole and purposeTypical personal dataRegion or regional noteInternational transfer note
ShopifyCommerce integration and app distributionCustomer-directed integration used when a customer connects a Shopify store; separate from Shopify’s billing role for eligible Shopify-originated workspacesMerchant and store metadata, product data, inventory data, media metadata, metafields, and webhook payloads within approved scopesShopify-managedGoverned by the customer’s Shopify relationship and applicable Chapter V mechanism where required
OpenAIChatGPT or Codex connected through MCPCustomer-directed external MCP client or recipient when the customer independently connects its own OpenAI client to Avut’s MCP endpointPrompts, conversation context, tool requests, and returned Avut data resulting from authorized tool usageDepends on the customer’s own account and provider settingsGoverned by the customer’s OpenAI relationship and applicable Chapter V mechanism where required
AnthropicClaude connected through MCPCustomer-directed external MCP client or recipient when the customer independently connects its own Anthropic client to Avut’s MCP endpointPrompts, conversation context, tool requests, and returned Avut data resulting from authorized tool usageDepends on the customer’s own account and provider settingsGoverned by the customer’s Anthropic relationship and applicable Chapter V mechanism where required
Other customer-selected standards-compatible MCP clientsExternal MCP clientCustomer-directed client or recipient connected independently by the customerPrompts, conversation context, tool requests, and returned Avut data resulting from authorized tool usageDepends on the customer’s own provider settingsGoverned by the customer’s relationship with the selected provider and applicable Chapter V mechanism where required

Notes on interpretation

A provider may appear in different sections because the role can differ by feature. For example, OpenAI is an Avut-engaged provider for Avut-operated AI features, but an OpenAI product selected and connected directly by a customer through MCP is customer-directed and is not automatically classified as Avut’s subprocessor solely because Avut provides an MCP endpoint. Shopify is a customer-directed commerce integration and can also provide billing for eligible Shopify-originated workspaces. Cloudflare describes itself as a processor when providing Turnstile protection and as a controller when using Turnstile signals to improve bot detection.

Not every third-party provider used by a customer is necessarily a subprocessor engaged by Avut. Where the customer independently chooses, authorizes, and configures an external client or integration, the legal role may differ from an Avut-engaged subprocessor relationship.

New Avut-engaged subprocessors are handled under the notice and objection process described in the DPA. Customer-directed integrations and external MCP clients are instead governed primarily by the customer’s own selection and the applicable external provider relationship.