1. Criterio
Smart Steel Sales distingue tra fornitori che trattano dati per conto della piattaforma, servizi con possibili trasferimenti fuori dallo SEE e strumenti operativi che non devono ricevere dati personali dei clienti nel normale flusso di produzione.
Una voce indicata come "verifica aperta" o "non approvata" non viene presentata come conforme per supposizione: resta un gate prima dell'uso commerciale del relativo trattamento.
2. Registro dei principali fornitori
Supabase
PostgreSQL, Auth, Storage and Edge Functions
- Uso e localizzazione
- Database, authentication and storage are hosted primarily in the EU region selected for the production project. International access may occur under contractual safeguards.
- Garanzia di trasferimento
- Supabase DPA; EU SCC Module 2 or 3 for restricted transfers, as applicable.
- Conservazione / stato
- Product retention is controlled by Smart Steel Sales; provider operational/support retention remains subject to Supabase terms and service configuration.
Vercel
Next.js hosting, edge/network delivery and server-side web runtime
- Uso e localizzazione
- Web hosting and delivery may involve processing in the United States and other locations under the provider's applicable contractual transfer safeguards.
- Garanzia di trasferimento
- Vercel DPA provides SCC transfer mechanisms where applicable.
- Conservazione / stato
- Customer Data can be exported/deleted during service use; post-termination deletion is described as within a commercially reasonable timeframe, subject to law.
Railway
FastAPI ingestion, parsing and Commercial Memory worker
- Uso e localizzazione
- The document-processing worker currently operates in the United States; the transfer is subject to the provider's contractual safeguards.
- Garanzia di trasferimento
- Railway DPA; EU SCCs and, where available/applicable, Data Privacy Framework mechanisms.
- Conservazione / stato
- Railway states unnecessary data is disposed of and customer content is purged/anonymized on account deletion; Smart Steel Sales must still enforce its own Commercial Memory lifecycle.
Resend
Transactional authentication and team-invitation email
- Uso e localizzazione
- Transactional email is sent from an EU sending region, while provider storage occurs in the United States under contractual transfer safeguards. Tracking is disabled.
- Garanzia di trasferimento
- Resend DPA incorporates EU SCCs; Resend also states participation in the EU-U.S. Data Privacy Framework.
- Conservazione / stato
- Resend states email/log data is retained 30 days on Free, Pro and Scale plans, backups 7 days, and remaining customer data deleted within 90 days after termination.
Google Analytics 4
Consent-gated public website analytics
- Uso e localizzazione
- Public-site analytics runs only after consent. Google may process data internationally using its applicable transfer mechanisms.
- Garanzia di trasferimento
- Google processing terms; EU-U.S. Data Privacy Framework where relied upon and SCCs for restricted transfers where applicable.
- Conservazione / stato
- Internal target is the minimum GA4 user/event retention setting of 2 months. Actual production property setting is not verifiable from the current toolset.
Hugging Face Inference Providers
External embedding and grounded RAG inference used by the worker
- Uso e localizzazione
- External AI processing of customer personal data is not approved for commercial production until the exact inference provider, processing location and contractual safeguards are fixed.
- Garanzia di trasferimento
- UNRESOLVED for the actual downstream inference provider.
- Conservazione / stato
- Hugging Face states it does not store request/response bodies when routing and keeps debugging logs up to 30 days without user data/tokens; downstream provider retention remains provider-specific and unresolved.
3. AI e Commercial Memory
Le funzioni di embedding/RAG del worker utilizzano attualmente un percorso Hugging Face Inference Providers. Poiché il provider di inferenza effettivo e la relativa catena contrattuale/localizzazione devono essere fissati e verificati, l'invio di dati personali dei clienti a tale percorso non è approvato per il lancio commerciale.
4. Aggiornamenti
Il registro viene riesaminato quando cambia un fornitore, la regione di esecuzione, un subprocessor, il meccanismo di trasferimento o una configurazione che modifica il trattamento. Le fonti contrattuali e le evidenze operative complete sono mantenute nel registro interno di accountability.