Sub-processors

Service providers used to operate VariationDesk.

VariationDesk uses trusted providers to host the service, protect accounts, store evidence, send service messages, process billing and connect to customer-selected accounting providers. Providers only process personal data where needed to deliver the relevant service.

Accounting, SMS and AI providers are not used for every customer action. They apply only when the relevant feature is enabled, connected or deliberately invoked by an authorised user.

Core service providers

These providers help deliver the main VariationDesk web, mobile and workspace service.

Supabase

Purpose
Authentication, database, tenant isolation and private evidence-file storage.
Personal data involved
Account, organisation, project, variation, evidence, support, billing metadata and audit records.
When this applies
Used for VariationDesk workspaces.

Vercel

Purpose
Application hosting, server-side web routes and deployment infrastructure.
Personal data involved
Application request metadata, service logs and data processed through VariationDesk application routes.
When this applies
Used to deliver the web application and public website.

Expo, Apple and Google mobile services

Purpose
Mobile app builds, app distribution, updates and push notification routing where enabled.
Personal data involved
App/device delivery metadata, mobile push tokens and app-store privacy or data-safety information.
When this applies
Used for the mobile app and notifications. Notification payloads should not contain sensitive project details.

Billing and communications providers

These providers are used for customer billing and service messages.

Stripe

Purpose
Subscriptions, checkout, customer billing portal, invoices and payment webhooks.
Personal data involved
Billing contacts, subscription identifiers, invoice metadata, payment status and tax/VAT billing records.
When this applies
Used where a workspace starts a trial, subscription, checkout or paid billing process.

Resend

Purpose
Transactional email delivery for account, invite, sign-off, support and billing messages.
Personal data involved
Recipient email addresses, service-message content, delivery metadata and template references.
When this applies
Used for VariationDesk service emails.

Twilio

Purpose
SMS verification, two-step verification and remote sign-off verification where phone/SMS features are enabled.
Personal data involved
Phone numbers, verification metadata, masked destinations and delivery status.
When this applies
Used only where SMS or phone-verification features are enabled for a workspace or user action.

Optional AI services provider

AI drafting and voice variation intake are optional and only run when an authorised user deliberately invokes the relevant feature. VariationDesk does not send every workspace record or background device audio to the AI provider.

OpenAI

Purpose
Generate optional drafting suggestions and, where voice variation intake is enabled, transcribe a user-recorded site voice note and convert its transcript plus explicit follow-up answers into structured draft variation fields. VariationDesk performs approved SOR/rate-card matching itself; customer rates are not generated by the AI model.
Personal data involved
For drafting, the wording deliberately selected by the user and limited relevant record context. For voice intake, the user-recorded audio, resulting transcript, explicit guided follow-up answers, and limited project/form context needed for transcription and structured extraction. Approved commercial rates remain inside VariationDesk's trusted rate-card matching layer. A limited set of approved item names may be used as transcription vocabulary hints to improve construction terminology; the corresponding rate values are not sent for that purpose.
When this applies
Only used when the relevant AI feature is configured for VariationDesk and a signed-in authorised user actively requests AI Assist or chooses the voice-capture workflow.

Customer-enabled accounting integrations

Accounting integrations only apply when a workspace owner connects that provider. VariationDesk does not send every workspace's data to every accounting provider.

Xero

Purpose
Accounting connection for draft-invoice export and evidence records.
Personal data involved
Accounting tenant identifiers, contact/invoice metadata, export references and evidence attachment metadata where supported.
When this applies
Only used for workspaces that connect Xero.

QuickBooks Online

Purpose
Accounting connection for draft-invoice export and, where supported, evidence attachment upload.
Personal data involved
Company/account identifiers, contact/invoice metadata, export references and evidence PDF attachment metadata where supported.
When this applies
Only used for workspaces that connect QuickBooks Online.

Sage Accounting

Purpose
Accounting connection for contact and draft sales-invoice export.
Personal data involved
Business/account identifiers, contact/invoice metadata and export references.
When this applies
Only used for workspaces that connect Sage Accounting.

FreeAgent

Purpose
Accounting connection for contact and draft-invoice export.
Personal data involved
Account identifiers, contact/invoice metadata and export references.
When this applies
Only used for workspaces that connect FreeAgent.

Changes to this list

We may update this list as the service develops or as customers enable new integrations. Where a change materially affects customer workspace data, VariationDesk will provide notice through the service or customer support channels where appropriate.