Sub-processors
Service providers used to operate VariationDesk.
VariationDesk uses trusted providers to host the service, protect accounts, store evidence, send service messages, process billing and connect to customer-selected accounting providers. Providers only process personal data where needed to deliver the relevant service.
Accounting, SMS and AI providers are not used for every customer action. They apply only when the relevant feature is enabled, connected or deliberately invoked by an authorised user.
Core service providers
These providers help deliver the main VariationDesk web, mobile and workspace service.
Supabase
- Purpose
- Authentication, database, tenant isolation and private evidence-file storage.
- Personal data involved
- Account, organisation, project, variation, evidence, support, billing metadata and audit records.
- When this applies
- Used for VariationDesk workspaces.
Vercel
- Purpose
- Application hosting, server-side web routes and deployment infrastructure.
- Personal data involved
- Application request metadata, service logs and data processed through VariationDesk application routes.
- When this applies
- Used to deliver the web application and public website.
Expo, Apple and Google mobile services
- Purpose
- Mobile app builds, app distribution, updates and push notification routing where enabled.
- Personal data involved
- App/device delivery metadata, mobile push tokens and app-store privacy or data-safety information.
- When this applies
- Used for the mobile app and notifications. Notification payloads should not contain sensitive project details.
Billing and communications providers
These providers are used for customer billing and service messages.
Stripe
- Purpose
- Subscriptions, checkout, customer billing portal, invoices and payment webhooks.
- Personal data involved
- Billing contacts, subscription identifiers, invoice metadata, payment status and tax/VAT billing records.
- When this applies
- Used where a workspace starts a trial, subscription, checkout or paid billing process.
Resend
- Purpose
- Transactional email delivery for account, invite, sign-off, support and billing messages.
- Personal data involved
- Recipient email addresses, service-message content, delivery metadata and template references.
- When this applies
- Used for VariationDesk service emails.
Twilio
- Purpose
- SMS verification, two-step verification and remote sign-off verification where phone/SMS features are enabled.
- Personal data involved
- Phone numbers, verification metadata, masked destinations and delivery status.
- When this applies
- Used only where SMS or phone-verification features are enabled for a workspace or user action.
Optional AI services provider
AI drafting and voice variation intake are optional and only run when an authorised user deliberately invokes the relevant feature. VariationDesk does not send every workspace record or background device audio to the AI provider.
OpenAI
- Purpose
- Generate optional drafting suggestions and, where voice variation intake is enabled, transcribe a user-recorded site voice note and convert its transcript plus explicit follow-up answers into structured draft variation fields. VariationDesk performs approved SOR/rate-card matching itself; customer rates are not generated by the AI model.
- Personal data involved
- For drafting, the wording deliberately selected by the user and limited relevant record context. For voice intake, the user-recorded audio, resulting transcript, explicit guided follow-up answers, and limited project/form context needed for transcription and structured extraction. Approved commercial rates remain inside VariationDesk's trusted rate-card matching layer. A limited set of approved item names may be used as transcription vocabulary hints to improve construction terminology; the corresponding rate values are not sent for that purpose.
- When this applies
- Only used when the relevant AI feature is configured for VariationDesk and a signed-in authorised user actively requests AI Assist or chooses the voice-capture workflow.
Customer-enabled accounting integrations
Accounting integrations only apply when a workspace owner connects that provider. VariationDesk does not send every workspace's data to every accounting provider.
Xero
- Purpose
- Accounting connection for draft-invoice export and evidence records.
- Personal data involved
- Accounting tenant identifiers, contact/invoice metadata, export references and evidence attachment metadata where supported.
- When this applies
- Only used for workspaces that connect Xero.
QuickBooks Online
- Purpose
- Accounting connection for draft-invoice export and, where supported, evidence attachment upload.
- Personal data involved
- Company/account identifiers, contact/invoice metadata, export references and evidence PDF attachment metadata where supported.
- When this applies
- Only used for workspaces that connect QuickBooks Online.
Sage Accounting
- Purpose
- Accounting connection for contact and draft sales-invoice export.
- Personal data involved
- Business/account identifiers, contact/invoice metadata and export references.
- When this applies
- Only used for workspaces that connect Sage Accounting.
FreeAgent
- Purpose
- Accounting connection for contact and draft-invoice export.
- Personal data involved
- Account identifiers, contact/invoice metadata and export references.
- When this applies
- Only used for workspaces that connect FreeAgent.
Changes to this list
We may update this list as the service develops or as customers enable new integrations. Where a change materially affects customer workspace data, VariationDesk will provide notice through the service or customer support channels where appropriate.