Generated from the code-verified register on 2026-09-14 (codebase audit).
Processors of personal data
Third parties that process eznest users' personal data on our behalf.
| Vendor | Purpose | Data categories | Processing | Storage | Status |
|---|---|---|---|---|---|
| Amazon Web Services | Object storage (S3), transactional email relay (SES), and Nestor AI inference (Bedrock). | uploaded_documents; bank_statement_files; email_content; ai_prompts_and_context | ca-central-1; us-east-1 (SES); us-east-1 / us-east-2 / us-west-2 (Bedrock inference, cross-region us.* profiles) | ca-central-1 | live |
| Stripe | Card payments; Stripe-hosted embedded provider onboarding and account management; connected-account payouts (Stripe Connect). | payment_card; name; email; identity_and_verification_information; payout_bank_account; transaction_amounts | us | us | flag_off |
| Clerk | Front-door identity and authentication (verify Clerk token, then eznest issues its own session). | email; name; authentication_events; ip_address | us | us | live |
| RFC 3161 timestamp authority | Independent trusted timestamp on signed agreements (P1-029). eznest is a party to these agreements and takes a fee from them, so a "signed at" eznest records is a claim by an interested party; the authority's token is not. | signature_digest | depends_on_selected_authority | depends_on_selected_authority | pending |
| Apple Push Notification service | iOS push notification delivery. | device_token; notification_payload | us | us | flag_off |
| Firebase Cloud Messaging (Google) | Android push notification delivery. | device_token; notification_payload | us | us | flag_off |
| Google Places / Maps Platform | Geocoding and place lookup for user-entered addresses. | address_text | us | us | key_gated |
| Intuit QuickBooks Online | Accounting sync for providers who connect QuickBooks (invoices, payments). | provider_business_financials; invoice_line_items; customer_names | us | us | flag_off |
| Voyage AI | Text embeddings for Nestor retrieval (production embedding provider option). | user_content_for_embedding | us | us | key_gated |
| OpenAI | Optional frontier LLM adapter for Nestor (not the default; Bedrock/Ollama are). | ai_prompts_and_context | us | us | flag_off |
Public data sources
Read-only public/reference data. No eznest user personal data is sent — listed for transparency.
| Source | Purpose | Region |
|---|---|---|
| OpenCorporates | Company-registry legitimacy enrichment for prospect providers (public business data). | uk |
| Open-Meteo | Weather / seasonal signals (no user PII sent). | ch; servers us/eu |
| OpenStreetMap / Nominatim (OSMF) | Fallback geocoding of address text. | uk; eu |
| Government of Canada / City of Toronto open data | Business collection (StatsCan ODBus), product recalls, municipal datasets — all public data reads. | ca |
| Overture Maps Foundation | Open places dataset for the business/provider directory (batch ingest; no user PII sent). | us |
| Foursquare (Open Source Places) | Open places dataset (Ontario home-services slice) for the business directory; batch ingest, no user PII. | us |
| OpenStreetMap Overpass API (community mirrors) | Query OSM place/business data for the directory (no user PII sent). | eu |
| U.S. Consumer Product Safety Commission | Public product-recall data (safety alerts). Public data reads; no user PII sent. | us |
Regulator lookups
| Regulator | Purpose | Region |
|---|---|---|
| Home Construction Regulatory Authority (Ontario) | Builder/vendor licence verification. | ca |
| Electrical Safety Authority (Ontario) | Electrical contractor (ECRA/ESA) licence verification. | ca |