Provider Register
Version 2026-09-14. This register identifies integrations used when the corresponding deployment, feature or model route is enabled. It does not imply that every vendor receives every customer’s data. Payment and other vendors can act as independent controllers for their own regulated functions.
The active checkout disclosure identifies the payment seller and provider. Model selection identifies the requested model; routing intermediaries and substitutes must comply with the customer’s agreed processing restrictions.
| Provider | Purpose / data | Processing location | Vendor information |
|---|---|---|---|
| Vercel | Website hosting, CDN and AI Gateway routing where enabled Network metadata; prompts/media only for gateway-routed requests | Deployment and downstream-provider regions | Provider terms / notice |
| Railway | Application and worker infrastructure Application requests, logs and operational data | Configured deployment region | Provider terms / notice |
| Supabase | Database, authentication and object storage Account, project, media, billing metadata and audit records | Configured project region and contracted subprocessors | Provider terms / notice |
| Resend | Transactional email delivery Recipient email, message content and delivery events | Contracted email delivery and processing locations | Provider terms / notice |
| fal.ai | Selected model inference and media processing Submitted prompts, reference media, generation settings and outputs | Selected model infrastructure; obtain route-specific details | Provider terms / notice |
| Replicate | Selected model inference and moderation Submitted prompts, media, settings, outputs and safety results | Contracted inference infrastructure | Provider terms / notice |
| Google / Gemini / Vertex AI | Selected AI inference and associated cloud media processing Submitted prompts, media, settings and outputs | Selected API/product and configured region | Provider terms / notice |
| OpenAI | Selected AI inference and moderation, directly or through routing vendors Submitted prompts, media and safety results | Selected API/product and contractual configuration | Provider terms / notice |
| ElevenLabs | Selected speech, voice, transcription, audio and music services Submitted text, audio, voice references, voice settings and generated outputs | Selected service, contracted region and safety review locations | Provider terms / notice |
| remove.bg / Canva Austria | Background removal where this optional integration is enabled Submitted images and resulting cut-outs | Applicable service and contractual processing locations | Provider terms / notice |
| Connected social platforms | User-authorised account connection, scheduling and publishing; platform controller activities may apply Selected account identifiers, scoped credentials and approved content | The connected platform and its published processing locations | Provider terms / notice |
| Configured analytics and advertising services | Optional measurement or advertising integrations, including Google and Meta where configured and permitted Browser identifiers, page events and conversion signals according to configured consent and event controls | The selected service and its contractual configuration | Provider terms / notice |
| Selected downstream model providers | Model execution through the chosen direct or intermediary route, including Kling and Seedance integrations Only the inputs, settings and outputs necessary for the request | Varies by actual route; model brand is not a data-region guarantee | Provider terms / notice |
| Active checkout provider | Payment processor or merchant of record as identified at checkout; independent-controller activities may apply Billing contact, transaction, tax, subscription and fraud data; full card details stay with hosted payment tooling | The checkout provider and its contracted payment infrastructure | Provider terms / notice |
Retention, training and contractual safeguards
Retention, deletion, model-training restrictions and transfer mechanisms depend on the actual service and contract configuration. No country, zero-retention setting or no-training commitment is inferred from a vendor brand. Request the recipients, locations, retention settings and transfer safeguards applicable to your account from aslan@aslax.eu before restricted business processing. Aslax does not train its own general-purpose models on private customer inputs or outputs.
For processing on behalf of business customers, the DPA governs authorisation, equivalent subprocessor obligations, change notices and objections. A requested restricted route must be agreed and configured before data is sent; unsupported requests may be declined. Optional marketing and analytics vendors may only receive data under the applicable consent or other lawful requirements.