Subprocessor and Service Provider Information
Last updated: 24 August 2026
This page identifies infrastructure and optional service-provider categories used by Quantara. The providers that apply depend on the active service configuration and workflows selected by the customer.
A provider is used only when the relevant infrastructure is active or an optional user workflow is enabled. Inclusion here does not claim that every provider processes every customer's data.
Current provider register
| Service | Status | Purpose | Data categories |
|---|---|---|---|
| Cloudflare application runtime / Hyperdrive architecture | Implemented; live provider or region requires confirmation | Application delivery and optional database connection proxy in the committed deployment architecture. | HTTP request and application traffic; database traffic if Hyperdrive is configured. |
| PostgreSQL origin database provider | Implemented; live provider or region requires confirmation | Primary structured application data storage. | Account, company, project, BOQ, audit, support, billing and integration records. |
| Vercel Blob private object storage | Implemented; live provider or region requires confirmation | Implemented production adapter for uploaded files and generated documents. | Authorized project files and generated document bytes. |
| Configured SMTP provider | Implemented; live provider or region requires confirmation | Account verification, password reset and configured service email. | Recipient address, message subject and necessary email content. |
| Stripe | Conditional on enabled workflow | Eligible recurring subscription checkout, billing portal and subscription-event reconciliation. | Company legal name and email, internal company and price references, customer, checkout, subscription and event identifiers; no card data stored by Quantara. |
| Google Drive services | Conditional on enabled workflow | Read-only connection, browsing and import of user-selected supported project files. | OAuth credentials, selected file metadata and selected file content. |
| OpenAI | Conditional on enabled workflow | Configured voice transcription and transcript interpretation for reviewable BOQ change proposals. | Voice audio and transcript or relevant proposal context for the selected workflow. |
Owner confirmation is required for the legal entity, production activation, processing region and transfer safeguards of each active provider before this register can support a final customer DPA.
Not listed as an active provider
Arcade and planned CAD, BIM, Autodesk or other integration providers are not listed as active subprocessors because no production-backed configuration is enabled in the current provider registry.
Changes and customer terms
Material provider changes will be reflected on this page. Where a customer agreement requires notice or an objection process, that agreement controls.
Google Drive and WhatsApp may also be user-chosen external services. Their legal classification and any customer-specific processing terms require owner or legal confirmation.
Contact and privacy requests
Use the verified channels below for privacy rights, security reports, legal questions and support. Do not send passwords, authentication tokens or confidential project documents by email or WhatsApp.
- Email: solution@vistabylara.com
- Telephone: +971 50 799 4292
- WhatsApp: +971 50 799 4292