VATFIND LEGAL
Service providers
The services involved in operating VATFind and the information each receives.
Updated 8 September 2026
How to read this list
This is a functional disclosure of integrations in VATFind. A provider can act as processor, subprocessor or independent controller depending on the purpose and its contract. The relevant legal contracting entity, processing countries and transfer safeguards must be confirmed in the applicable agreement. A service’s presence here is not a claim of a particular region, certification or signed transfer instrument.
Providers and purposes
| Provider or category | Purpose and information | Scope |
|---|---|---|
| OpenAI Sites / Cloudflare infrastructure | Website delivery, application execution, database and private object storage, request and security metadata | Hosting stack; application records and authorised infrastructure access depend on the service arrangement |
| WorkOS | Account identity, verified email, profile, sign-in and session information | Registration, authentication and account access |
| Stripe | Checkout contact and billing information, payment details, subscriptions, invoices, refunds and disputes | Payment processing; VATFind receives payment references and status, not full card numbers or security codes |
| Resend | Email address, relevant service-message content, delivery status and message references | Transactional account, billing and support emails when configured |
| HubSpot | Business contact, registration and enquiry details, request context and CRM delivery information | Customer relationship management and responding to requests; registration alone is not a marketing subscription |
| Google Analytics | Public-page interactions, online identifiers and technical information, with limited events forwarded by VATFind | Optional analytics after permission; Google’s privacy terms also apply |
| Licensed company-information sources and official registries | Submitted company name or identifier, selected jurisdiction and source-request metadata | Retrieve and match business records; source access and roles vary by jurisdiction and contract. Request the applicable source schedule for your workflow. |
| Your selected identity provider, MCP/AI client or webhook recipient | Sign-in information or results and events within your chosen authorisation | Customer-selected integrations; their independent privacy terms and your permissions apply |
Locations and transfers
The stack does not establish exclusive UK or EEA residency. Suppliers can use facilities and support teams in the United States and other locations. To assess a restricted workflow, request the current contractual entities, countries, onward providers, retention, data-access scope and transfer safeguards. We will distinguish the application’s hosting location from backup, support and other supplier processing.
Read the privacy notice’s transfer information. Where VATFind acts as processor, the signed data processing agreement identifies authorised subprocessors and provides the advance-notice and objection process.
Questions and changes
We review this page when material integrations change. For an enterprise assessment or a particular rights request, contact us for the relevant schedule; this general inventory does not replace an executed supplier or transfer agreement.
For legal, privacy or support requests, click here with “VATFind” and the nature of your request in the subject, or use the support centre. Do not send passwords, API keys or full payment-card details.