Home / Trust & privacy

The services behind the service.

Updated 13 September 2026

This register describes providers in the hosted configuration and optional feature paths. A provider receives data only when the corresponding processing path is used.

Vercel: application hosting

Vercel hosts the application and website. Data can include web requests, necessary application payloads and operational logs. Its role is delivering and operating the service.

Supabase: database and file storage

Supabase provides database and file storage for workspace records, permitted conversations, knowledge and uploaded assets. The relevant workspace access and retention rules apply to that information.

Google Cloud Vertex AI: AI features

Google Cloud Vertex AI is used for configured text and image generation. Relevant prompt content, selected business knowledge and requested media are sent for the generation task. AI features do not require sending every record in a workspace for every request.

OpenAI: optional fallback text generation

OpenAI is available as a fallback text-generation provider in the application. Relevant prompts and selected context can be processed when that path is configured and used. Listing this provider does not mean every conversation is routed through it.

Groq: configured transcription

Groq is used for configured audio transcription. Requested audio and associated task information may be processed to produce a transcript.

Resend: service email

Resend delivers service emails. Processing includes recipient email, required email content and delivery metadata. This role does not imply permission to send marketing messages to your followers.

Meta: connected Instagram service

Meta provides Instagram authorisation, authorised account data and the destination for eligible Instagram actions. Meta’s own terms and privacy practices also govern Instagram. Its role is not identical to BIGI’s contracted hosting or AI subprocessor roles.

Processing locations, contracts and changes

These providers operate international services. This register does not promise EEA-only processing or confirm the legal execution of every agreement. Before customer-data processing, the binding data processing arrangement must identify applicable provider terms, locations and lawful transfer safeguards.

Requests for processing and transfer documentation go to gdpr@sita.dev. Material changes to a contracted subprocessor arrangement must follow the notice and objection provisions of the relevant data processing agreement. We update this register when the service configuration changes.

Useful links

Contact the privacy team · Company details · Privacy notice · Request deletion · GDPR & processing · Data processing agreement · Subprocessors · Terms

Your rights: Swedish Authority for Privacy Protection · EU General Data Protection Regulation