Enterprise legal
Sub-processor list
Last updated: June 2026
ZRG Mineral uses the following sub-processors to operate the platform. This list is provided for GDPR Art. 28 and enterprise due diligence.
Infrastructure & storage
Vercel Inc. — application hosting, edge functions, Vercel KV (sessions, configs). Location: EU region preferred. Supabase — optional PostgreSQL and object storage for portfolio files and audit mirror. Location: EU.
Billing & communications
Stripe, Inc. — B2B invoicing and payment collection (company name, email, billing address). Resend, Inc. — transactional email (magic links, alerts, invoices).
Optional AI processing
OpenAI, L.L.C. — text extraction from uploaded compliance documents when AI validation is enabled. Only document excerpts required for field extraction are transmitted.
Customer-controlled identity
Microsoft Entra ID / customer SAML IdP — authentication federation when SSO is configured by the customer. ZRG does not store IdP credentials.
OpenAI is used only when OPENAI_API_KEY is configured for document extraction. Microsoft identity services apply only when the customer enables SSO.