Trust Centre

Subprocessor register

This register identifies service providers that may process personal information or customer content for SR&ED Copilot. A provider receives customer content only when necessary for the stated service or when the customer activates the relevant feature.

Effective: July 14, 2026

Residency notice: This register does not promise Canadian data residency. Core production hosting is currently in the United States on Render. Feature-specific providers may process data in the United States, Canada, or other locations on global infrastructure.

Appointed service providers

ProviderPurposeData involvedWhen usedLocation note
RenderApplication, API, and managed database hostingAccount data, customer content, integration tokens in encrypted form, logs, and service metadataCore serviceCore production hosting is currently in the United States on Render; Canada-only residency is not available
CohereHosted AI narrative generationThe generation prompt and evidence text selected for the requestWhen a customer uses the default hosted Cohere modelProvider-controlled processing; do not assume Canada-only processing
AnthropicOptional AI narrative generationThe generation prompt and evidence text selected for the requestOnly when an Anthropic model is selected and available through hosted or customer-supplied credentialsProvider-controlled processing; may include the United States
OpenAIOptional AI narrative generationThe generation prompt and evidence text selected for the requestOnly when an OpenAI model is selected and available through hosted or customer-supplied credentialsProvider-controlled processing; may include the United States
StripeSubscription checkout, invoicing, and payment processingBilling contact, organization and transaction metadata; card data is entered into Stripe and is not stored by SR&ED CopilotWhen billing or checkout is usedProvider-controlled processing, including the United States and other locations described by Stripe
ResendTransactional email deliveryRecipient email address and the content of account, security, billing, or support-related messagesWhen the service sends transactional emailProvider-controlled processing; may include the United States
Google AdsPublic-site campaign attribution and completed-sign-up conversion measurementPublic page URL and title, browser/device/network metadata, consent state, permitted ad-click identifiers, and a completed-sign-up event; no registration form fields or SR&ED customer contentOnly on designated public marketing and registration routes; advertising storage is denied by default and the tag is excluded from dashboard, welcome, invitation, and password-reset routesProvider-controlled global processing, including the United States; do not assume Canada-only processing

Customer-directed connections

The following services are not activated by default. If an account owner connects one, that provider remains subject to the customer's own agreement with it, and SR&ED Copilot exchanges the scopes and records the customer authorizes:

  • GitHub
  • GitLab
  • Atlassian Jira
  • Slack
  • Microsoft Teams
  • Microsoft Azure DevOps
  • Bitbucket
Before disconnecting, an owner sees how many imported evidence items and narrative citations are affected and chooses to keep the evidence or permanently purge matching evidence from that provider. Purging also removes its citation links and cannot be undone. Review and revoke the provider-side authorization separately; removing the SR&ED Copilot connection cannot guarantee removal from the provider's own systems or managed backup rotation.

Browser measurement status

Google Ads is limited to designated public marketing and registration routes and receives a completed sign-up event only after the registration API succeeds. Consent mode denies advertising and analytics storage by default and presents an allow/decline control. Declining keeps advertising storage denied and uses redacted, cookieless signals. Google Ads is not loaded on authenticated dashboard, welcome, invitation, or password-reset routes. Product and evidence identifiers, claim content, registration form fields, account email addresses, and authenticated page URLs are not sent by this measurement code. Plausible and PostHog remain disabled.

AI-specific controls

  • Only the project context, evidence selected for a generation request, and generation instructions are sent to the selected AI provider.
  • An organization owner can disable AI processing, require customer-supplied provider keys, or allow only selected providers.
  • Data minimization limits the request to project name, description, fiscal year, and technology stack; selected evidence IDs, sources, titles, summaries, dates, and tags; instructions; and draft narrative text when improving a draft. Evidence links and raw integration payloads are excluded.
  • Hosted and customer-supplied-key requests still send content to the selected provider; supplying a key changes credentials, not the data path.
  • Customer-supplied API keys are used for the request and are not intentionally persisted by SR&ED Copilot.
  • SR&ED Copilot does not use customer content to train its own models and relies on applicable provider API terms for provider training restrictions.
  • Customers should redact secrets, personal data, and technical detail that is not needed for the draft.

Changes and objections

We will update this page before or promptly after a material provider change. Where a signed agreement requires advance notice or an objection period, that agreement controls. Self-service customers who object to a new material subprocessor may stop using the affected feature, export available records, and request deletion before the provider is used for their future requests. We cannot promise that every core provider can be replaced for an individual self-service account.

Need a vendor document?

Review the DPA framework and Security & Data Handling, then email legal@sredcopilot.ca with any required contractual terms.

Return to the Trust Centre.