This register identifies key suppliers currently intended for the MV Workshop pilot/production architecture. It must be kept aligned with the actual service.
1. Supabase
Purpose: managed PostgreSQL database, authentication, storage and related backend services for MV Workshop.
Data: Customer Data, account/profile information, workshop records, documents and service/security metadata as configured.
Location/transfers: depends on the selected Supabase project region and supplier infrastructure. Restricted transfers, if any, must use a lawful UK transfer mechanism.
2. Freeola / customer-selected web hosting used by MV
Purpose: hosting and delivery of the static MV Workshop web application where deployed on the MV website.
Data: normal web-server request/security data and the public application files. Core Customer Data is stored in the Supabase backend rather than the static web files.
3. Customer-configured SMTP provider
Purpose: where a workshop chooses to send notifications using its own SMTP account, that provider handles the email transmission under the Customer's own supplier arrangement and configuration. MV must protect stored SMTP credentials using appropriate server-side secret storage before this feature is enabled for production.
4. MV-managed notification/email provider
No additional production provider is listed in this version because the final MV-managed email supplier for MV Workshop has not yet been enabled in the pilot build. The register must be updated before that supplier processes Customer Data.
5. Payment provider
No payment-card provider is listed because the current pilot build does not take card payments. The register and Privacy Notice must be updated before online payment processing is enabled.
Changes
Where reasonably practicable, MV will provide customers with prior notice of a material new or replacement subprocessor in accordance with the DPA.