Data Processing
Last updated: January 29, 2026
Overview
This page describes how SuperTrained processes data on behalf of our clients and website visitors. For enterprise engagements requiring a formal Data Processing Agreement (DPA), please contact us directly.
Data We Process
Website Visitors (Automation Blueprint Generator)
- Input text: The workflow challenge you describe
- Email address: For Automation Blueprint delivery
- IP address: Hashed for rate limiting (not stored in plaintext)
- Marketing consent: Your opt-in preference
Professional Engagements
For consulting and development engagements, data processing terms are defined in the engagement-specific agreement. We only access client systems and data as required to deliver the contracted services.
Sub-Processors
We use the following sub-processors to deliver our services:
| Provider | Purpose | Data Location |
|---|---|---|
| Anthropic (Claude) | AI processing for Automation Blueprint generation | United States |
| Supabase | Database storage (leads, rate limits) | US East (AWS us-east-1) |
| Resend | Transactional email delivery | United States |
| Vercel | Application hosting and CDN | Global (Edge network) |
| Calendly | Meeting scheduling | United States |
This list was last reviewed on January 29, 2026. We will update this page when sub-processors change.
Data Retention
- Automation Blueprint data: Stored for 90 days, then automatically deleted
- Lead information: Retained for up to 2 years or until deletion is requested
- Rate limit records: Automatically purged after 2 days
- Email delivery logs: Retained for 30 days
Security Measures
- All data transmitted via HTTPS/TLS encryption
- Database access restricted to service role credentials
- Row Level Security (RLS) enabled on all database tables
- IP addresses hashed (SHA-256) before storage
- API keys and credentials stored as environment variables, never in source code
- Rate limiting to prevent abuse
Enterprise DPA
If your organization requires a formal Data Processing Agreement for a consulting engagement, please contact us at hello@supertrained.ai. We can provide a DPA that covers:
- Scope and purpose of data processing
- Technical and organizational security measures
- Sub-processor management and notification
- Data subject rights assistance
- Data breach notification procedures
- Data return and deletion upon termination
Contact
For data processing inquiries, contact us at hello@supertrained.ai