Data Processing and Vendor Schedule
Version 2026-07-20 · Effective July 20, 2026
Issued by Ohana Capital AG
Effective date
July 20, 2026

Issued by
Ohana Capital AG
1. Status of this document
This Data Processing and Vendor Schedule lists processors and infrastructure providers actually used (or configured) for the Ohana Capital platform and CRM. It supports privacy, security, and counsel review of data-processing agreements (DPAs).
Controller: Ohana Capital AG (see Privacy Policy).
Vendor commercial terms and DPAs must be filed internally. Public listing here does not replace signed contracts.
2. Core processing inventory
| Provider | Purpose | Categories of data (typical) | Location notes |
|---|---|---|---|
| Supabase | Auth, Postgres database, storage, server functions | Account, profile, KYC files metadata/objects, ledgers, audit | Cloud region per project config |
| Vercel | Application hosting, edge/serverless delivery, Analytics / Speed Insights (if consented) | Request logs, deployment metadata, performance metrics | Global edge network |
| Resend | Transactional and CRM email send/receive | Email addresses, message content, delivery events | Per Resend account region |
| PostHog | Product analytics / session insights (if consented) | Pseudonymous usage events; configured masking for inputs/text | US project configuration in current staging |
| Upstash Redis | Rate limiting, quote cache | IP/user rate keys, cached market quotes | Per Upstash region |
| Financial Modeling Prep (FMP) | Market data API | Instrument symbols / quote requests (not full KYC dossiers) | Provider infrastructure |
| Browser local storage | Session / cookie preference persistence | Consent flags, session identifiers | User device |
Career applications may use a dedicated storage bucket for resumes. Legacy support-download buckets are not part of the public support model.
3. Subprocessor governance
Before adding a material processor that handles personal data:
- Complete vendor due diligence (security, location, subprocessors).
- Execute a DPA / SCCs or equivalent where required.
- Update this schedule and, if needed, the Privacy Policy.
- Limit access to least privilege and encrypt in transit.
4. International transfers
Where personal data is transferred outside Switzerland or the EEA, Ohana Capital relies on appropriate safeguards (for example standard contractual clauses, adequacy, or other lawful mechanisms) as documented with the relevant vendor. Exact transfer tools should be confirmed by counsel against current vendor contracts.
5. Security expectations for vendors
Vendors processing personal data are expected to provide:
- Access controls and authentication
- Encryption in transit
- Incident notification commitments
- Deletion / return assistance on contract end
- Subprocessor transparency
Platform-side controls include authenticated APIs, role-based CRM access, private document storage, and audit logging for sensitive reviews.
6. Customer rights routing
Access, deletion, and correction requests follow the Privacy Policy. Operators must not export KYC documents outside approved systems except for legal / compliance necessity.
7. Related documents
Questions about this document?
Contact Ohana Capital AG and include the document title and version in your message.
Contact support