1. Scope of this list
HQL Solutions CRM uses the providers below for hosting and supported email or invoicing workflows. Core hosting is distinct from an integration connected to a customer’s own account. Their contractual roles may differ by activity: an engaged processor, a customer-contracted service, or a provider handling some information for its own purposes.
The configured primary database country and application runtime country describe specific components. They do not establish that support, delivery, logs, backups, network services, or all onward processing stay in those countries. Any binding residency or transfer commitments must be assessed and agreed for the actual service configuration.
2. Confirmed providers
| Provider | Function and information involved | Configuration and provider information |
|---|---|---|
| Supabase | Hosted database, authentication, private document/attachment storage and related realtime services. Information includes account/session and recovery identifiers, customer case records, files and permitted realtime updates. | Canada is the configured primary database region. |
| Vercel | Application hosting and runtime, processing information needed to serve CRM requests and associated request or operational metadata. | United States application runtime. This is not a commitment that every Vercel service or activity occurs only in the United States. |
| Resend | Outbound transactional email delivery. Depending on the workflow, recipients, message and template content, and estimate or invoice PDFs are sent. | Processing and delivery locations depend on the provider’s services and delivery route. No country-specific residency commitment is made here. |
| Zoho | Customer-enabled invoicing integration. Estimate, invoice, contact, and currency records are transmitted when the customer uses connected invoicing workflows. | Processing locations depend on the connected customer account and Zoho’s applicable service terms. Check the customer account’s region before use. |
Provider links describe the providers’ own terms and practices. They do not establish which contract has been executed for a customer or that all legal transfer or filing requirements have been satisfied.
3. Customer-selected integrations
Other integrations or external processing features may be available depending on configuration. Availability in the software does not mean an integration is enabled for every customer or that information has been sent to it. Before enabling or using an integration, the customer should assess its purpose, the information transmitted, its provider terms and processing locations, and the notices, legal basis, authority, or safeguards its workflow requires.
Sensitive case documents can contain information about children, dependants, identity, health, finances, or criminal history. Send only information needed for the intended workflow and authorized for the recipient. See the Privacy Notice for the service’s processing context.
4. Changes and contractual questions
Review this page alongside your customer agreement and any agreed processing schedule. A required subprocessor authorization, advance change notice, or objection process must be established in the actual agreement; publication of this list alone does not provide that process. The proposed Data Processing Addendum is available for customer and counsel review and binds only when expressly agreed.
Use the existing business contact identified in your customer agreement for provider and contractual questions. If your question concerns a case record handled by a customer organization, contact that organization first.
