Infrastructure and Hosting Jurisdictions
This page identifies the infrastructure used to provide the BRY3D Services and describes the jurisdictions and safeguards relevant to international governmental access. It is maintained pursuant to the Terms of Service and, where applicable, Regulation (EU) 2023/2854 (the "EU Data Act").
BRY3D's primary database, authentication, and storage infrastructure is deployed in the Central EU (Frankfurt) region in Germany. Optional integrations may process data in additional jurisdictions according to Customer configuration and the applicable provider's infrastructure.
1. Core infrastructure
| Provider | Function and data | Hosting jurisdiction |
|---|---|---|
| Hostinger International Ltd. | Public bry3d.com marketing and legal website. | United States. |
| Vercel Inc. | BRY3D dashboard application delivery, server-rendered pages, API routes, scheduled application jobs, and platform logs. | Globally distributed edge delivery. No fixed compute region or exclusive data-residency jurisdiction is guaranteed. |
| Supabase, Inc. | Primary PostgreSQL database, authentication, object storage, realtime delivery, and edge functions. Customer Content may include accounts, company settings, leads, contacts, quotes, communications, files, jobs, portal records, analytics, and configuration data. | Germany — Central EU (Frankfurt), the selected production region. |
2. Supporting and optional providers
The Services support the providers below. Processing occurs only where the relevant feature is configured or used. Provider infrastructure may be distributed across multiple countries under the provider's service terms and Customer configuration.
| Provider or category | Purpose | Data commonly involved |
|---|---|---|
| Stripe | Subscription checkout, billing, customer portal, payment events, and customer payment flows. | Account and company identifiers, billing contact information, subscription metadata, transaction and payment status; payment-card data is entered into Stripe-controlled interfaces. |
| Resend or a Customer-configured SMTP provider | Transactional and customer-directed email delivery. | Sender and recipient addresses, message subject and body, attachments, delivery metadata, and tracking events where enabled. |
| PostHog | Product analytics where configured. | Usage events, device and session metadata, and identifiers configured by BRY3D. |
| Sentry | Error monitoring and application diagnostics. | Error events, stack traces, request and device metadata, and diagnostic context subject to scrubbing configuration. |
| Calendar, Drive, Maps, OAuth, and Customer-selected integrations. | OAuth tokens, calendar events, Drive file metadata or content, addresses or map queries, and integration activity as applicable. | |
| Microsoft | Outlook calendar and OAuth integrations. | OAuth tokens, calendar events, user identifiers, and integration activity as applicable. |
| n8n | Customer-configured workflow automation. | Workflow definitions, event payloads, credentials or connection references, and data selected for an automation. |
| Meta | Customer-configured lead and conversion integrations. | Lead, event, campaign, attribution, and conversion data selected by Customer. |
| SignRequest | Optional external electronic-signature delivery. | Documents, signer identity and contact details, signature status, timestamps, and provider audit data. |
3. International governmental access safeguards
For non-personal data held in the European Union, BRY3D's policy is to use reasonable technical, organizational, and contractual measures intended to prevent international or third-country governmental access or transfer where that access or transfer would conflict with European Union law or the law of the relevant Member State.
- Access to production systems is restricted through account authentication, role-based permissions, service credentials, and least-privilege application controls.
- Production traffic uses encrypted HTTPS or equivalent encrypted provider connections. Provider-managed encryption at rest applies where included in the selected hosted service.
- Customer data is logically separated through company identifiers, database authorization rules, and row-level security policies.
- Privileged credentials are kept in server-side environment or secret-management facilities and are not delivered to browser clients.
- BRY3D evaluates a governmental demand for facial validity, authority, scope, jurisdiction, and conflicts with applicable law; seeks clarification, narrowing, protective treatment, or challenge where there is a reasonable basis; and discloses only data legally required.
- BRY3D will notify the affected Customer before disclosure unless legally prohibited and, where delayed notice is permitted, will provide notice after the prohibition expires.
- Third-party providers may publish their own law-enforcement-request policies and transparency reports. Their independent legal obligations and infrastructure jurisdictions also apply.
These measures do not constitute a guarantee that a government will never seek or obtain access. Requests concerning infrastructure, governmental access, or a customer-specific deployment must be directed to admin@bry3d.com.
4. Changes to this page
BRY3D will update this page when a core hosting provider or hosting jurisdiction materially changes. Optional providers may change when Customer enables, disables, or replaces an integration. Infrastructure descriptions reflect the date shown above and may change.