Supplier and Data-Flow Register
Verified against active Cloudflare Worker bindings on July 22, 2026. This is an operational register, not a substitute for reviewing each supplier's DPA, subprocessor list, processing regions and transfer mechanism.
Core platform and operations
- Cloudflare — hosting, Workers, D1, R2, KV, Queues, Durable Objects, Workflows, Browser Rendering, Workers AI, Vectorize, security and AI Gateway. Data: account, content, messages, transcripts, technical and security records.
- Passion.io — native/web app, courses, access, community, private messages and notifications. Data: account, progress, community and message data.
- HighLevel / LeadConnector — CRM, forms, websites, email, contact identity, progression, access and guarantee workflow. Data: contact, programme, business, campaign and claim status.
- Google Workspace / Apps Script — operational documents, sheets, assessments and approved automation. Data depends on the workflow.
- Google Workspace, Google APIs and Gemini — OAuth, Docs, Drive, Calendar, YouTube publication, configured model fallback and related user-authorised Google connections.
- Google Gemini / Google AI services — language-model fallback for selected assessment and analysis workflows routed through an authorised gateway. Data: only the minimised prompt, transcript excerpt or assessment material required for that task.
- Slack — internal Messenger Center approval, support and operational alerts. Data: relevant message excerpts, drafted replies and operational metadata.
- Zapier — event automation between authorised systems. Data: the minimum event payload required by each Zap.
AI, audio and content production
- Cloudflare Workers AI — assignment classification, message analysis and retrieval/embedding tasks inside Cloudflare, including configured Meta Llama and BAAI models.
- Anthropic — language-model analysis and drafting routed through configured gateways.
- AssemblyAI — transcription and LLM gateway processing.
- Descript — user-authorised recording, transcription and production source workflow.
- ElevenLabs — authorised synthetic-voice and audio production. Data can include scripts, recordings, voice samples and generated audio.
- Placid — generated visual assets.
- VideoAsk / Typeform — assessment, form or video-form collection where the relevant flow is enabled.
- Sendspark — personalised video workflow.
- Vimeo — video hosting and delivery.
Podcast, promotion and distribution
- Captivate — podcast hosting, RSS publication and analytics workflows.
- Ayrshare — scheduling and publication to user-connected social platforms.
- Publer — customer-authorised social scheduling where a legacy PPA workflow or connected customer account still uses it. Publer is not the current audit route for the PPA Implementation Guarantee; Mr. Podcast Suite is.
- Spotify — user-connected or public podcast distribution and metadata.
- YouTube / Google — user-connected video publication, discovery and Google Workspace services.
- Apple Podcasts / iTunes directory — public podcast metadata and RSS discovery; generally a public data source or independent platform, not an instructed processor for this use.
- Meta — advertising and user-connected social distribution where enabled.
Website analytics, attribution and delivery
- HYROS — consent-based marketing attribution where enabled. Data can include page, campaign, device, transaction and contact-matching signals.
- Google Tag Manager and related Google measurement services — consent-controlled loading of analytics or advertising tags where configured.
- Bunny Fonts — website-font delivery and ordinary technical request metadata.
Non-essential analytics and advertising tags must not load before valid consent. The live page and tag configuration, not merely the Privacy Policy, determines whether this requirement is met.
Sales, payment and B2B outreach
- Stripe — payment, invoicing, fraud prevention and transaction status where used.
- Instantly — relevant B2B outreach, reply state and suppression.
- Rephonic — professional and public podcast discovery and enrichment.
Public directories and independent platforms
The Workers can read public metadata or construct user-facing links for Apple Podcasts, Spotify, YouTube, Amazon Music, Acast, Podtail, Podimo, Podcast Addict, Podfriend, Hubhopper and similar directories. These services are normally public sources or independent platforms in that use, not MPriet processors. A platform may have a different role if a user separately connects an account for publication or advertising.
Active Worker evidence
- `instantly-ghl-worker-v1`: HighLevel, Instantly, Cloudflare.
- `mp26-worker-0-podcast-finder`: Rephonic, HighLevel, Slack, Cloudflare.
- `mp26-worker-6-message-center`: Passion, HighLevel, Slack, Google Workspace, Anthropic, AssemblyAI, Cloudflare Workers AI and Cloudflare data services.
- `mr-podcast-cold-funnel-sentinel`: Cloudflare and internal service bindings.
- `mr-podcast-suite`: HighLevel, AssemblyAI, Ayrshare, Captivate, Placid, Spotify, YouTube and Cloudflare AI/data/browser services; Descript is a user-level connected production source where enabled.
- `mrpodcast-legal`: Cloudflare hosting only.
- `podcast-profit-assessment-worker-v1`: VideoAsk, HighLevel, Google Workspace, Instantly, Anthropic, AssemblyAI, Google Gemini fallback and Cloudflare.
- `rephonicv16-lifecycle-category`: Rephonic workflow, HighLevel, Instantly, Anthropic and Cloudflare.
- `video-pipeline-worker-v2-native`: HighLevel, Sendspark, Vimeo and Cloudflare.
- `w7-growth-engine`: HighLevel, Instantly, Meta, Slack, Stripe, Vimeo, Zapier, AssemblyAI and Cloudflare.
Required controller actions
- Obtain and retain a current DPA for each processor.
- Record whether each supplier is processor, subprocessor, joint controller or independent controller for each use case.
- Record countries and remote-access locations, not only the supplier's registered address.
- For transfers outside the EEA, record adequacy status or SCC module, transfer-impact assessment and supplementary measures.
- Subscribe to subprocessor change notices and review changes before they take effect where possible.
- Record purposes, categories, recipients, access roles, security measures and deletion schedule in the Article 30 record.
- Remove unused credentials and stop sending data to retired integrations.
- Run a documented annual review and an event-driven review when a Worker gains a new external binding.