Files
supabase/apps/www/data
claude[bot]andClaude 7776b1f7ee docs(www): add Data Residency and Transfers FAQ legal page and Privacy Resources hub section (#51318)
<!-- ccr-slack-attribution -->
_Requested by **Sofia Calado** · [Slack
thread](https://supabase.slack.com/archives/C0161K73J1J/p1791273150504749?thread_ts=1791273150.504749&cid=C0161K73J1J)_

**Before:** The Data Residency and Transfers FAQ only existed as a PDF.
The Legal Hub (`/legal`) listed the Data Processing Addendum and the
Subprocessor List under "Customer Legal Resources", with no
privacy-specific grouping.

**After:** The FAQ is a native, indexable page at
`/legal/privacy-resources/data-residency-and-transfers-faq`. The Legal
Hub has a new "Privacy Resources" section with the Data Processing
Addendum, the Subprocessor List and the FAQ. The DPA and Subprocessor
List URLs are unchanged.

This publishes the FAQ as a web page and groups it with the other
privacy documents in the Legal Hub.

## Problem

The FAQ needs to be discoverable on supabase.com (including search) and
linked from the Legal Hub next to the DPA and Subprocessor List.

## Solution

How: the page mirrors the DPA shell (`DefaultLayout` > `NextSeo` >
`PageHeader` with `PageBreadcrumb` > `MDXProvider` > `LegalDocVersions`)
with a single `v1` entry. The body is
`data/legal/privacy-resources/data-residency-and-transfers-faq/v1.mdx`,
transcribed verbatim from the source PDF (17 questions in 9 sections),
with one correction confirmed by the requester: the marketplace Note
names "Supabase, Inc.", and the "plan documentation" link points to
`/docs/guides/platform/backups`. The Transfer Impact Assessment has no
direct link, so it and the Trust Center link go to
`https://trust.supabase.io`, as confirmed by the requester. The version
date reads "October 6, 2026", per the requester (the source PDF gave
only the month), and the closing "Last updated / Owner" line from the
PDF is dropped. Further edits made at the requester's direction: the
Usage Information bullet in the retention answer no longer states a log
purge period, and the Usage Information category in the data-location
answer now says "processors". PDF hyperlinks are mapped to real routes.
The hub gets a `privacy-resources` section, and the DPA and Subprocessor
List breadcrumbs now point to it (text and anchor only). The sitemap is
generated from `pages/**/*.tsx`, so the new route is included without
changes.

## Review instructions

1. Open `/legal` and check the "Privacy Resources" section lists the
three documents, and "Customer Legal Resources" still lists Terms of
Service, Support Policy and Service Level Agreement.
2. Open `/legal/privacy-resources/data-residency-and-transfers-faq` and
compare the text with the source PDF.
3. Click through the links in the page, and the breadcrumbs on the DPA
and Subprocessor List pages.

## Open questions for Legal

None remaining. The requester's edits are applied: the closing "Last
updated" line is removed, the ISO 27001 / SOC 2 link goes to
`/security`, the "Legal Hub" link in the subprocessor question goes to
`/legal`, and the meta description wording is confirmed.

## Checks

- `pnpm install --filter www...` worked. Prettier check passes on the
touched files, MDX compiles, and `next dev` renders both `/legal` and
the new page (200, indexable, canonical set).
- Full `tsc`/lint/`next build` were not run as CI-equivalent.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_012JHSu7iLpQ3XPfmfQzFraw

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-10-08 10:01:57 +11:00
..
2022-10-14 17:12:44 +08:00
2026-07-03 15:00:43 +10:00
2023-12-12 16:41:16 +01:00
2026-07-03 15:00:43 +10:00
2022-10-13 10:42:36 +08:00
2026-06-26 15:47:52 +02:00
2026-10-02 16:14:13 +02:00
2026-07-03 15:00:43 +10:00
2022-12-05 23:52:44 -05:00
2026-09-11 12:17:49 +08:00
2024-12-05 15:05:47 +00:00
2024-12-04 21:42:23 +08:00