Last updated: June 2026

Sub-processors

pmdox uses the following third-party providers ("sub-processors") to operate the Service. This page is updated whenever we add or change a sub-processor. We will give at least 30 days' notice of any new sub-processor by updating this page and, for business customers under a DPA, by email.

ProviderPurposeDataLocationTransfer mechanism
Lovable Cloud (Supabase on AWS)Database, authentication, file storage, edge runtimeAll account and project dataEU — Ireland (eu-west-1)None — data hosted inside the EEA
Google AI Studio (Gemini)LLM inference powering doxAssist (document generation), doxChat (project chat), doxScan (integrity checks), upload extraction, and questionnaire assistPrompts + project context (charter, RAID, scope, uploaded document text) needed to generate the requested artifact or answerUS (Google LLC)Standard Contractual Clauses; EU–US Data Privacy Framework
Stripe (Stripe Payments Europe, Ltd.)Subscription billing and payment processing for paid plans (Stripe Checkout, customer portal, webhook events)Name, billing email, billing address, payment method token, Stripe customer/subscription IDs, plan and invoice history. Card numbers are entered directly into Stripe — pmdox never sees or stores them.EU (Ireland) with US processing by Stripe, Inc.Standard Contractual Clauses; EU–US Data Privacy Framework
Google Analytics 4 (Google Ireland Ltd)Aggregate product analytics — only after you opt inPseudonymous client ID + your pmdox user UUID (no email), page paths, IP-anonymisedEU collection / US processingStandard Contractual Clauses; EU–US Data Privacy Framework
Lovable Email (Resend)Transactional email — sign-up confirmation, password reset, account notices, billing receipts, weekly project digest, and notification emailsEmail address, recipient name, message body, delivery and bounce metadataEUNone — data hosted inside the EEA
Cloudflare, Inc.CDN, edge runtime, DDoS protection, IP geolocationIP address, request metadataGlobal edge networkStandard Contractual Clauses; EU–US Data Privacy Framework

How we vet sub-processors

  • Each provider is bound by a data processing agreement (DPA).
  • Cross-border transfers rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and the Swiss addendum where relevant.
  • Providers certified under the EU–US Data Privacy Framework are noted above.

Service availability

pmdox is not offered in jurisdictions subject to comprehensive sanctions (currently Cuba, Iran, North Korea, Syria, and the Crimea, Donetsk, and Luhansk regions of Ukraine), and we do not currently offer service to mainland China (PIPL) or the Russian Federation (Federal Law 152-FZ). Access from those regions may be blocked at the network edge.

Questions

Email info@pmdox.com to request our DPA or ask about a specific sub-processor.