pmdox uses the following third-party providers ("sub-processors") to operate the Service. This page is updated whenever we add or change a sub-processor. We will give at least 30 days' notice of any new sub-processor by updating this page and, for business customers under a DPA, by email.
| Provider | Purpose | Data | Location | Transfer mechanism |
|---|---|---|---|---|
| Lovable Cloud (Supabase on AWS) | Database, authentication, file storage, edge runtime | All account and project data | EU — Ireland (eu-west-1) | None — data hosted inside the EEA |
| Google AI Studio (Gemini) | LLM inference powering doxAssist (document generation), doxChat (project chat), doxScan (integrity checks), upload extraction, and questionnaire assist | Prompts + project context (charter, RAID, scope, uploaded document text) needed to generate the requested artifact or answer | US (Google LLC) | Standard Contractual Clauses; EU–US Data Privacy Framework |
| Stripe (Stripe Payments Europe, Ltd.) | Subscription billing and payment processing for paid plans (Stripe Checkout, customer portal, webhook events) | Name, billing email, billing address, payment method token, Stripe customer/subscription IDs, plan and invoice history. Card numbers are entered directly into Stripe — pmdox never sees or stores them. | EU (Ireland) with US processing by Stripe, Inc. | Standard Contractual Clauses; EU–US Data Privacy Framework |
| Google Analytics 4 (Google Ireland Ltd) | Aggregate product analytics — only after you opt in | Pseudonymous client ID + your pmdox user UUID (no email), page paths, IP-anonymised | EU collection / US processing | Standard Contractual Clauses; EU–US Data Privacy Framework |
| Lovable Email (Resend) | Transactional email — sign-up confirmation, password reset, account notices, billing receipts, weekly project digest, and notification emails | Email address, recipient name, message body, delivery and bounce metadata | EU | None — data hosted inside the EEA |
| Cloudflare, Inc. | CDN, edge runtime, DDoS protection, IP geolocation | IP address, request metadata | Global edge network | Standard Contractual Clauses; EU–US Data Privacy Framework |
How we vet sub-processors
- Each provider is bound by a data processing agreement (DPA).
- Cross-border transfers rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and the Swiss addendum where relevant.
- Providers certified under the EU–US Data Privacy Framework are noted above.
Service availability
pmdox is not offered in jurisdictions subject to comprehensive sanctions (currently Cuba, Iran, North Korea, Syria, and the Crimea, Donetsk, and Luhansk regions of Ukraine), and we do not currently offer service to mainland China (PIPL) or the Russian Federation (Federal Law 152-FZ). Access from those regions may be blocked at the network edge.
Questions
Email info@pmdox.com to request our DPA or ask about a specific sub-processor.