pmdox uses the following third-party providers ("sub-processors") to operate the Service. This page is updated whenever we add or change a sub-processor. We will give at least 30 days' notice of any new sub-processor by updating this page and, for business customers under a DPA, by email.
| Provider | Purpose | Data | Location | Transfer mechanism |
|---|---|---|---|---|
| Lovable Cloud (Supabase on AWS) | Database, authentication, file storage, edge runtime | All account and project data | EU — Ireland (eu-west-1) | None — data hosted inside the EEA |
| Lovable AI Gateway (Google Gemini, OpenAI) | LLM inference for document generation, chat, integrity checks | Prompts + project context needed to generate the requested artifact | US (model providers) | Standard Contractual Clauses; EU–US Data Privacy Framework where applicable |
| Google Analytics 4 (Google Ireland Ltd) | Aggregate product analytics — only after you opt in | Pseudonymous client ID + your pmdox user UUID (no email), page paths, IP-anonymised | EU collection / US processing | Standard Contractual Clauses; EU–US Data Privacy Framework |
| Lovable Email | Transactional email (sign-up confirmation, password reset, account notices) | Email address, message body | EU | None — data hosted inside the EEA |
| Cloudflare | CDN, edge runtime, DDoS protection, IP geolocation | IP address, request metadata | Global edge network | Standard Contractual Clauses; EU–US Data Privacy Framework |
How we vet sub-processors
- Each provider is bound by a data processing agreement (DPA).
- Cross-border transfers rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and the Swiss addendum where relevant.
- Providers certified under the EU–US Data Privacy Framework are noted above.
Service availability
pmdox is not offered in jurisdictions subject to comprehensive sanctions (currently Cuba, Iran, North Korea, Syria, and the Crimea, Donetsk, and Luhansk regions of Ukraine), and we do not currently offer service to mainland China (PIPL) or the Russian Federation (Federal Law 152-FZ). Access from those regions may be blocked at the network edge.
Questions
Email info@pmdox.com to request our DPA or ask about a specific sub-processor.