Sub-processors
The service providers that process personal data on our behalf, what each is used for, and where.
Current sub-processors
We use the service providers below to operate LegalReview. Each processes personal data on our instructions, as a processor, under a data protection agreement. Where a provider acts as an independent controller for its own purposes rather than on our instructions, this list says so; none of the providers below currently does.
Our Privacy Policy describes what we process and why. This page carries the specific providers, so that adding or replacing one does not require a change to that policy.
| Provider | Purpose | Personal data involved | Processing location | Transfer mechanism |
|---|---|---|---|---|
| Supabase, Inc. | Database, authentication and file storage | Account email addresses, organisation membership, monitoring history | European Union (Ireland) for primary project data; other locations may apply for support and subprocessors | SCCs where applicable |
| Vercel Inc. | Website and application hosting | Technical connection data, including IP addresses and request metadata | United States and other locations used by Vercel and its subprocessors | EU–U.S. Data Privacy Framework; SCCs where applicable |
| Brevo (Sendinblue SAS) | Transactional and notification email | Recipient email addresses and delivery records | European Union (France); subprocessors may operate in other locations | Not applicable for EU/EEA processing; appropriate transfer safeguards where applicable |
| PostHog Inc. | Product analytics, prompt storage and AI-generation traces | Usage events, account and organisation identifiers, and prompt or trace content where applicable | European Union (Frankfurt) for EU Cloud; limited processing or access may occur from other locations | SCCs where applicable |
What is not sent to an AI model
Your account data — your email address, your organisation and your subscription list — is not sent to an AI model. The input to those steps is the text of the public third-party documents being analysed. A public document may itself contain personal data, as described in section 4 of our Privacy Policy.
Changes to this list
We publish changes to this list here before a new provider begins processing. Customers with a data processing agreement may object to a new sub-processor in accordance with that agreement.
The version and date at the top of this page are the record of when it last changed.