Draft for legal review

Subprocessors

Only providers confirmed to be in use by the application are listed. Any detail we have not verified in writing with the provider is marked as unconfirmed rather than assumed. Processing roles, locations, retention periods, transfer mechanisms and data processing agreements are being confirmed and must be documented before public launch.

Effective date: To be confirmed before public launch

Last updated: 28 July 2026

Version: Draft 0.1

Status: Draft for legal review

Operated by: Mohammad Asif, trading as PublicVoiceShield, United Kingdom

This document is provided for information only. It is not legal advice and no guarantee of compliance is given. Designed to support UK GDPR compliance, subject to organisational use, configuration and legal review.

Lovable / Lovable Cloud — managed backend built on Supabase infrastructure (application hosting, database, authentication)

Purpose: Application hosting, managed database and authentication.

Categories of data: Account details, organisation records, submitted posts and threads, AI analyses, human decisions, audit and security records.

Integration status: Active — verified in the application code path

Controller / processor role: Unconfirmed — processor expected

Processing location: Unconfirmed

Retention: Unconfirmed

Data processing agreement: Unconfirmed — no data processing agreement obtained

Transfer mechanism: Unconfirmed

Last reviewed: August 2026

Verification source: Code review of hosting, database and authentication clients

OpenAI (AI model processing)

Purpose: Direct model processing for analysis, classification, recommendations, drafted replies, research synthesis, and the help and support assistants.

Categories of data: Submitted post text, selected discussion text, chosen source passages, the selected tone and identity, help and support questions, and the model responses.

Integration status: Active — verified in the application code path

Controller / processor role: Processor

Processing location: Unconfirmed — to be assessed against the executed DPA

Retention: Response-object storage disabled with store: false on supported requests. OpenAI may retain API content in abuse-monitoring logs for up to 30 days under its standard API data controls. Zero Data Retention is not enabled.

Data processing agreement: Accepted — OpenAI Data Processing Addendum v.010126, effective 1 January 2026, executed 6 August 2026. OpenAI may use sub-processors listed in its published Sub-Processor List under the terms of its DPA.

Transfer mechanism: Unconfirmed — transfer mechanism to be assessed against the executed DPA

Last reviewed: August 2026

Verification source: Code review of the AI routing layer plus live provider model-list check

Lovable AI Gateway (owner-only fallback)

Purpose: Emergency fallback transport, selectable by the platform owner only.

Categories of data: As sent for an AI task, only if the owner selects the fallback route.

Integration status: Not used for live customer analysis. Retained for rollback.

Controller / processor role: Unconfirmed

Processing location: Unconfirmed

Retention: Unconfirmed

Data processing agreement: Unconfirmed — no data processing agreement obtained

Transfer mechanism: Unconfirmed

Last reviewed: August 2026

Verification source: Code review of the AI routing layer

Lovable email service

Purpose: Authentication emails (sign-up, magic link, password recovery, email change, reauthentication) and membership or support notifications.

Categories of data: Email address, name where supplied, message content.

Integration status: Active — verified as the authentication email code path

Controller / processor role: Unconfirmed

Processing location: Unconfirmed

Retention: Unconfirmed

Data processing agreement: Unconfirmed

Transfer mechanism: Unconfirmed

Last reviewed: August 2026

Verification source: Code review of the authentication email webhook and templates

Brave Search

Purpose: Retrieve authoritative public sources when a user deliberately selects a public-source search.

Categories of data: A search query derived from the discussion, with personal data redacted before it leaves the service.

Integration status: Active — user-initiated only

Controller / processor role: Unconfirmed

Processing location: Unconfirmed

Retention: Unconfirmed

Data processing agreement: Unconfirmed

Transfer mechanism: Unconfirmed

Last reviewed: August 2026

Verification source: Code review of the search provider layer

Zoho Mail

Purpose: PublicVoiceShield business mailboxes for support, privacy and security correspondence.

Categories of data: Inbound and outbound business correspondence.

Integration status: Active for business mailboxes only. Not part of the authentication email code path.

Controller / processor role: Unconfirmed

Processing location: Unconfirmed

Retention: Unconfirmed

Data processing agreement: Unconfirmed

Transfer mechanism: Unconfirmed

Last reviewed: August 2026

Verification source: Operational review; no application code path

GitHub

Purpose: Source code repository and development history.

Categories of data: Source code, documentation and commit metadata. Customer content is not stored here.

Integration status: Active — development only

Controller / processor role: Unconfirmed

Processing location: Unconfirmed

Retention: Unconfirmed

Data processing agreement: Unconfirmed

Transfer mechanism: Unconfirmed

Last reviewed: August 2026

Verification source: Operational review

Payment provider

Purpose: Payment processing.

Categories of data: None currently.

Integration status: Not integrated — no payment code path exists in the application.

Controller / processor role: Not applicable

Processing location: Not applicable

Retention: Not applicable

Data processing agreement: Not applicable

Transfer mechanism: Not applicable

Last reviewed: August 2026

Verification source: Code review

Changes

New subprocessors will be added to this page. Questions or objections: privacy@publicvoiceshield.com.