Draft for legal review
Subprocessors
Only providers confirmed to be in use by the application are listed. Any detail we have not verified in writing with the provider is marked as unconfirmed rather than assumed. Processing roles, locations, retention periods, transfer mechanisms and data processing agreements are being confirmed and must be documented before public launch.
Effective date: To be confirmed before public launch
Last updated: 28 July 2026
Version: Draft 0.1
Status: Draft for legal review
Operated by: Mohammad Asif, trading as PublicVoiceShield, United Kingdom
This document is provided for information only. It is not legal advice and no guarantee of compliance is given. Designed to support UK GDPR compliance, subject to organisational use, configuration and legal review.
Lovable / Lovable Cloud — managed backend built on Supabase infrastructure (application hosting, database, authentication)
Purpose: Application hosting, managed database and authentication.
Categories of data: Account details, organisation records, submitted posts and threads, AI analyses, human decisions, audit and security records.
Integration status: Active — verified in the application code path
Controller / processor role: Unconfirmed — processor expected
Processing location: Unconfirmed
Retention: Unconfirmed
Data processing agreement: Unconfirmed — no data processing agreement obtained
Transfer mechanism: Unconfirmed
Last reviewed: August 2026
Verification source: Code review of hosting, database and authentication clients
OpenAI (AI model processing)
Purpose: Direct model processing for analysis, classification, recommendations, drafted replies, research synthesis, and the help and support assistants.
Categories of data: Submitted post text, selected discussion text, chosen source passages, the selected tone and identity, help and support questions, and the model responses.
Integration status: Active — verified in the application code path
Controller / processor role: Processor
Processing location: Unconfirmed — to be assessed against the executed DPA
Retention: Response-object storage disabled with store: false on supported requests. OpenAI may retain API content in abuse-monitoring logs for up to 30 days under its standard API data controls. Zero Data Retention is not enabled.
Data processing agreement: Accepted — OpenAI Data Processing Addendum v.010126, effective 1 January 2026, executed 6 August 2026. OpenAI may use sub-processors listed in its published Sub-Processor List under the terms of its DPA.
Transfer mechanism: Unconfirmed — transfer mechanism to be assessed against the executed DPA
Last reviewed: August 2026
Verification source: Code review of the AI routing layer plus live provider model-list check
Lovable AI Gateway (owner-only fallback)
Purpose: Emergency fallback transport, selectable by the platform owner only.
Categories of data: As sent for an AI task, only if the owner selects the fallback route.
Integration status: Not used for live customer analysis. Retained for rollback.
Controller / processor role: Unconfirmed
Processing location: Unconfirmed
Retention: Unconfirmed
Data processing agreement: Unconfirmed — no data processing agreement obtained
Transfer mechanism: Unconfirmed
Last reviewed: August 2026
Verification source: Code review of the AI routing layer
Lovable email service
Purpose: Authentication emails (sign-up, magic link, password recovery, email change, reauthentication) and membership or support notifications.
Categories of data: Email address, name where supplied, message content.
Integration status: Active — verified as the authentication email code path
Controller / processor role: Unconfirmed
Processing location: Unconfirmed
Retention: Unconfirmed
Data processing agreement: Unconfirmed
Transfer mechanism: Unconfirmed
Last reviewed: August 2026
Verification source: Code review of the authentication email webhook and templates
Brave Search
Purpose: Retrieve authoritative public sources when a user deliberately selects a public-source search.
Categories of data: A search query derived from the discussion, with personal data redacted before it leaves the service.
Integration status: Active — user-initiated only
Controller / processor role: Unconfirmed
Processing location: Unconfirmed
Retention: Unconfirmed
Data processing agreement: Unconfirmed
Transfer mechanism: Unconfirmed
Last reviewed: August 2026
Verification source: Code review of the search provider layer
Zoho Mail
Purpose: PublicVoiceShield business mailboxes for support, privacy and security correspondence.
Categories of data: Inbound and outbound business correspondence.
Integration status: Active for business mailboxes only. Not part of the authentication email code path.
Controller / processor role: Unconfirmed
Processing location: Unconfirmed
Retention: Unconfirmed
Data processing agreement: Unconfirmed
Transfer mechanism: Unconfirmed
Last reviewed: August 2026
Verification source: Operational review; no application code path
GitHub
Purpose: Source code repository and development history.
Categories of data: Source code, documentation and commit metadata. Customer content is not stored here.
Integration status: Active — development only
Controller / processor role: Unconfirmed
Processing location: Unconfirmed
Retention: Unconfirmed
Data processing agreement: Unconfirmed
Transfer mechanism: Unconfirmed
Last reviewed: August 2026
Verification source: Operational review
Payment provider
Purpose: Payment processing.
Categories of data: None currently.
Integration status: Not integrated — no payment code path exists in the application.
Controller / processor role: Not applicable
Processing location: Not applicable
Retention: Not applicable
Data processing agreement: Not applicable
Transfer mechanism: Not applicable
Last reviewed: August 2026
Verification source: Code review
Changes
New subprocessors will be added to this page. Questions or objections: privacy@publicvoiceshield.com.