Legal
To deliver the Artivex platform we use a small number of third-party subprocessors that may process Customer Personal Data on our behalf. This page lists every subprocessor currently in use, what they do, and where data is hosted.
We require all subprocessors to maintain appropriate technical and organisational security measures, and we have signed Data Processing Agreements (DPAs) and Standard Contractual Clauses (SCCs) where required.
| Provider | Purpose | Data hosted in |
|---|---|---|
| Supabase DPA |
Database, authentication, storage, and core platform infrastructure. Hosts all Customer data and AppSpec definitions. | EU (Frankfurt) |
| Vercel DPA |
Hosting and edge delivery for the Artivex platform and generated Customer applications. Logs and request metadata only — Customer Personal Data not stored at rest. | Global edge |
| Anthropic DPA |
AI model provider (Claude) used for AppSpec generation, classification, summarisation, and AI-powered automation steps. Inputs may include Customer-provided content; no training on your data. | US |
| OpenAI DPA |
Alternative AI model provider (GPT family) used as failover or when explicitly selected by the Customer. No training on your data. | US |
| Mistral AI Terms |
EU-resident AI model provider. Available as default for Customers who enable EU-only data residency for AI processing. | EU (Paris) |
| Stripe DPA |
Subscription billing, payment processing, and invoice management. | US (with EU data residency option) |
| Resend DPA |
Transactional email delivery — account verification, password reset, alerts, and Customer-configured workflow emails. | US |
| UptimeRobot Privacy |
Uptime monitoring and incident alerting for deployed Customer applications. Stores URL endpoints and uptime status only. | Global |
| GitHub DPA |
Source code hosting for generated Customer applications (private repositories per app). | US |
| Plausible Data policy |
Cookieless, GDPR-compliant analytics for the artivex.io marketing site. No personal data, no cookies, no cross-site tracking. | EU |
| Slack DPA |
Used as a delivery channel for Customer-configured workflow notifications when the Customer connects their Slack workspace. | US (with EU data residency option) |
By default, Customer data and AppSpec definitions are stored on Supabase in the EU (Frankfurt). Customers on any paid tier can enable an EU-only AI setting that restricts AI step processing to EU-hosted providers (Mistral) and excludes US-based providers (Anthropic, OpenAI) from the model registry for their workspace.
Some operational subprocessors (Vercel edge, Stripe, GitHub, UptimeRobot) may process limited metadata outside the EU. Where this involves personal data, transfers are governed by Standard Contractual Clauses (SCCs).
We will update this page whenever a subprocessor is added, removed, or replaced. Material changes will be communicated to active Customers by email at least 30 days in advance of taking effect, giving Customers an opportunity to object before the change is applied.
To receive subprocessor change notifications, ensure your account email is current and that you have not opted out of operational communications.
If you object to a current or proposed subprocessor on legitimate data protection grounds, please contact us at david@artivex.io. We will work in good faith to find a resolution. Where no resolution is possible, you may terminate your subscription in accordance with our Terms of Service.