Sub-processor Register
Last updated: March 15, 2026
This page lists third-party processors used by Legalithm to deliver the service. We maintain this register to support GDPR transparency obligations and customer due diligence.
If we intend to add or replace a sub-processor that materially changes processing risk, we provide advance notice to customers and a reasonable window to raise objections.
| Sub-processor | Purpose | Data Categories | Location | Transfer Safeguard | DPA |
|---|---|---|---|---|---|
| Supabase | Database hosting, authentication, and object storage | Account data, service data, encrypted application records | Germany (EU) | No international transfer for core storage (EU-hosted project) | DPA Link |
| Vercel | Application hosting and delivery infrastructure | Application logs, runtime metadata, request diagnostics | EU region primary with global edge delivery | SCC-based transfer safeguards where non-EEA processing occurs | DPA Link |
| OpenAI | AI inference for compliance analysis and drafting assistance | User-submitted AI system descriptions and regulatory prompts | United States | EU SCCs + contractual no-training/no-retention controls where configured | DPA Link |
| Resend | Transactional email delivery | Recipient email, message metadata, delivery events | United States | EU SCCs | DPA Link |
| Sentry | Error monitoring and reliability diagnostics | Error traces, service metadata, scrubbed operational context | United States / EU routing options | EU SCCs + data scrubbing controls | DPA Link |
| PostHog | Product analytics and event telemetry | Pseudonymous usage events and product interaction metrics | EU cloud (Frankfurt) | Configured for EU data residency | DPA Link |
Contact
For sub-processor questions or objections, contact privacy@legalithm.com.