{
  "version": "2026-07-15",
  "notice_period_days": 30,
  "subscribe_email": "subprocessors@connectandflow.app",
  "subprocessors": [
    { "name": "Lovable Cloud (Supabase)", "purpose": "Primary database, authentication, object storage", "data": "All customer data (identifiers, messages, attachments, telemetry)", "storage_region": "EU or US (per project region)", "access_from": "Global (support access from EU/US)", "transfer": ["SCCs Module 3 (Processor → Processor)", "UK IDTA", "Swiss addendum"], "dpa_date": null, "tia_date": null, "url": "https://supabase.com/privacy" },
    { "name": "Lovable AI Gateway", "purpose": "LLM inference gateway (chat completions, embeddings, image/audio generation) for in-product AI features", "data": "Prompt content, model I/O, request metadata; no long-term storage of prompts by upstream providers per gateway policy", "storage_region": "US / EU (per upstream model provider)", "access_from": "US / EU", "transfer": ["SCCs Module 3 (Processor → Processor)", "UK IDTA"], "dpa_date": null, "tia_date": null, "url": "https://lovable.dev/legal/privacy" },
    { "name": "OPSWAT MetaDefender", "purpose": "Attachment malware scanning and content disarm", "data": "Uploaded file bytes and derived hashes (transient scan only; not retained)", "storage_region": "US (transient)", "access_from": "US", "transfer": ["SCCs Module 3 (Processor → Processor)", "UK IDTA"], "dpa_date": null, "tia_date": null, "url": "https://www.opswat.com/legal/privacy-policy" },
    { "name": "Cloudflare", "purpose": "Edge network, TLS termination, DDoS mitigation, object storage", "data": "Request metadata, IP addresses, cached static assets", "storage_region": "Global edge (nearest PoP)", "access_from": "Global", "transfer": ["SCCs Module 3 (Processor → Processor)", "UK IDTA"], "dpa_date": null, "tia_date": null, "url": "https://www.cloudflare.com/privacypolicy/" },
    { "name": "Stripe", "purpose": "Payments processing (only when billing is enabled)", "data": "Billing contact, tokenized card metadata (last 4, brand); card data never touches our servers", "storage_region": "US / EU", "access_from": "US / EU", "transfer": ["SCCs Module 2 (Controller → Processor)", "UK IDTA"], "dpa_date": null, "tia_date": null, "url": "https://stripe.com/privacy", "optional": true },
    { "name": "Postmark", "purpose": "Transactional email and email-to-channel bridging", "data": "Recipient email addresses, message subject and body", "storage_region": "US or EU (per account)", "access_from": "US", "transfer": ["SCCs Module 2 (Controller → Processor)"], "dpa_date": null, "tia_date": null, "url": "https://postmarkapp.com/eu-privacy" },
    { "name": "Slack Technologies", "purpose": "Slack channel bridging (only when a workspace connects Slack)", "data": "Slack user IDs, channel names, message content routed through the connected channel", "storage_region": "US", "access_from": "US", "transfer": ["SCCs Module 3 (Processor → Processor)"], "dpa_date": null, "tia_date": null, "url": "https://slack.com/trust/privacy", "optional": true },
    { "name": "Freshworks (Freshdesk)", "purpose": "Helpdesk ticket bridging (only when connected)", "data": "Ticket content, contact fields", "storage_region": "US / EU (per account)", "access_from": "US / India", "transfer": ["SCCs Module 3 (Processor → Processor)"], "dpa_date": null, "tia_date": null, "url": "https://www.freshworks.com/privacy/", "optional": true },
    { "name": "Zendesk", "purpose": "Helpdesk ticket bridging (only when connected)", "data": "Ticket content, contact fields", "storage_region": "US / EU (per account)", "access_from": "US", "transfer": ["SCCs Module 3 (Processor → Processor)"], "dpa_date": null, "tia_date": null, "url": "https://www.zendesk.com/company/agreements-and-terms/privacy-notice/", "optional": true },
    { "name": "Intercom", "purpose": "Helpdesk / conversations bridging (only when connected)", "data": "Conversation content, contact fields", "storage_region": "US / EU (per account)", "access_from": "US", "transfer": ["SCCs Module 3 (Processor → Processor)"], "dpa_date": null, "tia_date": null, "url": "https://www.intercom.com/legal/privacy", "optional": true }
  ]
}
