GDPR Article 28 Transparency

Sub-Processor List

ArvexLab uses the following sub-processors to deliver our compliance platform services. This list is maintained as part of our commitment to transparency under GDPR Article 28(2).

Last Updated: February 25, 2026 · Version: 1.0

Changes to this list are communicated to data controllers with at least 14 days advance notice, as specified in our Data Processing Agreement (DPA).

Supabase Inc.

Database, Authentication, File Storage

Location: EU (Frankfurt, Germany)
Transfer Mechanism: EU data residency — no transfer
Website: supabase.com

Vercel Inc.

Application Hosting, Edge Functions, CDN

Location: EU (Frankfurt) + Global Edge
Transfer Mechanism: EU-US Data Privacy Framework
Website: vercel.com

Google LLC (Gemini 2.5 Flash)

AI Evidence Mapping, Policy Assessment

Location: EU Data Processing
Transfer Mechanism: EU Cloud Data Processing Addendum
Website: cloud.google.com

Anthropic PBC (Claude Haiku 4.5 / Sonnet 4)

AI Document Parsing, Contract Analysis, Board Reports

Location: United States
Transfer Mechanism: Standard Contractual Clauses
Website: anthropic.com

Resend Inc.

Transactional Email Delivery

Location: United States
Transfer Mechanism: EU-US Data Privacy Framework
Website: resend.com

SecurityScorecard Inc.

Vendor Security Rating & Monitoring

Location: United States
Transfer Mechanism: EU-US Data Privacy Framework
Website: securityscorecard.com

Have I Been Pwned (Troy Hunt)

Data Breach Monitoring

Location: Australia / United States
Transfer Mechanism: Standard Contractual Clauses
Website: haveibeenpwned.com

OpenSanctions

Sanctions & PEP Screening

Location: European Union
Transfer Mechanism: EU data residency — no transfer
Website: opensanctions.org

GLEIF (Global LEI Foundation)

Legal Entity Identifier Verification

Location: Switzerland / European Union
Transfer Mechanism: Adequacy decision (Switzerland)
Website: gleif.org

NewsAPI GmbH

Business Intelligence News Feeds

Location: European Union
Transfer Mechanism: EU data residency — no transfer
Website: newsapi.org

International Data Transfer Summary

RegionSub-ProcessorsSafeguard
EU / EEASupabase, Google (Gemini), OpenSanctions, GLEIF, NewsAPINo transfer required
United StatesVercel, Anthropic, Resend, SecurityScorecardEU-US Data Privacy Framework
Australia / USHIBPStandard Contractual Clauses
SwitzerlandGLEIFAdequacy Decision

Change Notification Process

In accordance with our DPA, ArvexLab will notify data controllers at least 14 days before engaging a new sub-processor or changing an existing one. Controllers have the right to object within this period. If an objection cannot be resolved, the controller may terminate the affected services under the terms of the MSA.

To receive sub-processor change notifications, contact privacy@arvexlab.com.

Questions?

For questions about our sub-processors or data processing practices: