Subprocessors
Effective: August 2026
ProofInk.AI uses a limited number of third-party service providers ("subprocessors") to operate our service. This page lists all subprocessors that may process your data.
We will update this page when subprocessors are added or removed. If you are an institutional customer with a Data Processing Agreement, we will notify you of changes in advance as specified in your agreement.
Current Subprocessors
| Subprocessor | Purpose | Data Processed | Location | Compliance |
|---|---|---|---|---|
| Anthropic | AI analysis (Claude API) | Document text content (for generating feedback reports) | United States | SOC 2 Type II, GDPR |
| OpenAI | AI analysis (API) | Document text content (for generating feedback reports) | United States | SOC 2 Type II, GDPR |
| Paddle | Merchant of Record, payment processing, tax compliance (privacy) | Email, payment details (no document content) | United Kingdom | PCI DSS Level 1, SOC 2, GDPR |
| Resend | Transactional email delivery — address verification, password reset, account and billing notices (privacy) | Email address and message content (no document content) | United States | SOC 2 Type II, GDPR |
| DigitalOcean | Infrastructure hosting and encrypted off-site backup storage (DigitalOcean Spaces) | All uploaded documents and stored review data (encrypted at rest) | United States | SOC 2 Type II, ISO 27001 |
| Cloudflare | DNS, CDN, DDoS protection, Web Analytics | Web traffic metadata, anonymous aggregate analytics (no document content, no PII) | Global | SOC 2 Type II, ISO 27001, GDPR |
| Sentry | Application error monitoring and performance tracing (privacy) | Error diagnostics and technical request metadata (no document content, no personal data) | United States | SOC 2 Type II, ISO 27001, GDPR |
Data Processing Commitments
- AI providers (Anthropic, OpenAI): data sent via their APIs is not used for model training. API data is automatically deleted after a short safety-monitoring period.
- Paddle: acts as Merchant of Record, handling payment data and global tax compliance under PCI DSS Level 1 compliance. We do not store credit card details.
- Resend: delivers transactional email only (verification links, password resets, account and billing notices). It receives your email address and the message body. It never receives uploaded documents or review content, and we do not use it for marketing email.
- DigitalOcean: hosts our application and managed database. The managed database is encrypted at rest, as is DigitalOcean Spaces object storage, where our off-site backups are held in the United States after we encrypt them with AES-256.
- Cloudflare: provides SSL/TLS termination and DDoS protection. Does not access document content.
- Sentry: receives application error reports and performance traces. We configure it to send no personal data, no request bodies, and no stack-frame variables, so uploaded documents and review content are never transmitted. Used solely to detect and diagnose faults.
What We Do NOT Use
- No third-party analytics services (Google Analytics, Mixpanel, Amplitude, etc.)
- No advertising networks or data brokers
- No customer data platforms or marketing automation tools
- No third-party error tracking that receives document content — our error monitor (Sentry, listed above) is configured to exclude request bodies and stack-frame variables
Last updated: August 2026
Contact
For questions about our subprocessors or to request notification of changes, email [email protected].