Fideria engages the sub-processors below to deliver the AI Investment Overview platform. Each is bound by a written data-processing agreement and provides safeguards equivalent to those Fideria offers its customers. All production customer data is stored in the EU.
| Sub-processor | Purpose | Data categories | Region |
|---|---|---|---|
| Supabase (Lovable Cloud) | Application database, authentication, file storage | Account, profile, audit log, customer content | EU (Frankfurt) |
| Cloudflare | Application hosting, CDN, edge compute, DDoS protection | IP address, request metadata, application traffic | EU edge (global routing) |
| Resend | Transactional email delivery (sign-in links, notifications) | Email address, message content | EU |
| Lovable AI Gateway | Routing layer for in-product AI inference calls | Prompt content, model metadata (not retained for training) | EU |
| Anthropic | AI inference for in-product assistance (via gateway) | Prompt content submitted by the user (zero-retention API) | EU/US (SCC) |
| OpenAI | AI inference for in-product assistance (via gateway) | Prompt content submitted by the user (zero-retention API) | EU/US (SCC) |
| Google (Workspace + OAuth) | Single sign-on (Google), discovery of AI usage in Workspace, internal operations | Email, name, OAuth identifier, Workspace audit metadata (only when customer connects) | EU/US (SCC) |
| Microsoft (Entra ID + Graph) | SSO (Entra ID) and discovery of AI usage in Microsoft 365 (only when customer connects) | Email, name, directory metadata, app inventory | EU/US (SCC) |
| Slack | Discovery of AI tools mentioned in customer's Slack workspace (only when connected) | Channel metadata, message snippets containing tool references | EU/US (SCC) |
| Notion | Discovery of AI tools referenced in customer's Notion workspace (only when connected) | Page titles, content snippets containing tool references | EU/US (SCC) |
| Okta | SAML SSO (only when customer configures Okta as identity provider) | Email, name, directory metadata | EU/US (SCC) |
Change notifications
Customers on a paid plan receive at least 30 days' advance notice of any intended addition or replacement of a sub-processor. To subscribe to change notifications, email privacy@fideria.ai with the subject line "Sub-processor updates".
Objections
Customers may object on reasonable data-protection grounds. If the objection cannot be resolved, the customer may terminate the affected portion of the Service in accordance with the master agreement.