Data Processors and Sub-processors

Last updated: April 2026

In compliance with Article 28 of the GDPR, we publish the complete and up-to-date list of external providers involved in processing personal data on behalf of LongevityMap. A Data Processing Agreement (DPA) is in place with all of them, guaranteeing protection levels equivalent to those required by the GDPR.

For transfers outside the European Economic Area, we apply the Standard Contractual Clauses (SCC) approved by the European Commission, together with additional technical measures when necessary.

Providers

ProviderService providedData processedLocationSafeguards
SupabaseDatabase and authenticationAll platform dataEU (Frankfurt)DPA + AES-256 encryption + PITR
VercelHosting, CDN and serverless functionsAccess logs, HTTP requestsEU / US (global CDN)DPA + SCC
ResendTransactional email deliveryEmail and message contentUSDPA + SCC
Stripe Payments EuropePayment processingEmail, amount, card token (we do not store card numbers)Ireland (EU)Native GDPR DPA + PCI-DSS
CloudinaryImage storage and transformationImages uploaded by clinics (logos, photos, before/after)USDPA + SCC
SentryError monitoringError stack traces (personal data automatically redacted)USDPA + SCC + PII redaction
Google Analytics (GA4)Website usage analyticsAnonymous usage (only after explicit consent in the cookie banner), anonymized IPUSDPA + SCC + IP anonymization + Consent Mode v2
Google OAuthOptional OAuth authentication ("Sign in with Google")Email and name (only if the user chooses this login method)USOAuth 2.0 standard + DPA

Updates to this list

If we add or replace any provider, we will update this page before the change takes effect. For greater transparency, we invite you to review it periodically. If you have questions about any provider, write to privacidad@longevitymap.co.