Labshare Sub-processors

Overview

Labshare engages the third-party service providers listed below to help us deliver, secure, and improve our Services. Each sub-processor is bound by a Data Processing Agreement (DPA) or equivalent contractual terms that require them to protect customer data consistent with applicable law and our security commitments.

We will update this page when sub-processors are added, removed, or replaced. Customers with active subscriptions may subscribe to notifications of changes by emailing security@labshare.app.

Current sub-processors

Third-party processors that handle Labshare customer data, the purpose of each engagement, the data-processing region, and the governing contract or DPA.
Sub-processorPurposeProcessing regionContract / DPA
Amazon Web ServicesCompute, object storage, push notifications, transactional emailus-east-1AWS standard DPA
MongoDB Atlas (MongoDB Inc.)Primary application database (inventory, orders, grants)United StatesMongoDB DPA
Supabase (Supabase Inc.)Authentication and relational database (users, institutions, RBAC)United StatesSupabase DPA
CloudflareCDN, DNS, edge TLS termination, DDoS mitigation, web app hostingGlobal edge networkCloudflare DPA
Microsoft (Entra ID / Azure AD)Optional federated identity for "Sign in with Microsoft" — receives only OAuth identity attributes for users who choose this sign-in optionGlobalMicrosoft Products and Services DPA
OpenAIOptical character recognition (OCR) and structured information extraction from uploaded images and documents (raw image sent to OpenAI GPT-4o vision; no-training tier)United StatesOpenAI DPA
LlamaIndex (LlamaParse)Document parsing for structured data extractionUnited StatesLlamaIndex DPA
Google (Calendar API)Optional calendar event synchronization (per-user OAuth)United StatesGoogle API Terms of Service
Apple (APNs)iOS push notification deliveryGlobalApple Developer Program License Agreement
Google (Firebase Cloud Messaging)Android push notification deliveryUnited StatesGoogle Cloud DPA
AmplitudeMobile product analytics — event names, screen names, pseudonymous user IDs, and product-usage properties (including order totals, grant amounts, and search queries)United StatesAmplitude DPA
GitHub (Microsoft)Source control and CI/CD pipelineUnited StatesGitHub DPA
Docker HubBuild artifact storage (server container images)United StatesDocker Subscription Service Agreement

Notes

  • Google Calendar processing only occurs when an individual user explicitly authorizes the integration via OAuth and is limited to the calendar.events scope.
  • OpenAI is used under the API tier in which submitted data is not used to train models.
  • Amplitude receives pseudonymous user identifiers and product-usage events from the mobile applications, including order totals, grant amounts, and search queries used to understand feature adoption.