Labshare Sub-processors
Overview
Labshare engages the third-party service providers listed below to help us deliver, secure, and improve our Services. Each sub-processor is bound by a Data Processing Agreement (DPA) or equivalent contractual terms that require them to protect customer data consistent with applicable law and our security commitments.
We will update this page when sub-processors are added, removed, or replaced. Customers with active subscriptions may subscribe to notifications of changes by emailing security@labshare.app.
Current sub-processors
| Sub-processor | Purpose | Processing region | Contract / DPA |
|---|---|---|---|
| Amazon Web Services | Compute, object storage, push notifications, transactional email | us-east-1 | AWS standard DPA |
| MongoDB Atlas (MongoDB Inc.) | Primary application database (inventory, orders, grants) | United States | MongoDB DPA |
| Supabase (Supabase Inc.) | Authentication and relational database (users, institutions, RBAC) | United States | Supabase DPA |
| Cloudflare | CDN, DNS, edge TLS termination, DDoS mitigation, web app hosting | Global edge network | Cloudflare DPA |
| Microsoft (Entra ID / Azure AD) | Optional federated identity for "Sign in with Microsoft" — receives only OAuth identity attributes for users who choose this sign-in option | Global | Microsoft Products and Services DPA |
| OpenAI | Optical character recognition (OCR) and structured information extraction from uploaded images and documents (raw image sent to OpenAI GPT-4o vision; no-training tier) | United States | OpenAI DPA |
| LlamaIndex (LlamaParse) | Document parsing for structured data extraction | United States | LlamaIndex DPA |
| Google (Calendar API) | Optional calendar event synchronization (per-user OAuth) | United States | Google API Terms of Service |
| Apple (APNs) | iOS push notification delivery | Global | Apple Developer Program License Agreement |
| Google (Firebase Cloud Messaging) | Android push notification delivery | United States | Google Cloud DPA |
| Amplitude | Mobile product analytics — event names, screen names, pseudonymous user IDs, and product-usage properties (including order totals, grant amounts, and search queries) | United States | Amplitude DPA |
| GitHub (Microsoft) | Source control and CI/CD pipeline | United States | GitHub DPA |
| Docker Hub | Build artifact storage (server container images) | United States | Docker Subscription Service Agreement |
Notes
- Google Calendar processing only occurs when an individual user explicitly authorizes the integration via OAuth and is limited to the calendar.events scope.
- OpenAI is used under the API tier in which submitted data is not used to train models.
- Amplitude receives pseudonymous user identifiers and product-usage events from the mobile applications, including order totals, grant amounts, and search queries used to understand feature adoption.