Legal

Service Providers and Transfers

Named service-provider register for archevis, with roles, broad purposes, legal links, and transfer posture.

Version

2026-03-28

Effective date

March 28, 2026

Jurisdiction

European Union

This page is the public named service-provider register for archevis.

1. Why this page exists

The main legal policies describe processing at a service level. This page separately lists the current hosted providers archevis uses for core service functions such as authentication, billing, analytics, storage, database hosting, rate limiting, and GPU-backed processing.

2. Public vs internal records

This public register intentionally names providers, broad purposes, data categories, and public legal links.

It does not publish security-sensitive implementation detail such as storage layout, deployment topology, workflow internals, model/runtime identifiers, object-key structure, or provider account configuration.

3. Business-customer processing

If you are a business customer and archevis processes customer personal data on your behalf, the Data Processing Addendum applies to that processor activity.

4. Transfers

Some providers may process personal data outside the EEA or support archevis from multiple jurisdictions.

Where personal data is transferred outside the EEA, Monolithiq relies on the lawful safeguard appropriate to the relationship, such as an adequacy decision, standard contractual clauses, or another valid safeguard under applicable law.

Questions about the current transfer posture may be sent to info@monolithiq.co.

Current service providers

archevis publicly discloses the current hosted providers that support the service, together with broad roles, data categories, and public legal links. This register omits security-sensitive implementation detail.

ProviderRoleBroad purposeData categoriesPublic noteLegal links
ClerkProcessorAuthentication, account session management, and sign-in verification flows.account identifiers, email address, authentication eventsAuthentication services are provided through a contracted identity-management provider under applicable processor terms.
StripeIndependent controllerSubscription checkout, payment processing, invoicing, and billing portal operations.billing identifiers, subscription metadata, payment-related customer recordsStripe provides hosted checkout, payment, invoicing, and billing-management services. Payment processing may be subject to Stripe's own legal obligations in addition to services provided to Monolithiq.
SupabaseProcessorManaged PostgreSQL databases, application storage metadata, and related backend platform services.account records, project metadata, consent logs, application dataManaged database and backend platform services are provided under processor terms, with customer-specific contract records maintained internally.
Cloudflare R2ProcessorPrivate object storage for uploaded files, generated compositions, previews, and archival objects.project files, generated images, derived previews, archival objectsPrivate object storage is provided by a contracted infrastructure provider under applicable processor and transfer safeguards.
Plausible AnalyticsProcessorAnonymous cookieless product analytics and aggregate usage measurement.page paths, event metadata, derived aggregate analyticsPlausible analytics is used for aggregate product measurement rather than advertising profiling and does not set optional tracking cookies in the current setup.
RunPodProcessorGPU-backed generation and image-processing workloads.generation job payloads, input assets needed for processing, job metadataGPU-backed processing is used only for generation workloads, with provider-specific contract records maintained internally.

Where personal data is transferred outside the EEA, archevis relies on the lawful safeguard appropriate to the relationship, such as an adequacy decision, standard contractual clauses, or another valid safeguard under applicable law.