Home
MedeliX

Sub-processors

Version: v1.0 — launch · Last updated: 2026-05-20 · Effective: from public launch

This page lists all third-party service providers ("sub-processors") that may process personal data on Medelix's behalf. We maintain this page as the authoritative source — Privacy Policy §5 links here.

We notify signed-in users by email at least 14 days before adding, removing, or materially changing a sub-processor.


Infrastructure

ProviderRoleLocationData received
SupabaseManaged database, authentication, storageEU (Frankfurt)Account record, conversation history, consent flags
RailwayBackend hostingEU (Amsterdam)All request data in transit
NetlifyFrontend hosting and edgeEU edge of US-HQ providerPage requests; no personal data persisted
CloudflareDNS, CDN, WAF, anti-DDoSEU edge of US-HQ providerIP addresses for security filtering

AI processing

ProviderRoleLocationData received
Mistral AILanguage-model inferenceFranceQuestion text per request; no training on inputs
Jina AIText-embedding generationGermanyQuestion text only

Communications and identity

ProviderRoleLocationData received
BrevoTransactional email (verification, password reset)FranceEmail address, message content
Google (Google Ireland Ltd)"Sign in with Google" authenticationEEAName and email if you choose this option
Apple (Apple Distribution International Ltd)"Sign in with Apple" authenticationIrelandStable identifier; name and email on first sign-in

Analytics

ProviderRoleLocationData received
PlausibleCookieless aggregate analyticsGermany / EUAggregated pageviews; no user identifier

Public literature APIs (not sub-processors for personal data)

The following APIs receive only anonymised query text (no account identifier, no IP) and no personal data about you. Listed here for transparency, not because they process personal data on our behalf:

APIRoleLocation
EuropePMCCurrent source of evidence retrievalUK

Additional open-access literature APIs are planned and will be added to this list when integrated.


Transfer mechanisms

For US-headquartered providers (Cloudflare, Netlify), transfers rely on Standard Contractual Clauses (SCCs) under Commission Decision 2021/914, supplemented by the EU–US Data Privacy Framework where the provider is self-certified. Internal Transfer Impact Assessments are maintained and available to supervisory authorities on request.


Contact

Privacy questions: [email protected]


Change log

  • 2026-05-20 — Initial publication.