Sub-processors
Governly sub-processors
This page is maintained by the Governly team and lists the third parties Governly relies on to deliver its vendor due diligence platform. It is provided so customer procurement and security teams can complete their fourth-party assessment.
| Sub-processor | Purpose | Data categories | Region |
|---|---|---|---|
| Lovable Cloud (application hosting & managed backend) | Hosts the Governly web application; provides the managed PostgreSQL database, authentication, storage and edge-function runtime. | All customer and supplier account data, assessment data, uploaded evidence files. | EU (primary) |
| Lovable AI Gateway | Executes the AI analysis of uploaded evidence against assessment requirements. Customer data is never used to train models. | Evidence extracts and requirement text submitted for a single analysis request. | EU (primary), with model providers per the AI Transparency page |
| Stripe Payments Europe, Ltd. | Payment processing for paid tiers and one-off purchases. Governly never receives full card numbers. | Billing contact, payment method metadata, invoice records. | EU / Ireland |
| Transactional email delivery (via Lovable Cloud) | Delivers invitation, notification and support emails to customers and suppliers. | Recipient email address, sender, subject and message body. | EU (primary) |
Change management
- New sub-processors are evaluated against our security-review process before being added.
- Material changes to this list are announced by email to account administrators, with a reasonable objection window.
- Contractual obligations relating to security and privacy are flowed down to every sub-processor.
Related pages
- • Data Processing Agreement — GDPR-aligned DPA scope and how to request it.
- • Security & privacy — encryption, residency, retention and compliance posture.
- • AI Transparency — model providers and how AI is used.