Back to Login
GDPR Article 28 Compliance

Data Subprocessors Registry

Pursuant to Article 28 of the GDPR and Law of Ukraine No. 2297-VI, below is the official registry of third-party sub-processors engaged by ViralEngine to process personal data.

Supabase Inc.

Database & User Authentication
Purpose: Secure storage of user profiles, auth credentials, and project metadata.
Location: EU (Frankfurt) / US
GDPR Compliant, SOC2 Type II, TLS 1.3 & Row-Level Security (RLS)

Google LLC (Gemini API)

AI Scripting & Vision Prompting
Purpose: Generating script blueprints, viral titles, and visual thumbnail prompts.
Location: US / Global
GDPR Compliant, Zero Data Retention for Model Training

OpenAI LLC / Groq Inc.

AI Language Processing
Purpose: High-speed script refinement and tone-of-voice alignment.
Location: US / Global
Stateless API Processing, Zero-Retention Enterprise Terms

ElevenLabs Inc.

AI Voice Synthesis
Purpose: Generating lifelike voiceovers for video scripts.
Location: US / EU
GDPR Compliant, Voice Safety & Verification Protocols

Stripe Inc. / Tribute / Paddle

Payments & Merchant of Record
Purpose: Secure processing of subscriptions and payment invoices.
Location: US / EU / Global
PCI-DSS Level 1, GDPR Compliant, Fraud Protection

Cloudflare Inc. (R2 Storage)

Encrypted Object Storage & CDN
Purpose: Secure global CDN delivery of rendered video and audio assets.
Location: Global Edge Network
AES-256 Encryption at Rest, GDPR Compliant

Telegram Messenger LLP

Bot Authentication & Messaging
Purpose: Secure Telegram login authentication and subscription alerts.
Location: EU / Global
Encrypted Telegram Bot API & Blocklist Sync

Updates & Rights

This registry is updated regularly as infrastructure evolves. All sub-processors operate under Data Processing Agreements (DPAs). You can exercise your right to erasure at any time via billing@virale.uno.