Skip to content
Sign In Try Free
Workflow-specific products Content, decks, briefs, proposals, legal, and sales each have a clearer buying path.
Review before delivery Draft, edit, collaborate, approve, and export in the same workspace.
Security + procurement path Security policy, support, and Azure Marketplace buying are public.

Subprocessor List

Last Updated: September 20, 2026 | Version 2.1

GDPR Transparency Requirement: This page lists all third-party service providers (subprocessors) that process personal data on behalf of Gixo.ai. This disclosure is required under GDPR Article 28.

Overview

Gixo.ai uses carefully selected third-party service providers to deliver our AI-powered content generation platform. All subprocessors are bound by Data Processing Agreements (DPAs) and are required to comply with GDPR, CCPA, and other applicable data protection laws.

Current Subprocessors
Provider Service Data Processed Location Privacy Policy
OpenAI AI Text & Image Generation (GPT, DALL-E) User prompts, uploaded inputs, and content generation requests sent via API United States View Policy
Anthropic AI Text Generation (Claude) User prompts, uploaded inputs, and content generation requests sent via API United States View Policy
Google (Gemini) AI Multimodal Generation User prompts, uploaded inputs, and content generation requests sent via API United States View Policy
Microsoft Azure Cloud Infrastructure & Storage User account data, generated content, application data Central US. Requests reach the application through Azure Front Door, which terminates TLS at global edge locations. View Policy
Azure Cosmos DB for MongoDB Managed Database Services Application database records, account data, and generated content metadata stored in the managed database Central US View Policy
Microsoft Application Insights Telemetry, Diagnostics, and Performance Monitoring Diagnostic events, usage telemetry, device/browser metadata, and application performance data Central US View Policy
Polar Payment Processing (Merchant of Record) Payment information, billing details, transaction records. Collected directly by Polar — card data does not transit or rest on Gixo systems. United States View Policy
Descope Authentication and Identity (CIAM) Email address, authentication factors, sign-in events, and identity-provider linkage for Google, Microsoft, Facebook and LinkedIn sign-in United States View Policy
Replicate AI Image Generation Image prompts and generation parameters sent via API United States View Policy
Resend Transactional E-mail Delivery Recipient e-mail address and the full rendered body of every message the product sends — verification, team and share invitations, billing and account-lifecycle notices United States View Policy
Lemon Squeezy Payment Processing (superseded — Polar is the merchant of record for new purchases; a legacy Lemon Squeezy checkout path remains configured as a fallback for individual shop items) Historical payment and transaction records from the period when it acted as merchant of record, and any transaction taken through the remaining fallback path. Retention position pending confirmation. United States View Policy
PayPal Payment Processing (historical — removed from the product on 2 August 2026) Historical payment and transaction records from the period when the flow was live. Retention position pending confirmation. United States View Policy
Data Protection Measures

Data Processing Agreements

All subprocessors have signed DPAs compliant with GDPR Article 28

Encryption in Transit

All data transmitted to subprocessors is encrypted with TLS 1.2 or higher

No Training on Your Data (AI Providers)

Gixo trains no models of its own. Content is sent to the AI providers listed below under their API terms, which do not use API inputs to train their models. Each provider applies its own limited retention window for abuse monitoring — see their policies below. Ask us and we will tell you which provider handles a given feature.

Subprocessor Review

We review this list when a provider changes. We do not run a scheduled subprocessor audit programme.

Changes to Subprocessors

Notification of Changes: We will notify users at least 30 days in advance before adding or changing subprocessors that process personal data. Enterprise customers with specific DPA requirements may object to new subprocessors.

This page will be updated whenever we add, remove, or change subprocessors. You can subscribe to notifications by emailing privacy@gixo.ai.


Questions About Data Processing?

For questions about our subprocessors or data processing practices, contact:
privacy@gixo.ai or dpo@gixo.ai