A provider processes Customer Personal Data for Johco only when the provider is enabled in the production environment and the relevant Johco feature uses it. Johco’s Data Processing Agreement explains the general authorization, notice, and objection process.
Johco-operated production infrastructure
The current design uses Johco-operated infrastructure for the application server, database, API execution, and account records. No third-party hosting provider is identified as active in this draft. Before any third-party host receives Customer Personal Data, Johco must add the provider to this list, record its processing region and purpose, complete the required review and contract, and provide notice under the DPA.
| Provider | Status | Purpose | Data involved | Processing location |
|---|---|---|---|---|
| Johco LLC | Internal | Application, API, database, account, entitlement, metering, and support operations. | Account and organization records; authentication and usage metadata; Customer-submitted requests, files, project data, and generated outputs according to enabled features. | Johco-administered environment. The production region must be recorded before this document is activated. |
Optional AI processing providers
These providers are alternatives for natural-language logic parsing. A provider is used only if it is configured by Johco and selected for the relevant AI-assisted request. The model provider interprets language; Johco’s application validates the resulting structure and performs the financial or analytical calculation.
| Provider | Status | Purpose | Data involved | Location and terms |
|---|---|---|---|---|
| OpenAI, L.L.C. and applicable affiliates | Planned / conditional | Parse an authorized user’s natural-language request into structured instructions; return model output. | Request text and the minimum contextual fields included for that request; technical request metadata. Content is not sent in local-only mode. | Processing may occur in the United States and other locations identified for the API in OpenAI’s current subprocessor list. See the OpenAI DPA. |
| Anthropic, PBC and applicable affiliates | Planned / conditional | Parse an authorized user’s natural-language request into structured instructions; return model output. | Request text and the minimum contextual fields included for that request; technical request metadata. Content is not sent in local-only mode. | As described in Anthropic’s contract and provider disclosures; this draft makes no Johco-specific regional commitment. See the Anthropic DPA and Commercial Terms. |
| Google LLC — Gemini API | Planned / conditional | Parse an authorized user’s natural-language request into structured instructions; return model output. | Request text and the minimum contextual fields included for that request; technical request metadata. Content is not sent in local-only mode. | Depends on the configured Google service, region, and vendor terms; this draft makes no Johco-specific regional commitment. See Google’s Cloud Data Processing Addendum and Cloud subprocessors. |
Identity, payment, and consent services
Some providers in this section may act as Johco’s processor for one activity and as an independent controller for another. Their inclusion provides transparency and is not a legal conclusion about every processing activity.
| Provider | Status | Purpose | Data involved | Location and terms |
|---|---|---|---|---|
| Google LLC — Google Identity | Planned / conditional | Optional account creation and sign-in using OpenID Connect. | Google subject identifier and, within the scopes the user approves, email address, name, profile image, and authentication metadata. Johco should request only the scopes needed for sign-in. | Google’s global service infrastructure and terms. See the Google OAuth policies and Google Privacy Policy. |
| Microsoft Corporation — Microsoft Identity | Planned / conditional | Optional account creation and sign-in using the Microsoft identity platform. | Microsoft subject identifier and, within the permissions the user or administrator approves, email address, name, tenant information, and authentication metadata. | Microsoft’s global service infrastructure and terms. See the Microsoft identity platform documentation, Microsoft DPA resources, and Microsoft Privacy Statement. |
| Stripe, Inc. and applicable affiliates | Planned / conditional | Subscription checkout, payment processing, billing records, invoices, refunds, and customer billing portal when billing is enabled. | Customer and billing contact details, transaction and subscription metadata, payment method details supplied directly to Stripe, fraud signals, and payment tokens or limited payment-method details returned to Johco. | Locations depend on the transaction and Stripe service. See the Stripe DPA and service-provider and subprocessor list. |
| Termly, Inc. | Planned / conditional | Policy publication, consent-management interface, consent records, and privacy-request tooling if those products are enabled. | Consent identifier, truncated or anonymized IP information as described by Termly, country, browser/device information, consent choices, date and time, website and page URL; contact and request details if a Termly privacy-request form is used. | Termly states that consent logs and privacy-request forms are stored on AWS in the United States; other transfers are governed by its terms. See Termly’s privacy center and subprocessor list. |
Change notices and objections
- Johco will update this page when a listed provider’s status, purpose, or relevant processing information materially changes.
- Before a new Subprocessor receives Customer Personal Data, Johco will notify active customers at their current account-administrator or designated DPA-notice email when reasonably practicable. An urgent replacement needed for security, law, or service continuity may be announced as soon as reasonably practicable.
- To subscribe or change the address for notices, email admin@johco.store with the subject “Subprocessor notices.”
- A customer may object on reasonable, documented data-protection grounds within 15 days after notice by emailing admin@johco.store. The resolution process is described in the DPA.
Pre-launch review notes
- Change each status to “Enabled” only after the provider is configured in production, the applicable commercial and data-protection terms are accepted, and a proportionate security review is complete.
- Record the Johco production hosting region and add any third-party hosting, email-delivery, monitoring, support, or backup provider before that provider handles Customer Personal Data.
- Verify each AI route’s provider, data-retention setting, and training setting in the production account. Do not infer those settings from general vendor marketing.
- Review linked vendor pages periodically because vendors may change their entities, locations, terms, and upstream subprocessors.