Template notice — not legal advice. This Sub-processors page is a starting-point template generated to help ComplyWise, Inc. accelerate launch. It is not legal advice and does not create any contractual commitment. It must be reviewed, completed (see bracketed placeholders), and adapted by qualified legal counsel and your data-protection function before it is published or relied upon.
Sub-processors
To deliver the ComplyWise compliance-training platform, we engage a limited number of trusted third-party service providers, known as "sub-processors." A sub-processor is an organization we authorize to process personal data on our behalf, under our instructions, in order to provide part of the service (for example, cloud hosting, database storage, transactional email, or payment processing). Each sub-processor is engaged under a written data-processing agreement that requires it to protect personal data to a standard consistent with our commitments to customers and with applicable data-protection law, including the EU GDPR and UK GDPR.
ComplyWise, Inc. remains responsible to its customers for the performance of its sub-processors. We maintain this page as the current, authoritative list of sub-processors that may process customer personal data.
Our commitment to notify you of changes
We are committed to transparency about who processes personal data on our behalf. Before we engage a new sub-processor, or replace an existing one, in a way that may process customer personal data, we will update this page and, where you have subscribed to change notifications, provide advance notice. This gives customers a reasonable opportunity to review the change and, where a data-processing agreement provides a right to object, to raise a reasonable, good-faith objection on data-protection grounds. Details of any objection process and notice periods are set out in the applicable data-processing agreement. [Notice period for new sub-processors: e.g., 30 days.]
Current sub-processors
| Name | Purpose | Data processed | Location |
|---|---|---|---|
| Supabase, Inc. | Managed PostgreSQL database (the primary datastore, including the tamper-evident audit trail and rate-limit state) and object storage via an S3-compatible endpoint (uploaded files and generated artifacts such as course packages and certificates). | All customer and platform data hosted in the service: customer account data (org name, plan); user personal data (full name, work email, optional employee ID); training records (assignments, completions, scores, e-signatures, certificates); and audit/security logs (IP address, user agent, timestamps). | The Supabase project — database and object storage — is in us-east-1 (N. Virginia, USA). Supabase itself runs on Amazon Web Services infrastructure, so AWS is engaged as a sub-processor by Supabase rather than directly by ComplyWise. |
| Stripe, Inc. | Payment processing and subscription billing for paid plans. | Billing and subscription data, including customer/organization billing contact details, plan and subscription identifiers, and payment/transaction metadata. Card and payment-instrument details are collected and stored directly by Stripe; ComplyWise does not store full payment-card numbers. | United States. |
| Resend | Delivery of transactional email (for example account, assignment, and notification messages). This is the configured email provider for the Service. | Email delivery data: recipient work email address, sender/subject/message content of transactional emails, and related delivery metadata. | United States. [Confirm processing region for your configuration.] |
| Sentry — not currently enabled | Application error monitoring and diagnostics to detect, investigate, and resolve platform errors. | Error and diagnostic data, which may include technical event context, request metadata, IP address, user agent, and limited user or account identifiers associated with an error event. | United States. [Confirm processing region for your configuration.] |
| Vercel Inc. | Hosting and edge delivery of the ComplyWise web application. Separately, and only where the visitor has accepted analytics cookies via the cookie banner, Vercel Web Analytics is used for aggregate usage measurement. | Hosting: all request traffic to the Service, including request metadata (IP address, user agent, requested URL) and any customer or user data contained in the requests and responses it serves. Web Analytics: aggregate page-view data only — page path, referrer, country, and coarse device/browser type. Vercel Web Analytics sets no cookies and uses no persistent visitor identifier, and is not used for advertising or cross-site tracking. | United States, with global edge delivery. Vercel functions execute in the iad1 region (Washington, D.C., USA); static assets are served from Vercel’s global edge network. |
Note on optional sub-processors. Resend and Sentry are engaged only where the operator enables them for a given deployment. If they are not enabled for your environment, they do not process your personal data. Where required by applicable law, transfers of personal data outside your region are protected by an appropriate transfer mechanism, such as the EU Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum. [Confirm transfer mechanisms with counsel.]
How to subscribe to change notifications
To receive advance notice when we add or replace a sub-processor, subscribe to sub-processor change notifications by emailing [subscribe email placeholder — e.g., subprocessors@complywise.com] with the subject line "Subscribe — Sub-processor updates," and include your organization name and a contact email address. You may unsubscribe at any time by emailing the same address with the subject line "Unsubscribe." Questions about this list or our data-processing practices can be directed to our privacy contact at [DPO / privacy contact email].
Last updated: [date]. ComplyWise, Inc., [registered address]. Governing law: [e.g., State of Delaware, USA].