Legal

Subprocessors

Last updated: 28 May 2026

Overview

cmpliance.ai uses a limited set of service providers to operate, secure, support, and improve the Service. This page is a public summary. The applicable customer agreement controls final subprocessor commitments, notice periods, objection rights, data-transfer safeguards, and region commitments.

Provider use may vary by plan, deployment model, feature, and customer configuration.

This public page is category-based for launch-stage transparency. For production or pilot processing of real customer personal data, the applicable customer agreement or DPA package should identify the approved subprocessors, regions, transfer safeguards, notice process, and any customer-specific restrictions.


Current provider categories

Provider or categoryPurposeData involvedNotes
Hosting and deployment providerPublic website, application hosting, deployment, edge deliveryWebsite data, application traffic, operational logsRegion and retention may depend on deployment configuration
Managed database providerApplication databaseAccount data, workflow data, Customer Data where configuredUsed for core application persistence
Authentication providerLogin, account access, organisation membership, session managementAccount-user data, authentication metadataUsed to manage identity and access
Object storage providerDocument, evidence, and export storage where configuredUploaded artifacts, proofpacks, evidence filesRegion and bucket configuration are governed by the applicable setup
Workflow and event providerBackground workflow execution and event processingWorkflow metadata and task payloadsUsed to operate asynchronous platform workflows
Email delivery providerTransactional email, contact replies, notificationsEmail address, message metadata, message content where applicableUsed for service and business communications
Payment providerSubscription and billing processingBilling contact data, payment metadataPayment card data is handled by the payment provider
AI/model providerAI-assisted extraction, classification, summarisation, embeddings, and generation where enabledPrompt/input data, extracted text, workflow context, output dataCustomer Data is not used to train public or foundation models
CMS providerPublic website and insights content managementPublic marketing/editorial content and editor metadataNot intended for Customer Data
Monitoring and logging toolsSecurity, reliability, error diagnosis, abuse preventionOperational logs, error metadata, usage metadataUsed to maintain service reliability and security

Customer Data and production processing

Customers should not upload production personal data, sensitive data, special-category data, criminal-offence-related data, or regulated KYC/AML production data unless applicable written terms are in place.

For production or pilot processing of real customer personal data, the signed customer agreement controls:

  • Approved subprocessors
  • Transfer safeguards
  • Data locations
  • Notice and objection process
  • Audit and security documentation

Changes

We may update this page as providers, features, or deployment models change. Material subprocessor-change notices for active customers are governed by the applicable customer agreement.


Contact

cmp@cmpliance.ai paterhn GmbH, Gotthardstrasse 26, 6300 Zug, Switzerland