Sub-Processors
ComplianceOS uses the following third-party sub-processors to deliver our services. This list is maintained pursuant to our Data Processing Agreement.
Change Notification Policy
We will notify you at least 30 days in advance of any new sub-processor being added to this list. If you object to a new sub-processor on reasonable data protection grounds, please contact us at founder@aiactsolutions.com within the notice period.
Supabase (AWS)
OpenAI
Purpose
AI-powered risk classification, gap analysis, document generation, and document refinement
Data Processed
AI system descriptions, compliance document content (sent as prompts for processing)
Safeguards
SCCs, zero data retention policy (API inputs/outputs not used for training), encryption in transit
Anthropic
Groq
Vercel
Dodo Payments
Questions?
If you have questions about our sub-processors or wish to object to a new sub-processor, please contact us:
ComplianceOS
Email: founder@aiactsolutions.com