Back to home

Data Processing Agreement

Last updated: July 13, 2026

Purpose

This Agreement governs the Data Processor's processing of personal data on behalf of the Data Controller in accordance with Article 28 of the GDPR. The processing is part of the delivery of Complir's compliance platform and related services.

Nature of the processing

The Data Processor processes personal data to provide the Data Controller with tools for managing product compliance, including:

  • Storing supplier contact information
  • Processing uploaded product-related documentation
  • Supporting AI-powered workflows for classification, translation, and risk assessment

Types of personal data

The types of data may include, but are not limited to:

  • Name
  • Email
  • Phone number
  • Company affiliation
  • Role/title
  • Supplier company details
  • Uploaded documents containing personal or supplier information

Categories of data subjects

The Data Processor may process personal data relating to the following categories of data subjects on behalf of the Data Controller:

  • Employees and authorized users of the Data Controller who access or use the Complir platform.
  • Supplier contacts and representatives whose information is uploaded or managed within the platform by the Data Controller.
  • Subcontractors or external partners whose details may appear in documentation or compliance data provided by the Data Controller.

No special categories of personal data (as defined in Article 9 of the GDPR) are intended to be processed under this Agreement.

Security measures

The Data Processor implements appropriate technical and organisational measures, including:

  • Encrypted communication (TLS)
  • Role-based access control
  • Periodic access reviews
  • Logging and monitoring via Sentry
  • Regular backups
  • Use of ISO 27001-certified infrastructure providers

Sub-processors

The Data Controller grants the Data Processor general written authorisation to engage sub-processors where reasonably necessary to provide, secure, monitor, support or improve the Complir platform and related services.

The current list of authorised sub-processors is available at complir.io/legal/sub-processors. The Data Controller authorises the Data Processor's use of the sub-processors listed there as of the effective date of the Agreement, including cloud hosting providers, infrastructure providers, monitoring providers, workflow providers and AI model providers used to deliver the services.

The Data Processor remains responsible for the acts and omissions of its sub-processors to the extent required by applicable data protection law. The Data Processor will ensure that each sub-processor is bound by written obligations that provide at least the same level of protection for personal data as this Agreement, including confidentiality, security, breach notification and transfer safeguards where applicable.

The Data Processor will provide at least 30 days' prior notice before adding or replacing a sub-processor that will materially process personal data on behalf of the Data Controller, unless shorter notice is required because of security, legal, operational or emergency reasons. Notice may be provided to the Data Controller's platform administrators or other designated customer contacts by email, in-product notice or update to the published sub-processor list.

The Data Controller may object to a new or replacement sub-processor within 14 days after notice, but only on reasonable, documented data protection or information security grounds. The Data Processor will use commercially reasonable efforts to address the objection, which may include providing additional information, safeguards or an alternative where commercially and technically feasible.

If the Parties cannot resolve the objection within a reasonable period, the Data Controller may terminate the affected service by written notice. Where the affected service cannot reasonably be separated from the platform as a whole, the Data Controller may terminate the Agreement. In either case, the Data Controller's sole remedy is a pro-rated refund of prepaid fees for the terminated service covering the period after the effective termination date. The Data Processor is not required to modify its infrastructure, suspend use of the sub-processor for other customers or maintain a customer-specific processing environment.

Data subject rights and assistance

The Data Processor assists the Data Controller in fulfilling its obligations under GDPR Chapter 3 (data subject rights), including access, correction, deletion, and objection.

Deletion or return of data

Upon termination of the Agreement, the Data Processor will delete or return all personal data at the Data Controller's request, unless otherwise required by law.

Audit rights

The Data Controller may audit the Data Processor's data processing practices once per year with 30 days' written notice. Audit costs are borne by the Data Controller unless a material breach is found.

Breach notification

The Data Processor will notify the Data Controller without undue delay, and no later than 48 hours after becoming aware of a personal data breach.

Duration

This Agreement remains in effect as long as the Data Processor processes personal data on behalf of the Data Controller.