Back to home

Sub-Processors

Last updated: July 26, 2026

Complir uses the following third-party sub-processors to provide, secure, monitor, support and improve our services. This page is the Sub-Processor List incorporated by our Data Processing Agreement and Terms and Conditions.

All sub-processors are carefully vetted and bound by written data processing, confidentiality and security obligations designed to protect customer data.

EU-Based Sub-Processors

  • Supabase - Database and authentication services. Processes customer data and user credentials.
  • Vercel - Hosting and content delivery. Processes application data and metadata.
  • Microsoft Azure - Cloud infrastructure services. Processes system data and backups.
  • Resend - Transactional email delivery. Processes email addresses and notification content.
  • PostHog - Analytics, monitoring and error logging. Processes usage data and system metrics.
  • Turbopuffer - Vector storage for AI features. Processes document embeddings and metadata.
  • Reducto - Document parsing services. Processes uploaded documents.
  • Inngest - Workflow orchestration. Processes task metadata and system events.

US-Based Sub-Processors

  • OpenAI - AI processing services. Processes user queries and document content.
  • Anthropic - AI processing services. Processes user queries and document content.
  • GitHub - Source control and version management. Processes code and configuration files (no customer data).

Data Protection Measures

All sub-processors are required to:

  • Maintain appropriate technical and organizational security measures
  • Process data only according to our documented instructions
  • Comply with GDPR, including Standard Contractual Clauses for non-EU transfers
  • Notify us immediately of any data breaches

US Data Transfers

For sub-processors located in the United States, we rely on Standard Contractual Clauses approved by the European Commission and supplementary measures to ensure adequate protection of personal data.

Changes to This List

We will notify customer administrators or other designated customer contacts at least 30 days before adding or replacing a sub-processor that will materially process personal data on behalf of customers, unless shorter notice is required because of security, legal, operational or emergency reasons. Notice may be provided by email, in-product notice or update to this page.

Customers may object to a new or replacement sub-processor within 14 days after notice, but only on reasonable, documented data protection or information security grounds. We will use commercially reasonable efforts to address the objection, which may include providing additional information, safeguards or an alternative where commercially and technically feasible.

If an objection cannot be resolved, the customer's remedy is to terminate the affected service as described in the Data Processing Agreement. Complir is not required to modify its infrastructure, suspend use of the sub-processor for other customers or maintain a customer-specific processing environment.

Questions

If you have questions about our sub-processors or data processing practices, please contact our Data Protection Officer at compliance@complir.com.