
Loading CompliClear

Loading CompliClear
Register version 2026-07-12. Providers marked conditional process data only when that deployment route or optional service is configured and used.
| Provider | Role | Purpose | Data | Location |
|---|---|---|---|---|
| Vercel | Processor | Application hosting, edge delivery, deployment logs | Account, request, technical, and customer content processed by the application | Vendor/deployment region; global delivery |
| Supabase | Processor (when configured) | PostgreSQL database and private object storage | Account, workspace, generated document, evidence, and audit data | Selected project region |
| Cloudflare R2 | Processor (alternative storage) | Private object storage | Generated PDFs and uploaded evidence | Configured/global infrastructure |
| Clerk | Processor / separate controller by activity | Authentication, verified identity, session security | Account contact, authentication, session, device, and security data | Vendor infrastructure |
| AWS Bedrock | Processor (conditional AI route) | AI-assisted classification and generation | Authorized prompt context, answers, and excerpts | Configured AWS region |
| Anthropic | Processor (conditional AI route) | AI-assisted classification, generation, optional research | Authorized prompt context, answers, excerpts, and research request | Vendor infrastructure/contract configuration |
| OpenAI | Processor (conditional AI route) | AI-assisted generation and optional research | Authorized prompt context, answers, excerpts, and research request | Vendor infrastructure/contract configuration |
| Resend | Processor | Transactional email | Recipient email, company/contact context, and message content | Vendor infrastructure |
| Sentry | Processor (when configured) | Error and performance monitoring; replay disabled | Error, route, device, and diagnostic metadata with default PII disabled | Vendor project region/configuration |
| PostHog | Processor (optional consent) | Product analytics after opt-in | Usage events, device/browser, and approximate network metadata | Configured host/region |
| Crisp | Processor / separate controller by activity (optional consent) | Support chat after opt-in | Chat, contact, device, and conversation identifiers | Vendor infrastructure |
Dodo Payments is the currently routed hosted checkout provider and may act as merchant of record, legal seller, and independent controller for payment, fraud, tax, invoicing, refund, and regulatory duties. It is not treated as CompliClear's subprocessor for those independent purposes. Stripe integration code remains in the application but is not in the active provider order; Stripe becomes relevant only if separately configured and enabled.
Processing region, retention, model-training setting, DPA, SCC/transfer mechanism, and security evidence must be verified against each live vendor account and contract. “Vendor infrastructure” is not a claim of EU adequacy or localization. Where required, CompliClear and the customer must select the correct transfer mechanism, complete its annexes, assess destination risk, and apply supplementary measures.
CompliClear will update this versioned page before a new provider begins materially different processing where reasonably possible and will use account email or an in-product notice for material changes affecting customer content. Customers may request change notices or raise a reasoned data-protection objection at founder@compliclear.com. The parties will consider an alternative provider/configuration, suspension of the affected feature, or termination remedy under the DPA.