Last updated September 2026
To operate Complys we use the third-party providers below. Each processes personal data only to the extent needed to provide its service, under appropriate contractual terms. Some are located outside the UK — see Data hosting & international transfers for how those transfers are safeguarded. We keep this list current; for the exact data-residency of a particular category of your data, email support@complys.co.uk.
| Provider | Purpose | Data it may process | Location |
|---|---|---|---|
| Vercel | Application hosting, serverless functions and file storage | Application data in transit; uploaded files | United States / global edge |
| Neon | Managed PostgreSQL database — primary data store | Account, user, worker and compliance data | Managed cloud (region configurable) |
| Anthropic | AI generation and review of compliance content (e.g. RAMS/SWMS, toolbox talks) | Content submitted for generation or review | United States |
| Stripe | Payment and subscription processing | Billing name and email, transactions (card details held by Stripe) | United States / United Kingdom |
| UploadThing | Upload and storage of user files (documents, certificates, evidence) | Uploaded files, which may contain personal data | United States |
| Upstash | Rate limiting and abuse protection (Redis) | IP / session identifiers | Managed cloud (region configurable) |
| Resend | Sending transactional and service emails | Recipient name and email, message content | United States |
| Google (Gmail API) | Sending certain outbound emails | Recipient email and message content | United States / global |
| PostHog | Product and usage analytics (only with cookie consent) | Usage events and account/user identifiers | EU or US (as configured) |
Payment card details are handled directly by Stripe and are not stored by Complys. Tools that run inside the application and do not send personal data to a third party (such as PDF and QR-code generation) are not listed as sub-processors.