← Trust & Security

Sub-processors

Last updated September 2026

To operate Complys we use the third-party providers below. Each processes personal data only to the extent needed to provide its service, under appropriate contractual terms. Some are located outside the UK — see Data hosting & international transfers for how those transfers are safeguarded. We keep this list current; for the exact data-residency of a particular category of your data, email support@complys.co.uk.

ProviderPurposeData it may processLocation
VercelApplication hosting, serverless functions and file storageApplication data in transit; uploaded filesUnited States / global edge
NeonManaged PostgreSQL database — primary data storeAccount, user, worker and compliance dataManaged cloud (region configurable)
AnthropicAI generation and review of compliance content (e.g. RAMS/SWMS, toolbox talks)Content submitted for generation or reviewUnited States
StripePayment and subscription processingBilling name and email, transactions (card details held by Stripe)United States / United Kingdom
UploadThingUpload and storage of user files (documents, certificates, evidence)Uploaded files, which may contain personal dataUnited States
UpstashRate limiting and abuse protection (Redis)IP / session identifiersManaged cloud (region configurable)
ResendSending transactional and service emailsRecipient name and email, message contentUnited States
Google (Gmail API)Sending certain outbound emailsRecipient email and message contentUnited States / global
PostHogProduct and usage analytics (only with cookie consent)Usage events and account/user identifiersEU or US (as configured)

Payment card details are handled directly by Stripe and are not stored by Complys. Tools that run inside the application and do not send personal data to a third party (such as PDF and QR-code generation) are not listed as sub-processors.