OnComply

We use cookies to improve your experience and analyze site usage. Privacy Policy

Legal & trust

Data Processing Agreement

Clear terms for customer data, including how Microsoft Azure AI processes sensitive vendor documents.

Back to site

Last updated August 6, 2026

Microsoft Azure

AI subprocessor

Not permitted by default

Model training

Up to 24 hours at Azure

Extraction result

Restriction review available

Customer choice

AI processing disclosure

What Azure receives, and why

OnComply uses AI to extract and validate information from W-9s, ACH authorizations, certificates of insurance, contracts, licenses, and other documents a customer chooses to collect. This processing is performed only to provide the service on the customer's instructions; OnComply does not use customer documents to train its own general-purpose AI models.

1 · Extraction

Source document

When automated extraction is enabled, OnComply sends the uploaded file to Microsoft Azure Content Understanding. A file can contain sensitive vendor data, including an SSN, EIN or other tax identifier, bank routing and account details, insurance information, and signatures.

2 · Managed AI service

Azure processing

Content Understanding extracts structured fields and, according to Microsoft, uses Azure OpenAI within the managed service. Microsoft Corporation is therefore disclosed as an OnComply subprocessor for this workflow.

3 · Additional validation

Sensitive values redacted

For OnComply's separate Azure OpenAI validation request, selected fields and supporting text are minimized first. SSNs, EINs and TINs, bank account numbers, and routing numbers are removed or redacted; those values are checked through deterministic controls instead.

Microsoft commitments

No model training does not mean zero operational retention

No training or provider access

Microsoft states that prompts, completions, embeddings, and training data are not available to OpenAI or other model providers, are not used to train generative foundation models without permission or instruction, and are not used to improve Microsoft or third-party products without explicit permission or instruction.

Limited service retention

Microsoft states that Content Understanding input documents and intermediate representations are deleted when processing completes. Extraction output can remain available for asynchronous retrieval for up to 24 hours and is then deleted automatically.

Abuse-monitoring boundary

Azure's automated abuse review does not store prompts and completions, but content flagged for possible human review can be stored in Microsoft's logically separated abuse-monitoring system and accessed by authorized Microsoft personnel. Microsoft offers eligible customers an approval process for modified abuse monitoring, which removes that storage and human-review process for the approved scope.

Contractual protection

Microsoft's Products and Services Data Protection Addendum applies to Azure's handling of this data. OnComply's standard DPA makes OnComply responsible for imposing applicable data-protection obligations on subprocessors and remaining accountable for their processing as required by law and contract.

Customer AI choice

Request an AI processing restriction before use

A customer that cannot permit Microsoft Azure AI to process covered documents can request a review before uploading production documents. We will document whether a supported non-AI or manual workflow is available for the requested document types and tenant. A restriction is effective only after OnComply confirms its scope and effective date in writing. Restricting Azure AI processing can disable or materially limit automated extraction, validation, and related compliance decisions.

Request an AI restriction review

Request the complete DPA

This page is a public operational disclosure and supplements, but does not replace, the executed agreement. Email us with your company name, expected plan, and timing requirements to receive the current standard DPA or coordinate legal review.

W-9 CollectionCOI TrackingACH AuthorizationDocument Fill & SignAutomated ValidationRenewal RemindersCan-Work / Can-Pay ControlsVendor PortalCompliance DashboardWebhook IntegrationsEligibility APIAudit-Ready ExportsLicense TrackingGrace Period ManagementCustom FormsW-9 CollectionCOI TrackingACH AuthorizationDocument Fill & SignAutomated ValidationRenewal RemindersCan-Work / Can-Pay ControlsVendor PortalCompliance DashboardWebhook IntegrationsEligibility APIAudit-Ready ExportsLicense TrackingGrace Period ManagementCustom Forms