Legal
Data Processing Agreement
Last updated August 14, 2026
1. Scope and Roles
This Data Processing Agreement ("DPA") describes how OnComply processes personal data on behalf of a customer when providing the OnComply service, and forms part of the agreement between OnComply and the customer. For personal data submitted to the service, the customer acts as the controller (or as a processor on behalf of its own clients) and OnComply acts as a processor. A countersigned copy of this DPA, or a negotiated version where agreed, is available on request; an executed agreement prevails over this page if the two differ.
2. Processing Details
OnComply processes personal data to provide vendor compliance workflows: collecting vendor documents and information, validating them against customer-configured requirements, tracking compliance status, supporting e-signature, and delivering related communications and reports. Data subjects include customer personnel and the customer's vendors and their personnel. The categories processed include contact and business details, documents the customer chooses to collect, information extracted from those documents, and banking details vendors submit through a structured form. Vendor documents can contain sensitive vendor information such as tax identifiers, insurance details, and signatures. Processing continues for the duration of the customer's agreement.
3. Customer Instructions
OnComply processes customer personal data only on the customer's documented instructions, including the instructions given by configuring and using features of the service, unless processing is required by applicable law. In that case OnComply informs the customer of the legal requirement before processing where the law permits. OnComply does not sell customer personal data and does not use customer documents to train its own general-purpose AI models.
4. Confidentiality
OnComply ensures that persons authorized to process customer personal data are bound by contractual or statutory confidentiality obligations, and limits access to personnel who need it to provide, secure, and support the service.
5. Security
OnComply implements appropriate technical and organizational measures to protect customer personal data, including encryption in transit and at rest, an additional layer of application-level encryption for the most sensitive fields, database-enforced tenant isolation, role-based access controls, multi-factor and step-up authentication, protected audit logging, and continuous security monitoring. Support access to a customer workspace is tied to a ticket the customer's team opens, is time-limited, and is recorded in the customer's audit log. A summary of current controls is published on the Security page, and additional security documentation is available on request.
6. AI Document Processing
When automated document extraction is enabled, OnComply sends uploaded source documents to Microsoft Azure AI services for extraction, and those documents can contain sensitive vendor information. OnComply then makes a separate AI validation request in which identified sensitive values, such as tax identifiers, are removed or redacted and are checked through deterministic controls instead. Vendor banking details are collected through a structured form and are not part of the AI document-processing workflow. Per Microsoft's terms, this data is not used to train foundation models by default and operational retention within the AI services is limited; Microsoft's Products and Services Data Protection Addendum governs Microsoft's handling of this data. Customers with document types that cannot be processed by AI services can contact OnComply to discuss available options before uploading production documents.
7. Subprocessors
The customer authorizes OnComply to engage subprocessors to provide the service, including providers of cloud infrastructure and storage, AI document processing (Microsoft Corporation), transactional email, billing and payment processing, diagnostics and monitoring, and website delivery. OnComply imposes data-protection obligations consistent with this DPA on its subprocessors and remains responsible for their processing. A current list of subprocessors is available on request to admin@oncomply.biz, and customers can subscribe to change notices. OnComply provides notice of new subprocessors as required by the executed agreement, and a customer may object on reasonable data-protection grounds.
8. International Transfers
OnComply is a United States business and processes customer personal data primarily in the United States. Where a transfer of personal data is subject to cross-border transfer requirements, OnComply applies a lawful transfer mechanism and appropriate safeguards as required by applicable law and the executed agreement.
9. Assistance and Data Subject Requests
Taking into account the nature of the processing, OnComply assists the customer in responding to data subject requests and in meeting the customer's obligations relating to security, breach notification, and data protection assessments, through the features of the service and reasonable cooperation on request.
10. Incident Notification
OnComply notifies the customer without undue delay after becoming aware of a personal data breach affecting the customer's personal data, and provides information reasonably available to help the customer meet its own notification obligations, followed by updates as the investigation progresses.
11. Retention and Deletion
Customer personal data is retained while the customer's account is active and as needed to provide the service. Customer data is exportable at any time. On termination and written request, OnComply deletes customer personal data within a reasonable period, except where retention is required by law or for protected records such as audit logs, which are retained under documented retention schedules and then deleted.
12. Audit and Information
On written request, OnComply provides information reasonably necessary to demonstrate compliance with this DPA, including security documentation and completed assessment questionnaires, and allows for audits as agreed in the executed agreement.
13. Contact
Requests for the executed DPA, the current subprocessor list, security documentation, or data-protection questions can be sent to admin@oncomply.biz.
Requests
To receive a countersigned DPA, the current subprocessor list, or security documentation, email admin@oncomply.biz. Microsoft's commitments for the Azure services used in AI document processing are described in the Microsoft Products and Services DPA. Security controls are summarized on the Security page.