Legal & trust
Service providers that may process customer personal data to operate, secure, and support OnComply.
Last updated August 6, 2026
Microsoft Azure AI is an identified subprocessor
Azure processes source documents for Content Understanding extraction. Those files may contain SSNs, EINs, routing and account numbers, and other sensitive vendor data. Read the detailed training, retention, abuse-monitoring, redaction, and customer-choice disclosure in the DPA overview.
Current schedule
A provider processes only the categories needed for the applicable service. Some providers apply only when a customer uses the related feature.
Amazon Web Services, Inc. (AWS)
Core cloud infrastructure
- Purpose
- Application hosting, identity, databases, encrypted document storage, queues, key management, backups, and operational logs.
- Data scope
- Customer account and service data, including encrypted customer and vendor documents submitted to the core platform.
Microsoft Corporation (Microsoft Azure)
Azure Content Understanding and Azure OpenAI
- Purpose
- Automated document extraction and validation.
- Data scope
- Source documents and extraction results for Content Understanding; minimized fields and redacted supporting text for OnComply's separate validation request. Source documents can contain SSNs, EINs, bank details, and other sensitive vendor data.
ActiveCampaign, LLC (Postmark)
Transactional email
- Purpose
- Delivery of invitations, reminders, verification, security, and service messages.
- Data scope
- Recipient name and email address, message content, delivery metadata, and links generated for the requested workflow. OnComply does not attach source vendor documents to routine service emails.
Functional Software, Inc. (Sentry)
Error and performance monitoring
- Purpose
- Application diagnostics, reliability monitoring, and incident response.
- Data scope
- Technical error, request, device, release, and performance context. Source vendor documents are not intentionally submitted for monitoring.
Stripe, Inc.
Billing and payment processing
- Purpose
- Subscriptions, invoices, payments, refunds, and billing administration.
- Data scope
- Customer billing contacts, subscription and invoice details, payment metadata, and payment credentials submitted directly to Stripe. Vendor tax and bank documents are not used for OnComply subscription billing.
Vercel Inc.
Website and web-application delivery
- Purpose
- Hosting and delivery of OnComply's public website and browser applications.
- Data scope
- Website content, network and request metadata, and information submitted through marketing-site forms. Core vendor documents are uploaded to and stored in OnComply's AWS environment, not Vercel's marketing data stores.
Optional integrations
Customer-enabled integrations and destinations, such as accounting platforms or customer-managed file transfer locations, receive data only when the customer configures and directs that transfer. Their role and data scope are disclosed in the applicable feature configuration and agreement.
Changes and questions
OnComply updates this page when the schedule changes and provides customer notice where required by the executed DPA. Questions or objections can be sent to admin@oncomply.biz.