OnComply

We use cookies to improve your experience and analyze site usage. Privacy Policy

Legal & trust

Subprocessors

Service providers that may process customer personal data to operate, secure, and support OnComply.

Last updated August 6, 2026

Microsoft Azure AI is an identified subprocessor

Azure processes source documents for Content Understanding extraction. Those files may contain SSNs, EINs, routing and account numbers, and other sensitive vendor data. Read the detailed training, retention, abuse-monitoring, redaction, and customer-choice disclosure in the DPA overview.

Current schedule

A provider processes only the categories needed for the applicable service. Some providers apply only when a customer uses the related feature.

Amazon Web Services, Inc. (AWS)

Core cloud infrastructure

Purpose
Application hosting, identity, databases, encrypted document storage, queues, key management, backups, and operational logs.
Data scope
Customer account and service data, including encrypted customer and vendor documents submitted to the core platform.

Microsoft Corporation (Microsoft Azure)

Azure Content Understanding and Azure OpenAI

Purpose
Automated document extraction and validation.
Data scope
Source documents and extraction results for Content Understanding; minimized fields and redacted supporting text for OnComply's separate validation request. Source documents can contain SSNs, EINs, bank details, and other sensitive vendor data.

ActiveCampaign, LLC (Postmark)

Transactional email

Purpose
Delivery of invitations, reminders, verification, security, and service messages.
Data scope
Recipient name and email address, message content, delivery metadata, and links generated for the requested workflow. OnComply does not attach source vendor documents to routine service emails.

Functional Software, Inc. (Sentry)

Error and performance monitoring

Purpose
Application diagnostics, reliability monitoring, and incident response.
Data scope
Technical error, request, device, release, and performance context. Source vendor documents are not intentionally submitted for monitoring.

Stripe, Inc.

Billing and payment processing

Purpose
Subscriptions, invoices, payments, refunds, and billing administration.
Data scope
Customer billing contacts, subscription and invoice details, payment metadata, and payment credentials submitted directly to Stripe. Vendor tax and bank documents are not used for OnComply subscription billing.

Vercel Inc.

Website and web-application delivery

Purpose
Hosting and delivery of OnComply's public website and browser applications.
Data scope
Website content, network and request metadata, and information submitted through marketing-site forms. Core vendor documents are uploaded to and stored in OnComply's AWS environment, not Vercel's marketing data stores.

Optional integrations

Customer-enabled integrations and destinations, such as accounting platforms or customer-managed file transfer locations, receive data only when the customer configures and directs that transfer. Their role and data scope are disclosed in the applicable feature configuration and agreement.

Changes and questions

OnComply updates this page when the schedule changes and provides customer notice where required by the executed DPA. Questions or objections can be sent to admin@oncomply.biz.

W-9 CollectionCOI TrackingACH AuthorizationDocument Fill & SignAutomated ValidationRenewal RemindersCan-Work / Can-Pay ControlsVendor PortalCompliance DashboardWebhook IntegrationsEligibility APIAudit-Ready ExportsLicense TrackingGrace Period ManagementCustom FormsW-9 CollectionCOI TrackingACH AuthorizationDocument Fill & SignAutomated ValidationRenewal RemindersCan-Work / Can-Pay ControlsVendor PortalCompliance DashboardWebhook IntegrationsEligibility APIAudit-Ready ExportsLicense TrackingGrace Period ManagementCustom Forms