Last updated: 23 March 2026
When you upload a document or ask a question, here is exactly what happens to your data:
Your Browser
ComplianceIQ
Vercel (UK/EU edge)
Supabase
UK (London)
AES-256 at rest
OpenAI
US (embeddings only)
No training on API data
Anthropic
US (answers only)
No training on API data
Stripe
US (PCI DSS)
We never see card numbers
Required under UK GDPR. The following sub-processors may access your data as part of providing ComplianceIQ:
| Sub-processor | Purpose | Data processed | Location | DPA |
|---|---|---|---|---|
| Supabase | Database, storage, authentication | All customer data | UK (AWS London, eu-west-2) | Signed |
| Vercel | Application hosting, edge functions | Request data | EU/UK edge | Signed |
| OpenAI | Text embedding generation | Document text chunks | US | Signed |
| Anthropic | AI response generation | Questions + context | US | Signed |
| Stripe | Payment processing | Payment data | US | Signed |
| Resend | Email delivery | Email addresses, message content | US | Signed |
| Upstash | Rate limiting | IP addresses, user IDs | EU | Signed |
AI providers process your data to generate responses and embeddings. They do not retain your data beyond the processing request and do not use it to train their models.
Legal basis: Standard Contractual Clauses (SCCs) agreed with each US-based sub-processor. All providers maintain appropriate technical and organisational security measures.
For customers requiring all data to remain in the UK, please contact us about our Enterprise plan options.
ComplianceIQ data is backed up daily with point-in-time recovery capability. Backups are retained in accordance with our hosting provider's plan. In the event of data loss, we can restore to any point within the retention period.
Recovery time objective (RTO): 4 hours for full service restoration.
Encryption in transit
TLS 1.2+ on all connections
Encryption at rest
AES-256 (Supabase managed)
Tenant isolation
Row-Level Security (RLS) on all data
File scanning
All uploads scanned for malicious content
Rate limiting
API rate limiting on all endpoints
Input validation
Server-side validation on all inputs
Security logging
All security events logged and monitored
CSP headers
Content Security Policy on all responses
Security events are monitored via our security log, Vercel analytics, and Supabase monitoring. Critical events trigger immediate admin notification.
Affected customers will be notified by email with: what happened, what data was affected, what we are doing about it, and what they should do. The ICO will be notified within 72 hours if a personal data breach occurs (UK GDPR requirement).
Contain the incident, restore from backups if needed, patch the vulnerability, and conduct a post-incident review to update security measures.
Under UK GDPR, you have the right to access, rectify, erase, restrict processing of, and export your data.
Security concerns: security@complianceiq.co.uk
Data protection: dpo@complianceiq.co.uk