Questionnaire answers · Security
How to answer cloud and infrastructure questions in a supplier questionnaire
Written by Yobel TzegaiLast reviewed 9 October 2026Checked against Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744
The short answer
Name where the AI features run, on whose infrastructure and in which region, and which providers process the customer's data there. Under the GDPR an infrastructure provider that processes personal data on your behalf is a processor, chosen for sufficient guarantees (GDPR Article 28(1)), and the security of its systems is part of your measures under Article 32(1). Complipath (complipath.io) keeps the record these answers rest on.
What they usually ask
- Q1“Where are the AI features hosted?”
- Q2“Which cloud providers process our data?”
- Q3“In which region is our data stored and processed?”
- Q4“Is the AI model hosted by you or by a third party?”
An example answer, part by part
An illustration for an invented product, not a real supplier's answer, to the question: In which region is our data stored and processed?
- Direct answerYes, partly or no first
- Stored in Frankfurt. The model provider processes requests in the EU.
- ControlWhat you actually do
- The region is fixed in the infrastructure configuration, and a change goes through change review.
- ScopeWhich AI systems
- Production data. Support tickets sit in the help-desk vendor's EU region.
- EvidenceWhat you can show
- The configuration line and the hosting provider's region page, read on 1 October 2026.
- ExceptionsBe honest
- Backups are kept in a second EU region.
Example. Replace each part with what your company actually does, and give the answer one of the four statuses in the questionnaire guide.
What counts as proof
- DOCThe hosting and model providers on your subprocessor list, with their regions.
- DOCThe configuration or the contract clause that fixes the region.
- DOCFor each provider, the date its region and its terms were last read.
Common mistakes
- ✗Answering for the company. Article 6 classifies systems, not companies.
- ✗"Yes" with no evidence. If you cannot attach it, the status is Partially implemented or Planned.
- ✗A policy title as the control. It says nothing about what happens to an output.
- ✗Mixing up the roles. Article 50(1) is a provider duty; Article 26 is the deployer's. Which one you are is set per system: see provider or deployer.
- ✗Not applicable with no reason. The reason is the classification.
- ✗Dropping the exception. The summary that leaves out "unless" is the one that is wrong.
What the law says
GDPR Article 28(1): the controller uses only processors providing sufficient guarantees to implement appropriate technical and organisational measures so that the processing meets the GDPR's requirements and protects the data subject's rights; under Article 28(2) another processor is engaged only with the controller's prior specific or general written authorisation.
GDPR Article 32(1): taking into account the state of the art, the costs, the nature, scope, context and purposes of processing and the risk, the controller and the processor implement appropriate technical and organisational measures, including as appropriate pseudonymisation and encryption, the ongoing confidentiality, integrity, availability and resilience of processing systems, the ability to restore availability and access after an incident, and a process for regularly testing the measures.
The GDPR articles were read from its Official Journal text (OJ L 119, 4.5.2016) on 9 October 2026; the GDPR is not in the pinned corpus behind the rest of this site.
What Complipath does
- ✓Vendor management An AI tool you buy is registered and classified like one you build, with the obligations of a deployer and the AI literacy record. There is no vendor questionnaire and no contract review.
- ✓Evidence management A file linked to the requirements it proves, with the passage and its page
- ✓Audit log Who did what, and when. No one can edit or delete a line, an owner included; only deleting the whole workspace removes it
Rules decide. AI only drafts. A person confirms.
What it does not do yet
- ✗Customer questionnaires (audit room) Coming soon Coming soon: answering a customer's AI questionnaire from your own register.
- ✗Audit pack Coming soon One file for an auditor: every system, its classification, evidence, the audit log and a fingerprint. Not available yet.
Questions
Does Complipath manage our cloud providers?
Complipath does not do your security work. It keeps the evidence and answers with a source. Each AI tool you buy is registered and classified like one you build, and the file that proves a requirement is linked to it with the passage and its page. There is no vendor questionnaire and no contract review.
Where does Complipath itself run?
The database is in Supabase eu-central-1 and the application's functions run in Vercel fra1, both in Frankfurt, as read from the providers' own records; the trust page has the reading. Complipath's own subprocessors are listed on the subprocessors page.
Answer your next questionnaire with proof.No account needed. Every answer cites the article it rests on.