Subprocessors
Who else sees your data, and what they see
Every third party that processes data you put into Complipath is named below — and for each one, what it actually sees. A subprocessor list that names the vendor and leaves the scope to be assumed is not useful to the person reading it before a purchase — the assumption is always wrong in one direction or the other.
The questions a security team asks around this list — training, retention, deletion and sign-in — are answered in the security review.
Every row below names the party, what it is used for, and WHICH FIELDS REACH IT. Where we have not read a provider's own terms on a point, the row says unread rather than guessing. Each row carries the date it was read and the date it is to be read again.
Where a row says nothing about training, retention or region, that is because we have not read the term ourselves — not because there is none.
What we have read
One point, read off a named source and written down with what was read. Everything else about these parties is unread, in the sense above.
Resend (Resend, Inc.)
which region Resend processes in
“Ireland (eu-west-1)”
Read off our own dashboard, 24 August 2026.
This does not settle where anything else in the system is processed. A region read for one party is a region read for that party, and every subprocessor whose region is still unread is unchanged by it.
Where a language model sits, and where it does not
No language model is in the decision path. The classification engine takes your answers and nothing else — classify(answers: Answers) is its whole input — and a test in the application repository forbids every engine file from importing a database client or an observation module. That guard is a source scan, not a proof by execution: it verifies that no engine file imports those things, and the execution-level fact is carried by the type. Anchored in the application repository at commit 784a885, read 2026-08-18.
And a model does read what you give it, on the paths named in the Anthropic row below. The clearest one is the check's optional reading step: the domain you typed and the text of the public pages it fetched are sent to Anthropic's API. Your answers to the classification questions are never in that payload, because they never leave your browser. This paragraph does not list the paths itself — the row does, generated from the code rather than written twice. We have not read Anthropic's API retention terms; until someone does and records what they read, this page says so instead of guessing.
Either sentence alone is a false picture of the same system. The first without the second is a claim that no model touches anything, which the reading step contradicts; the second without the first invites the reader to assume a model decides the classification, which it does not.
Who processes what
Most seen first.
Supabase (Supabase Inc.)
Postgres database, authentication and file storage.
What they see
- users.email, users.name, users.role
- ai_systems.name, .purpose_use_case, .business_owner, .technical_owner, .type, .domain, .status, .github_repo_link
- risk_assessments.answers, .factors, .reasoning, .primary_citation, .risk_level, .confirmed_by, .contest_note, .question_wording
- obligations.owner, .evidence_link, .notes, .status
- doc_sections.body, .confirmed_by
- article_6_3_claims.reasoning, .recorded_by
- ai_literacy_records.person, .activity, .material, .evidence_link
- review_notes.body, .author_id
- activity_log.verb, .actor_id, .citation
- organizations.name, .plan, .billing_state, .settings, .profile
- every other column of every table in the schema
- the files she uploads as evidence or documentation, in a private storage bucket
What they do not see
- card numbers — the payment form is Stripe's own and never posts to us
Where it says so in the code
- lib/supabase/server.ts, lib/supabase/admin.ts (commit d77c6f7)
- supabase/migrations/ — the whole schema (commit d77c6f7)
Read 2026-08-23 by Claude (this session), from supabase/migrations/, lib/supabase/ at commit d77c6f7; project ref lfkviwccptstavpcjsho, region eu-central-1, read from the Supabase MCP project settings. To be read again by 2026-11-23.
Anthropic (Anthropic PBC)
Anthropic (Claude API) runs the AI features. When you add a file on the Evidence page or to Documentation, we send the file's text, up to 120,000 characters, so the passages can be found. When we read a company website, we send the text of its public pages and of public search results about it, up to 60,000 characters in all. Suggestions get the description you type (up to 2,000 characters) or the text of a web page you link (up to 20,000 characters). The assistant, documentation drafts and system reviews get your question and what your register and documentation say; a review also gets the passages from your files. Anthropic deletes API inputs and outputs within 30 days (Anthropic privacy center, 1 Jul 2026), does not use them for training without permission, and may keep content flagged by its safety systems for up to 2 years. Processing region: global.
What they see
- public check — the domain a visitor submits, and the extracted text of the public pages fetched from it
- answer suggestions — the description typed in the check or on the assess page, or the text of a public URL she pastes
- name suggestions — the description she typed
- documentation drafting — the system's fields, every stored engine answer, the recorded classification and the documentation section bodies that are hers
- the writing aid — her own answer for one part of the documentation
- the assistant — her question; per system its name, risk label, citation, confirmation state and obligation counts; documentation section bodies a named person has reviewed
- uploaded documentation files — the text of the file
- evidence files — the text of the file, with the requirements it is read against and her stored answers
- contradiction review — her own texts about one system
What they do not see
- any part of the register in the public check — it runs before an account exists
Where it says so in the code
- lib/check-read/read.ts
- lib/assist/model.ts
- lib/system-name-suggest.ts
- lib/docgen/generate.ts
- app/(app)/systems/[id]/documentation/writing-aid-actions.ts
- lib/assistant/answer.ts, lib/assistant/chat.ts
- lib/document/file-parts.ts (from lib/document/file-upload.ts)
- lib/evidence-read.ts (from lib/evidence-store.ts)
- lib/system-review-model.ts — all at commit b1597e4
What their own terms say
- Anthropic's privacy center, updated 1 July 2026 and read on 8 October 2026, says it deletes API inputs and outputs within 30 days of receipt or generation, except where it needs to keep them longer to enforce its Usage Policy or to comply with the law. Source.
- The same page, read on 8 October 2026, says that when its automated trust and safety systems flag content as violating its Usage Policy, Anthropic keeps inputs and outputs for up to 2 years and trust and safety classification scores for up to 7 years. Source.
- Anthropic's Data Processing Addendum, effective 24 February 2025 and read on 8 October 2026, includes the EU Standard Contractual Clauses, Module Two (controller to processor) and Module Three (processor to processor), with a UK Addendum and a Swiss Addendum, and the Commercial Terms incorporate it by reference. Source.
- For customers in the EEA, Switzerland or the UK, the contracting entity is Anthropic Ireland, Limited, according to the Commercial Terms read on 8 October 2026. Source.
- Anthropic publishes a list of its own subprocessors, read on 8 October 2026. Source.
- Its Data Processing Addendum, read on 8 October 2026, says Anthropic gives reasonable notice before a new subprocessor gets access to personal data, with 15 days from the date of that notice for a customer to object in writing; a customer that does not object within them is deemed to consent. Source.
Read 2026-10-06 by Claude (this session), from the ten `new Anthropic(` call sites in the application repository at commit b1597e4, cross-checked against the application's own content/legal/subprocessors-measured.md (5 October 2026), which named this row stale. To be read again by 2027-01-06. The description at the top is the founder's, measured in the application; its four character limits were read by Claude (this session) on 2026-10-09 at the application's commit caedbaf.
Resend (Resend, Inc.)
Delivering the sign-in link, the periodic snapshot, the corpus-change letter and feedback notes.
What they see
- users.email as the recipient of every message
- the sign-in link, which is a one-time token for that address
- snapshot — organizations.name and the letter's counts; and ai_systems.name where a legal update affects exactly one system, because the impact label then reads "Affects <name>"
- corpus letter — organizations.name and ai_systems.name for each system whose cited provisions moved
- feedback notes — organizations.name, ai_systems.name, the note she typed and the reply address she gave
What they do not see
- assessments, obligations, documentation or the activity log
- who wrote a feedback note: that column does not exist
Where it says so in the code
- app/api/snapshot/route.ts, lib/email/snapshot.ts (commit d77c6f7)
- app/api/corpus-watch/route.ts, lib/corpus-watch.ts (commit d77c6f7)
- lib/feedback-delivery.ts (commit d77c6f7)
- Supabase Auth SMTP — the sign-in template, a dashboard setting no code here can read
Read 2026-08-23 by Claude (this session), from lib/email/snapshot.ts, lib/corpus-watch.ts, lib/feedback-delivery.ts, lib/market-law.ts at commit d77c6f7. To be read again by 2026-11-23.
Vercel (Vercel Inc.)
Hosting, serverless functions and the platform log.
What they see
- the request URL of every page, which contains ai_systems.id in every /systems/<uuid>/… path
- the caller's IP address and user agent, as request metadata
- the request body of every form submission and server action — the same fields Supabase receives
- our own log lines: stripe_webhook <outcome>, stripe_webhook billing:<state>:<reason>, stripe_webhook plan_unchanged:<reason>, stripe_webhook money_back:<event>, stripe_webhook write_failed <message>, and the check-read fallback reason code
What they do not see
- a domain, a system name or a page excerpt in any log line we write — the check-read guard pins the log statement character-for-character and requires a bare literal at every call site
Where it says so in the code
- app/api/stripe-webhook/route.ts, lib/check-read/reason.ts (commit d77c6f7)
- middleware.ts — every matched route (commit d77c6f7)
Read 2026-08-23 by Claude (this session), from a sweep of every console.* call in app/ and lib/ at commit d77c6f7; vercel.json pins functions to fra1. To be read again by 2026-11-23.
Calendly (legal form not read — see unread)
One booking page for a call, published on the marketing site.
What they see
- the visitor's name, email address and time zone, collected by Calendly's own form on every booking
- her answer to "Company name and website" — a required question, so every booking carries it
- her answer to "Roughly how many AI systems do you think you have?" — a required question, so every booking carries it
- her answer to "Anything you want me to look at before we talk?" — optional, so only where she wrote something
What they do not see
- any field of a register — a booking happens before an account exists, and nothing in this application sends anything to Calendly
Where it says so in the code
- no file in this repository — a published link, not a module. Zero references to calendly.com in app/, lib/, components/ or public/ at commit eb0cd5f
- Yobetzegai/complipath-marketing holds the booking URL in content/call-to-action.json with onTheSite: true — 43 anchors across 34 delivered pages link it, and tools/cta-guard.mjs enforces them on every build
- walked 2026-10-09: five on the home page, four on the pricing page, two on the what-complipath-is page, two on the founder's page, one each on the deadlines, guides and partner programme pages
- and one on each of the 27 buyer pages and pages by tool, industry, use case and country, each a named row of content/cta-table.json
- It said thirteen until 2026-10-09, when the founder's design v12 put the walkthrough beside the check on the buyer pages and on /about/ and /partners/ (passes 59 and 60).
- It said eleven until 2026-10-07, when the founder's setup-call offer added one on /pricing/ and one on /what-complipath-is/ (pass 43).
- It said nine until 2026-10-05, when the tour film's end screen added one on the home page and one on /what-complipath-is/ (pass 34).
- It said five until 2026-10-04, when the founder's design moved the placements (pass 33); the count rose again as /deadlines/ and /guides/ were rebuilt.
- It said four until 2026-09-06, counting the pricing cards onto the home page as well and missing the FAQ anchor the same pass added; the number is derived from the delivered pages now.
- It said the opposite until 2026-09-06: the links came back by founder order on 2026-08-31 and the gate was correctly changed to enforce declared placements instead of zero, while this sentence about the gate was not
- the second instance of that class found on this site, the first being the same claim on /privacy/
- so a booking is reached by email today, and by nothing this application renders — the last in-product link was removed on 2026-08-22
Read 2026-08-23 by Yobel Tzegai (the founder, against Calendly's own API), from Calendly's API, read by the founder on 2026-08-23: one active event type under the hello-complipath account, with the three custom questions above; plus a sweep of this repository at commit eb0cd5f for the link. To be read again by 2026-11-23.
Stripe (Stripe Payments Europe, Ltd.)
Taking payment, through a Checkout session our server creates.
What they see
- organizations.id, sent as the session's client_reference_id
- the price of the plan she chooses
- her billing details, entered on Stripe's own page: name, address, card
What they do not see
- any field of the register — no system name, no purpose, no assessment, no obligation
- users.email, unless she types it into Stripe's own form
Where it says so in the code
- lib/checkout.ts — client_reference_id: args.organizationId (commit b1597e4)
- app/api/stripe-webhook/route.ts — receives (commit b1597e4)
Read 2026-10-06 by Claude (this session), from lib/checkout.ts and app/api/stripe-webhook/route.ts at commit b1597e4; components/pricing-table.tsx, which the previous reading cited, no longer exists. To be read again by 2027-01-06.
Perplexity (Perplexity AI, Inc.)
One search call in the public classifier, for what third parties publish about a company.
What they see
- the domain a visitor submits, inside the search prompt
What they do not see
- the text of her pages — those go to Anthropic, not here
- anything from a register: this runs before an account exists
Where it says so in the code
- lib/check-read/research.ts — buildResearchPrompt(domain) (commit d77c6f7)
Read 2026-08-23 by Claude (this session), from lib/check-read/research.ts at commit d77c6f7. To be read again by 2026-11-23.
Google Fonts (Google LLC)
Typeface files, downloaded once at build time and served from our own origin.
What they see
Nothing. No request from anyone reading this site or using the product reaches them.
What they do not see
- the request that loads a font file — it never leaves our origin, so no visitor IP, user agent or referrer reaches Google
Where it says so in the code
- app/layout.tsx — next/font/google (commit d77c6f7)
Read 2026-08-23 by Claude (this session), from app/layout.tsx at commit d77c6f7, plus a build-output count of .next/static/media/*.woff2 and a repository-wide search for fonts.googleapis.com and fonts.gstatic.com. To be read again by 2026-11-23.