Legal · Document 03 · Sub-processors
Sub-processors.
Who else processes your data when you use ComplyChat, what each one does, where the data sits, and what we have put in place to keep them honest. Every sub-processor on this page has a written contract with us that imposes the same data protection obligations on them as our contract with you imposes on us, in line with Article 28(4) UK GDPR.
01
How to read this list
"Sub-processor" has a specific meaning under the UK GDPR: another organisation we engage to process personal data on your behalf, subject to written terms that flow down from our agreement with you. It does not include parties to whom we send data on our own account (our accountants, our lawyers) or parties we communicate with on operational matters that do not involve your personal data.
The list is not "vendors we use" – it is specifically those vendors that touch personal data we process on your behalf. We have grouped them by role and shown, for each, the category of data that may flow to them, where they store it, and the legal safeguard we rely on for any transfer outside the United Kingdom.
02
Current sub-processors
Microsoft Corporation (Azure)
Hosting · Transient processing
Role
Underlying cloud platform: compute, storage, networking, brief message processing and operational logging across every governed channel (our own secure web space, including the SMS-verified web room, and Microsoft Teams). The message record at rest lives in the Customer's own Microsoft 365 tenant – where the governed record lives wherever the conversation comes from, the Customer's direct relationship with Microsoft, not a sub-processing arrangement of ours. Where a Customer answers from Microsoft Teams, the messages its staff post in a mapped Teams channel reach us through Azure Bot Service, a Microsoft Azure service under this same agreement.
Data categories
Customer Data in transit and operational state: governed message content during capture and processing, metadata, identifiers and audit logs.
Location of processing
United Kingdom for Customer Data at rest and in processing – UK South region, with backups of our operational database replicated to UK West, Microsoft's paired UK region. Both regions are in the United Kingdom. Three Azure services sit outside this and are listed separately below: Azure Front Door, the edge network and web application firewall every connection arrives through; Azure Static Web Apps in West Europe, which serves the static app shell and the public site; and Azure Maps, which draws the map picture on a shared location card.
Safeguards
Microsoft's Online Services Data Protection Addendum, including ISO 27001/27017/27018 and SOC 2 attestations. No transfers outside the UK in respect of Customer Data stored in these regions.
Microsoft Azure Front Door
Edge network · Web application firewall
Role
The edge network and web application firewall in front of the app, the client portal, the operator console and the public site: TLS termination, request routing and rate limiting. Nothing is cached or stored at the edge.
Data categories
Customer Data in transit only, while a request passes through; edge access and firewall logs (IP address, URL, user agent and timestamps – never message content).
Location of processing
The Microsoft point of presence nearest the person connecting, worldwide – normally a UK point of presence for someone in the United Kingdom – with the request carried to UK South over Microsoft's network. Edge logs are stored in UK South.
Safeguards
Microsoft's Online Services Data Protection Addendum; UK adequacy regulations for points of presence in the European Union; UK Addendum to the EU SCCs beyond them. No caching or storage at the edge.
Microsoft Azure Static Web Apps
Hosting · Static shell
Role
Serves the static shell of the app and the pages of the public site, and proxies app requests to the UK South backend. Holds no Customer Data at rest.
Data categories
Customer Data in transit only, while an app request is proxied to UK South; the static files themselves contain no Customer Data.
Location of processing
West Europe – Microsoft offers no UK region for this service. The backend it proxies to is in UK South.
Safeguards
Microsoft's Online Services Data Protection Addendum; UK adequacy regulations for the EU. No Customer Data at rest.
Microsoft Azure Communication Services
Email · Calls
Role
Two jobs. First, outbound email for the marketing site (contact form delivery) and in-product notifications. Second, where an organisation has calls in use – on a channel it has switched calls on for, or between its own people, who can call one another from the people directory unless the organisation switches that off: Azure Communication Services carries voice and video calls inside the governed app and makes the call recording – every call is recorded, both people are told before it connects, and on paid plans the recording plus its transcript then transit to the organisation's own Microsoft 365, where the lasting record rests. Free uses call captures for AI processing and removes them under the Free retention policy; see the
Free privacy notice. The written transcript is produced by machine transcription (Azure Speech, UK South), and a short AI-written summary of each recorded call is produced for staff (Azure OpenAI Service, UK South, with the AI processing itself pinned to that region); the summary is a clearly labelled working aid and is never filed into the lasting record. Both run under the same Microsoft DPA as the Azure services above – no new sub-processor entity is introduced. Messaging in a governed channel does not touch ACS; Meta plays no part anywhere.
Data categories
Email: addresses and message bodies submitted via the contact form; in-product notification recipients and content. Calls (only where the organisation has them in use, on a channel or between its own people): call audio/video in transit, the call recording and transcript while they are made and passed on, and call metadata (who called whom, when, for how long).
Location of processing
United Kingdom data location: data ACS holds at rest – including the short built-in window (up to 24 hours) it keeps a recording before hand-off – rests in the UK. Live call audio and video are carried transiently over Microsoft's global network while the call is in progress. Recording events use Azure Event Grid, whose event data may be processed outside the UK; the recording and the lasting record rest in the UK and in the organisation's own Microsoft 365. Machine transcription and the AI call summary run in the UK South region, with the AI processing itself pinned to that region.
Safeguards
Microsoft's Online Services DPA applies – the same DPA and the same processor entity as the Azure and Microsoft 365 services above, not a new sub-processor. Sender domain protected with SPF and DKIM. ACS sits within Microsoft's ISO 27001/27017/27018 and SOC 2 scope.
Microsoft Azure SignalR Service
Real-time fan-out · Message content in transit
Role
Real-time message fan-out: delivers each new message to the other people in a governed channel the instant it is sent, so the room updates live. This is the only sub-processor that carries governed message content between the people in a room while it is in flight; the inbound SMS doorbell also carries content, because the words someone texts to a published number become the first message of their conversation (see Andrews & Arnold below). It keeps no persistent store of its own, and the lasting record still lands in the Customer's own Microsoft 365. Governed message content transits our ComplyChat-operated Azure room service on the way, which is our processor-in-path role.
Data categories
Governed message content in transit only (the text and attachment references passed on to room participants), together with the room identifier and participant connection metadata. Nothing is retained.
Location of processing
United Kingdom only – UK South region.
Safeguards
Microsoft's Online Services DPA applies – the same DPA and the same processor entity as the Azure and Microsoft 365 services above, not a new sub-processor entity. Fan-out is transient and scoped to the individual room group, never a scope-less broadcast, and SignalR holds no persistent store. Within Microsoft's ISO 27001/27017/27018 and SOC 2 scope.
Microsoft Azure Maps
Location card map picture
Role
Draws the small map picture shown on a location card, and only where a member has chosen to share a location in a governed channel. Our servers fetch the picture and pass it on, so the member's device never contacts the map service; the same server-side route draws the picture in a client administrator's Replay view of a channel, so both surfaces behave identically. Azure Maps plays no part in capturing, delivering or storing the message itself – the shared coordinates are message content and rest, like every other message, in the Customer's own Microsoft 365.
Data categories
The shared coordinates and nothing else: a latitude and longitude, to six decimal places, sent once as the centre of the picture and once as the pin on it. No IP address, no name or phone number, no member, channel or organisation identity and no message text accompanies them, so the map service is given no means of connecting a point on a map to a person. The returned picture is held in the memory of the server that fetched it for up to twelve hours, under a coordinate rounded to roughly a ten-metre grain, and neither picture nor coordinate is written to any database of ours.
Location of processing
Outside the United Kingdom – the map account is in Microsoft's West Europe region and the service answers on a global endpoint (atlas.microsoft.com), so a request may be served from Microsoft infrastructure elsewhere. Map thumbnails are processed outside the United Kingdom. Live-call routing and recording-event delivery may also take place outside the UK; the other transfers named on this page – our operational mailboxes in the EU Data Boundary, the verification text, and device push – are listed in their own rows. Moving the map account to a UK region would not remove the transfer, because the endpoint that serves it is global – so we disclose it rather than promise to fix it.
Safeguards
Microsoft's Online Services Data Protection Addendum applies – the same DPA and the same processor entity as the Azure services above, not a new sub-processor entity; it is listed separately because its region differs from every other Azure entry on this page, and a residency row that reads “United Kingdom only” must not be made to cover it. Tapping a location card is a separate matter and Google is not a sub-processor for it. On a phone or tablet, and in our apps, the tap opens whichever map application the device already has, so nothing leaves the device to anyone. In a desktop browser it opens Google Maps at those coordinates: that request is made by your own browser directly to Google, not by us on your behalf, so no data is transferred to Google by us and Google processes nothing for us – which is why they are described here and in our privacy notice rather than listed as a processor. The UK's adequacy regulations for the EU cover the West Europe account, and the UK Addendum to the EU SCCs governs any transfer beyond it. Within Microsoft's ISO 27001/27017/27018 and SOC 2 scope. Data minimisation is the substantive safeguard here: coordinates alone, no identifier of any kind, and nothing retained by us beyond a short in-memory picture cache.
Microsoft 365 (Exchange Online)
Operational mailboxes
Role
Shared mailboxes (enquiries@chat.org.uk, compliance@chat.org.uk) that receive correspondence from customers, prospects and data subjects.
Data categories
Sender's name, email address, and whatever they choose to put in the body of their message.
Location of processing
European Union / United Kingdom (Microsoft 365 EU Data Boundary).
Safeguards
Microsoft's Online Services DPA applies. MFA required on all administrator accounts. Access limited to staff with a legitimate need.
Twilio
SMS · One-time passcode delivery
Role
Delivers the one-time passcode text used to verify a phone number when someone opens a ComplyChat web-room channel. Twilio is in the data path only for that verification text – no governed message content passes through Twilio.
Data categories
Phone number and the one-time passcode text itself; standard delivery telemetry.
Location of processing
Twilio's global messaging infrastructure, which may process outside the United Kingdom.
Safeguards
Twilio's Data Protection Addendum, including the UK Addendum to the EU Standard Contractual Clauses for transfers outside the UK.
Andrews & Arnold Ltd (A&A)
Inbound SMS doorbell · Carries inbound message content
Role
Provides the published inbound SMS number (020 3095) that a person texts to reach a governed channel – the SMS doorbell – and carries the outbound utility texts that go with it: the invite, the content-free "new message" nudge, and the leave/opt-out confirmation. Where a person texts the published number, the words they send are captured as the first message of that governed conversation, so their content passes through A&A in flight. In the outbound direction A&A carries only the utility texts listed above – no governed room message content is sent over it.
Data categories
Phone number; the text of an inbound message sent to the published number, which becomes a governed message; and the one-time passcode, keyword (for example STOP or LEAVE) or nudge text itself; standard delivery telemetry.
Location of processing
United Kingdom – A&A is a UK-based communications provider and its SMS routing is operated in the UK.
Safeguards
A&A's own terms and UK data protection law apply; the inbound number is replyable, and any opt-out keyword (STOP/LEAVE) that the carrier forwards to us is honoured – the reliable leave route is the channel menu in the app. Outbound processing is limited to SMS routing metadata – a passcode, a keyword or a nudge link. Inbound, a text sent to the published number carries its own content, and the reply that opens the conversation says on the record before the link.
Browser push services (Apple, Google, Mozilla)
Push notifications · Metadata only
Role
Deliver the "new message" notification to a person's device when the ComplyChat app is installed to their home screen or running in the background. Which service is used depends on the person's browser and operating system: Apple Push Notification service (Safari and iOS), Google Firebase Cloud Messaging (Chrome and Android), or Mozilla autopush (Firefox). They carry a content-free nudge only.
Data categories
A device push token, the room identifier, a generic "new message" prompt and a deep link back into the app. Payloads carry no message content, no sender name and no attachment – the message itself is fetched behind sign-in only when the person taps the notification.
Location of processing
Operated on each provider's global infrastructure (Apple, Google, Mozilla), which may process outside the United Kingdom.
Safeguards
The push payload is encrypted to the person's own device under the Web Push standard (RFC 8291), so the push service relays a payload it cannot read; in any case the payload is content-free. Because only a token and a generic nudge cross the network, and never message content or special category data, the transfer is limited to routing metadata.
Stripe Payments UK Limited
Billing · Card processing
Role
PCI-DSS Level 1 card processing and direct debit collection for subscription fees, where a Customer chooses to pay by card rather than by invoice and bank transfer. Card details are entered directly into Stripe-hosted elements; we never see or store them. What reaches Stripe is the billing contact's details and the payment itself, never Customer Data from a governed channel; Customers who pay on invoice, including against a purchase order, send nothing to Stripe.
Data categories
Billing contact name, billing email, billing address, masked payment instrument identifiers, transaction history.
Location of processing
Contracting entity is Stripe Payments UK Limited, an FCA-authorised payment institution. Stripe's processing infrastructure is global; transaction processing may take place in the United States and other Stripe regions.
Safeguards
Stripe's Services Agreement and Data Processing Addendum, including the UK Addendum to the EU Standard Contractual Clauses for any transfers outside the UK. PCI-DSS Level 1 Service Provider attestation. SOC 1, SOC 2 and ISO 27001 audited.
Microsoft Azure Application Insights (Azure Monitor)
Operational telemetry
Role
Receives application errors, performance traces, request and dependency telemetry, and basic usage metrics, so we can diagnose and fix issues quickly.
Data categories
Diagnostic logs, stack traces, request and response metadata, exception detail. We strip message content from telemetry at source and minimise personal data; some operational identifiers (such as phone numbers) may still appear in transient diagnostic logs.
Location of processing
United Kingdom only – the Application Insights workspace is provisioned in a UK Azure region alongside the rest of the platform.
Safeguards
Microsoft's Online Services DPA applies and is the same agreement that covers Azure hosting and ACS. No additional sub-processor is introduced.
Google Ireland Limited (Google Ads / gtag.js)
Advertising measurement · Consent-gated
Role
Conversion measurement on the public marketing site only – it tells us which adverts brought a visitor here. It plays no part in the product or any governed channel and never touches message content. The tag runs under Google Consent Mode v2 with consent denied by default: it sets no advertising cookies and sends no identifiers to Google unless a visitor accepts via the cookie banner.
Data categories
Only where a visitor consents: advertising/measurement cookie identifiers and basic page-interaction events for the marketing site. No Customer Data, and no message content, is ever involved.
Location of processing
Google's global infrastructure, including the United States.
Safeguards
Google Ads Data Processing Terms, including the UK Addendum to the EU Standard Contractual Clauses for transfers outside the UK. Loaded only after consent under Consent Mode v2; see our
cookies notice.
Microsoft Ireland Operations Limited (Microsoft Advertising UET tag, Microsoft Clarity)
Advertising measurement and page analytics · Consent-gated · Added 12 September 2026
Role
Two scripts on the public marketing site and the Free signup page only. The Microsoft Advertising tag (UET) tells us which Microsoft and Bing adverts brought a visitor here and whether the visit led to an enquiry or a Free signup. Microsoft Clarity records how those pages are used – clicks, scrolling and navigation – so that we can see where visitors get stuck; what a visitor types into a form is masked before it leaves the browser. Neither script is loaded until the visitor accepts our cookie banner, and neither plays any part in the product or any governed channel or ever touches message content.
Data categories
Only where a visitor consents: advertising/measurement cookie identifiers, page-interaction events and recordings of how the marketing site and the Free signup page are used, with form entries masked. No Customer Data, and no message content, is ever involved.
Location of processing
Microsoft's global infrastructure, including the United States.
Safeguards
Microsoft's published terms for Microsoft Advertising and Microsoft Clarity, including Microsoft's data-protection terms for those services and standard contractual clauses with the UK Addendum for any transfer outside the UK. Loaded only after consent; see our
cookies notice.
03
Not sub-processors
For the avoidance of doubt, the following parties are not sub-processors of Customer Data and are listed only because reviewers sometimes ask:
- GitHub, Inc. – source code repository hosting. Holds our code, not Customer Data.
- Azure Static Web Apps – delivery of the chat.org.uk marketing site, and of the static shell and API proxy for the ComplyChat web room. Both use Azure Static Web Apps' global edge network. The API proxy carries requests to the UK backend; this is not a guarantee that all request handling takes place in the UK. The application database and core message processing remain in the UK South region described under Azure above.
- Our professional advisers (lawyers, accountants, auditors) – engaged on our own account, under confidentiality, and only receive personal data of named individuals where strictly necessary for their advice.
04
Notification of changes
If we propose to add or replace a sub-processor that processes Customer Data, we will:
- Update this page at least 30 days before the change takes effect;
- Notify the account administrator of each affected Customer by email;
- Give you the opportunity to object on reasonable data protection grounds. If we cannot adequately address the objection, you may terminate the affected Order Form without penalty and we will refund any fees paid in advance for the unexpired portion.
If a change is needed urgently for security reasons (for example, to terminate a sub-processor that has experienced a breach), we may make the change immediately and notify you as soon as we reasonably can.
05
Questions
For questions about this list, the contracts that underpin it, or due-diligence packs on any of the named providers, write to compliance@chat.org.uk. We try to respond within five working days.