Legal · Document 03 · Sub-processors
Sub-processors.
Who else processes your data when you use ComplyChat, what each one does, where the data sits, and what we have put in place to keep them honest. Every sub-processor on this page has a written contract with us that imposes the same data protection obligations on them as our contract with you imposes on us, in line with Article 28(4) UK GDPR.
01
How to read this list
"Sub-processor" has a specific meaning under the UK GDPR: another organisation we engage to process personal data on your behalf, subject to written terms that flow down from our agreement with you. It does not include parties to whom we send data on our own account (our accountants, our lawyers) or parties we communicate with on operational matters that do not involve your personal data.
The list is not "vendors we use" – it is specifically those vendors that touch personal data we process on your behalf. We have grouped them by role and shown, for each, the category of data that may flow to them, where they store it, and the legal safeguard we rely on for any transfer outside the United Kingdom.
02
Current sub-processors
Microsoft Corporation (Azure)
Hosting · Transient processing
Role
Underlying cloud platform: compute, storage, networking, brief message processing and operational logging across every governed channel (our own secure web space, including the SMS-verified web room, and Microsoft Teams). The message record at rest lives in the Customer's own Microsoft 365 tenant – where the governed record lives wherever the conversation comes from, the Customer's direct relationship with Microsoft, not a sub-processing arrangement of ours.
Data categories
Customer Data in transit and operational state: governed message content during capture and processing, metadata, identifiers and audit logs.
Location of processing
United Kingdom only – UK South region.
Safeguards
Microsoft's Online Services Data Protection Addendum, including ISO 27001/27017/27018 and SOC 2 attestations. No transfers outside the UK in respect of Customer Data stored in these regions.
Microsoft Azure Communication Services
Email · Calls
Role
Two jobs. First, outbound email for the marketing site (contact form delivery) and in-product notifications. Second, where an organisation has calls in use – on a channel it has switched calls on for, or between its own people, who can call one another from the people directory unless the organisation switches that off: Azure Communication Services carries voice and video calls inside the governed app and makes the call recording – every call is recorded, both people are told before it connects, and the recording plus its transcript then transit to the organisation's own Microsoft 365, where the lasting record rests. The written transcript is produced by machine transcription (Azure Speech, UK South), and a short AI-written summary of each recorded call is produced for staff (Azure OpenAI Service, UK South, with the AI processing itself pinned to that region); the summary is a clearly labelled working aid and is never filed into the lasting record. Both run under the same Microsoft DPA as the Azure services above – no new sub-processor entity is introduced. Messaging in a governed channel does not touch ACS; Meta plays no part anywhere.
Data categories
Email: addresses and message bodies submitted via the contact form; in-product notification recipients and content. Calls (only where the organisation has them in use, on a channel or between its own people): call audio/video in transit, the call recording and transcript while they are made and passed on, and call metadata (who called whom, when, for how long).
Location of processing
United Kingdom data location: data ACS holds at rest – including the short built-in window (up to 24 hours) it keeps a recording before hand-off – rests in the UK. Live call audio and video are carried transiently over Microsoft's global network while the call is in progress, with nothing retained; the recording and the lasting record rest in the UK and in the organisation's own Microsoft 365. Machine transcription and the AI call summary run in the UK South region, with the AI processing itself pinned to that region.
Safeguards
Microsoft's Online Services DPA applies – the same DPA and the same processor entity as the Azure and Microsoft 365 services above, not a new sub-processor. Sender domain protected with SPF and DKIM. ACS sits within Microsoft's ISO 27001/27017/27018 and SOC 2 scope.
Microsoft Azure SignalR Service
Real-time fan-out · Message content in transit
Role
Real-time message fan-out: delivers each new message to the other people in a governed channel the instant it is sent, so the room updates live. This is the only sub-processor that carries governed message content between the people in a room while it is in flight; the inbound SMS doorbell also carries content, because the words someone texts to a published number become the first message of their conversation (see Andrews & Arnold below). It keeps no persistent store of its own, and the lasting record still lands in the Customer's own Microsoft 365. Governed message content transits our ComplyChat-operated Azure room service on the way, which is our processor-in-path role.
Data categories
Governed message content in transit only (the text and attachment references passed on to room participants), together with the room identifier and participant connection metadata. Nothing is retained.
Location of processing
United Kingdom only – UK South region.
Safeguards
Microsoft's Online Services DPA applies – the same DPA and the same processor entity as the Azure and Microsoft 365 services above, not a new sub-processor entity. Fan-out is transient and scoped to the individual room group, never a scope-less broadcast, and SignalR holds no persistent store. Within Microsoft's ISO 27001/27017/27018 and SOC 2 scope.
Microsoft 365 (Exchange Online)
Operational mailboxes
Role
Shared mailboxes (enquiries@chat.org.uk, compliance@chat.org.uk) that receive correspondence from customers, prospects and data subjects.
Data categories
Sender's name, email address, and whatever they choose to put in the body of their message.
Location of processing
European Union / United Kingdom (Microsoft 365 EU Data Boundary).
Safeguards
Microsoft's Online Services DPA applies. MFA required on all administrator accounts. Access limited to staff with a legitimate need.
Twilio
SMS · One-time passcode delivery
Role
Delivers the one-time passcode text used to verify a phone number when someone opens a ComplyChat web-room channel. Twilio is in the data path only for that verification text – no governed message content passes through Twilio.
Data categories
Phone number and the one-time passcode text itself; standard delivery telemetry.
Location of processing
Twilio's global messaging infrastructure, which may process outside the United Kingdom.
Safeguards
Twilio's Data Protection Addendum, including the UK Addendum to the EU Standard Contractual Clauses for transfers outside the UK.
Andrews & Arnold Ltd (A&A)
Inbound SMS doorbell · Carries inbound message content
Role
Provides the published inbound SMS number (020 3095) that a person texts to reach a governed channel – the SMS doorbell – and carries the outbound utility texts that go with it: the invite, the content-free "new message" nudge, and the leave/opt-out confirmation. Where a person texts the published number, the words they send are captured as the first message of that governed conversation, so their content passes through A&A in flight. In the outbound direction A&A carries only the utility texts listed above – no governed room message content is sent over it.
Data categories
Phone number; the text of an inbound message sent to the published number, which becomes a governed message; and the one-time passcode, keyword (for example STOP or LEAVE) or nudge text itself; standard delivery telemetry.
Location of processing
United Kingdom – A&A is a UK-based communications provider and its SMS routing is operated in the UK.
Safeguards
A&A's own terms and UK data protection law apply; the inbound number is replyable, and any opt-out keyword (STOP/LEAVE) that the carrier forwards to us is honoured – the reliable leave route is the channel menu in the app. Outbound processing is limited to SMS routing metadata – a passcode, a keyword or a nudge link. Inbound, a text sent to the published number carries its own content, and the reply that opens the conversation says on the record before the link.
Browser push services (Apple, Google, Mozilla)
Push notifications · Metadata only
Role
Deliver the "new message" notification to a person's device when the ComplyChat app is installed to their home screen or running in the background. Which service is used depends on the person's browser and operating system: Apple Push Notification service (Safari and iOS), Google Firebase Cloud Messaging (Chrome and Android), or Mozilla autopush (Firefox). They carry a content-free nudge only.
Data categories
A device push token, the room identifier, a generic "new message" prompt and a deep link back into the app. Payloads carry no message content, no sender name and no attachment – the message itself is fetched behind sign-in only when the person taps the notification.
Location of processing
Operated on each provider's global infrastructure (Apple, Google, Mozilla), which may process outside the United Kingdom.
Safeguards
The push payload is encrypted to the person's own device under the Web Push standard (RFC 8291), so the push service relays a payload it cannot read; in any case the payload is content-free. Because only a token and a generic nudge cross the network, and never message content or special category data, the transfer is limited to routing metadata.
Stripe Payments UK Limited
Billing · Card processing · Not yet active
Role
PCI-DSS Level 1 card processing and direct debit collection for subscription fees. Card details are entered directly into Stripe-hosted elements; we never see or store them. Listed for when card billing goes live: billing currently runs on invoice and bank transfer, including against a purchase order where your finance team works that way, so Stripe is not yet an active sub-processor and no Customer Data flows to it today. It will become active when we switch on card payments, and we will follow the change-notification process in section 04 before that happens.
Data categories
Billing contact name, billing email, billing address, masked payment instrument identifiers, transaction history.
Location of processing
Contracting entity is Stripe Payments UK Limited, an FCA-authorised payment institution. Stripe's processing infrastructure is global; transaction processing may take place in the United States and other Stripe regions.
Safeguards
Stripe's Services Agreement and Data Processing Addendum, including the UK Addendum to the EU Standard Contractual Clauses for any transfers outside the UK. PCI-DSS Level 1 Service Provider attestation. SOC 1, SOC 2 and ISO 27001 audited.
Microsoft Azure Application Insights (Azure Monitor)
Operational telemetry
Role
Receives application errors, performance traces, request and dependency telemetry, and basic usage metrics, so we can diagnose and fix issues quickly.
Data categories
Diagnostic logs, stack traces, request and response metadata, exception detail. We strip message content from telemetry at source and minimise personal data; some operational identifiers (such as phone numbers) may still appear in transient diagnostic logs.
Location of processing
United Kingdom only – the Application Insights workspace is provisioned in a UK Azure region alongside the rest of the platform.
Safeguards
Microsoft's Online Services DPA applies and is the same agreement that covers Azure hosting and ACS. No additional sub-processor is introduced.
Google Ireland Limited (Google Ads / gtag.js)
Advertising measurement · Consent-gated
Role
Conversion measurement on the public marketing site only – it tells us which adverts brought a visitor here. It plays no part in the product or any governed channel and never touches message content. The tag runs under Google Consent Mode v2 with consent denied by default: it sets no advertising cookies and sends no identifiers to Google unless a visitor accepts via the cookie banner.
Data categories
Only where a visitor consents: advertising/measurement cookie identifiers and basic page-interaction events for the marketing site. No Customer Data, and no message content, is ever involved.
Location of processing
Google's global infrastructure, including the United States.
Safeguards
Google Ads Data Processing Terms, including the UK Addendum to the EU Standard Contractual Clauses for transfers outside the UK. Loaded only after consent under Consent Mode v2; see our
cookies notice.
03
Not sub-processors
For the avoidance of doubt, the following parties are not sub-processors of Customer Data and are listed only because reviewers sometimes ask:
- GitHub, Inc. – source code repository hosting. Holds our code, not Customer Data.
- Azure Static Web Apps – delivery of the chat.org.uk marketing site, and of the static shell and API proxy for the ComplyChat web room. Both ride Azure Static Web Apps' global edge network for content delivery only; no Customer Data is stored on that edge network – message processing and storage remain in the UK South region described under Azure above.
- Our professional advisers (lawyers, accountants, auditors) – engaged on our own account, under confidentiality, and only receive personal data of named individuals where strictly necessary for their advice.
04
Notification of changes
If we propose to add or replace a sub-processor that processes Customer Data, we will:
- Update this page at least 30 days before the change takes effect;
- Notify the account administrator of each affected Customer by email;
- Give you the opportunity to object on reasonable data protection grounds. If we cannot adequately address the objection, you may terminate the affected Order Form without penalty and we will refund any fees paid in advance for the unexpired portion.
If a change is needed urgently for security reasons (for example, to terminate a sub-processor that has experienced a breach), we may make the change immediately and notify you as soon as we reasonably can.
05
Questions
For questions about this list, the contracts that underpin it, or due-diligence packs on any of the named providers, write to compliance@chat.org.uk. We try to respond within five working days.