Loading legal document…
Third-party service providers that process personal data on behalf of MultiComply
This page is re-checked when the region guard reports that compute has moved, when a provider notifies a sub-processor change, when a certification comes up for renewal, when a new third party enters a request path, and in any event every six months.
Under GDPR Article 28, you have the right to:
To exercise these rights, email privacy@multicomply.com
All third-party services that access or process customer data
| Subprocessor | Service | Data Location | Data Transferred | Added | Links |
|---|---|---|---|---|---|
Supabase, Inc. Supabase, Inc. (United States). The data importer under Supabase’s own SCCs is Supabase Pte. Ltd., Singapore — a country with no EU adequacy decision | Database & Authentication PostgreSQL database hosting, user authentication, file storage, backup and recovery | Where it processes: European Union (Sweden, Stockholm — AWS eu-north-1) Where it stores: European Union (Sweden, Stockholm — AWS eu-north-1) Evidence
| International Transfer SCCs in Processor DPA Protection Mechanisms:
Technical & Organizational Measures:
| ||
Stripe Payments Europe, Limited (EEA counterparty) — Stripe, LLC (recipient, United States) Stripe Payments Europe, Limited (Ireland) is the EEA counterparty; personal data is transferred onward to Stripe, LLC (United States) | Payment Processing Processing subscription payments, managing billing, handling refunds, fraud prevention, tax calculation | Where it processes: European Union (Ireland) — contracting entity; United States — recipient Where it stores: European Union (Ireland) — contracting entity; United States — recipient Evidence
| International Transfer EU-US DPF Certified Protection Mechanisms:
Technical & Organizational Measures:
| ||
Cloudflare, Inc. Cloudflare, Inc. (United States). Processor for bot-blocking and, separately, controller for improving its own detection models | Security & CAPTCHA Bot protection via Turnstile CAPTCHA, DDoS protection, web application firewall, CDN for static assets | Where it processes: Global (anycast — cannot be pinned to a country) Where it stores: Global (anycast — cannot be pinned to a country) Evidence
| International Transfer EU-US DPF Certified Protection Mechanisms:
Technical & Organizational Measures:
| ||
PLUS FIVE FIVE, INC. (trading as Resend) PLUS FIVE FIVE, INC. trading as Resend (United States). Processor for message data; independent controller for account, billing and usage data | Transactional Email Delivery Sending account notifications, password reset emails, DSAR verification emails, compliance alerts | Where it processes: United States Where it stores: United States Evidence
| International Transfer EU-US DPF Certified Protection Mechanisms:
Technical & Organizational Measures:
| ||
Billingo Technologies Zrt. Billingo Technologies Zrt., seat at 1133 Budapest, Árbóc utca 6 (Hungary) | NAV-compliant Invoice Issuance Issuing Hungarian NAV-compliant electronic invoices for paid subscriptions, VAT calculation and reporting, NAV Online Számla submission | Where it processes: Hungary (company seat); hosting provider named as AWS, region not stated Where it stores: Hungary (company seat); hosting provider named as AWS, region not stated Evidence
| EU Only | ||
European Commission (VIES) European Commission, Directorate-General for Taxation and Customs Union (an EU institution, not a third-country recipient) | EU VAT Number Validation (VIES) Verifying a business customer’s VAT number against the EU VIES register, as required to apply the B2B reverse charge and to hold proof of that check for a tax audit | Where it processes: European Union — European Commission infrastructure Where it stores: European Union — European Commission infrastructure Evidence
| EU Only | ||
Vercel Inc. Vercel Inc. (United States). Functions pinned to arn1/Stockholm; Vercel’s DPA states its primary processing facilities are in the United States | Application Hosting & Edge Compute Hosting the MultiComply web application, serverless function execution, edge CDN delivery, deployment infrastructure | Where it processes: European Union (Sweden, Stockholm — Vercel arn1) Where it stores: European Union (Sweden, Stockholm — Vercel arn1) Backup: United States (Vercel corporate processing; see DPA) Evidence
| International Transfer EU-US DPF Certified Protection Mechanisms:
Technical & Organizational Measures:
|
Database & Authentication
PostgreSQL database hosting, user authentication, file storage, backup and recovery
All user data, generated documents, form answers, activity logs
Payment Processing
Processing subscription payments, managing billing, handling refunds, fraud prevention, tax calculation
Name, email address, billing address, payment card details (tokenized), transaction history, IP address
Security & CAPTCHA
Bot protection via Turnstile CAPTCHA, DDoS protection, web application firewall, CDN for static assets
IP address, browser fingerprint, user agent, request metadata
Transactional Email Delivery
Sending account notifications, password reset emails, DSAR verification emails, compliance alerts
Recipient email address, recipient name, email subject and content
NAV-compliant Invoice Issuance
Issuing Hungarian NAV-compliant electronic invoices for paid subscriptions, VAT calculation and reporting, NAV Online Számla submission
Customer name, billing address, VAT/tax number, invoice line items, transaction amounts
EU VAT Number Validation (VIES)
Verifying a business customer’s VAT number against the EU VIES register, as required to apply the B2B reverse charge and to hold proof of that check for a tax audit
The customer’s country code and VAT number, and our own VAT number as the requesting party. No name, address or contact details are sent.
Application Hosting & Edge Compute
Hosting the MultiComply web application, serverless function execution, edge CDN delivery, deployment infrastructure
IP address, user agent, HTTP request metadata; production data flows through serverless functions to Supabase
We'll email you 30 days before adding new subprocessors (GDPR Article 28 requirement)
You can unsubscribe at any time. We will only send emails about subprocessor changes.
Supabase stores all primary data on EU servers (Sweden, Stockholm — eu-north-1). For disaster recovery purposes, encrypted backups are replicated to US servers.
Transfer protections in place:
This transfer is protected under GDPR Chapter V via Standard Contractual Clauses incorporated in the Supabase Data Processing Agreement.
Under GDPR Article 28(2), you have the right to object to new subprocessors. Here's the process:
Yes. As a customer, you have the right to review our DPAs with subprocessors to ensure adequate data protection.
Email privacy@multicomply.com with the subject "DPA Request" and specify which subprocessor's DPA you need.
You can also access public DPAs directly via the "DPA ↗" links in the table above.
No. MultiComply does NOT send your data to any AI service (Anthropic Claude, OpenAI, etc.) for document generation.
All documents are generated using template-based mail-merge technology. Your form answers are inserted into lawyer-written templates stored in our Supabase database. No AI is involved in the process.