This list distinguishes processors from independent providers and optional tools. Open-source components operated inside DocAccessible infrastructure—such as PostgreSQL, Valkey, MinIO/S3-compatible storage services, ClamAV, and veraPDF—do not receive data as separate third-party SaaS vendors when self-operated.
Current provider roles
Actual use depends on deployment configuration and the customer feature used. Providers receive only data needed for the stated purpose. No listed provider is authorized to use Customer Content for advertising.
Production infrastructure and S3-compatible storage provider
- Purpose
- Application hosting, database, queue, backup storage, and private object storage.
- Data involved
- Account, workspace, Customer Content, workflow, log, and operational data required to host the service.
- When used
- Required. The current legal provider and hosting location are deployment-dependent and are confirmed in a customer order or security response; DocAccessible does not publish an unsupported residency claim.
Anthropic
- Purpose
- Direct AI-assisted image description, visual transcript reconstruction, eligible PDF structure interpretation, and advisory fidelity comparison.
- Data involved
- Eligible source PDFs or images, extracted block inventory, and generated analysis. Not every document is sent.
- When used
- Feature-dependent. Commercial API handling applies; output remains advisory.
OpenAI
- Purpose
- Direct AI-assisted image description, visual transcript reconstruction, eligible PDF structure interpretation, and advisory fidelity comparison.
- Data involved
- Eligible source PDFs or images, extracted block inventory, and generated analysis. Not every document is sent.
- When used
- Feature-dependent and used only when configured. Commercial API handling applies; response storage is disabled by the integration.
OpenRouter and the selected downstream model provider
- Purpose
- Routing AI-assisted document and image work to the configured model provider.
- Data involved
- Eligible source PDFs or images, extracted block inventory, routing metadata, and generated analysis. Not every document is sent.
- When used
- Feature-dependent and used only when configured. Routes deny provider data collection and require Zero Data Retention compatibility by default; the selected downstream provider also processes the request.
Resend
- Purpose
- Transactional email, invitations, milestones, delivery notices, authentication messages, and contact notifications.
- Data involved
- Recipient email, message content, delivery metadata, and the minimum workflow context needed for the notice.
- When used
- Required for configured email delivery. Customer document attachments are not sent in routine transactional email.
Dodo Payments
- Purpose
- Merchant-of-record checkout, subscription management, invoices, taxes, refunds, and payment processing.
- Data involved
- Billing contact, selected plan, transaction and subscription identifiers, payment status, and card data collected directly by Dodo.
- When used
- Required for paid online subscriptions. Dodo may act as an independent controller for payment and legal obligations.
Sentry
- Purpose
- Application error monitoring and performance diagnostics.
- Data involved
- Scrubbed error, route, release, device, and performance context. Default PII capture is disabled.
- When used
- Deployment-dependent. Customer files, credentials, cookies, and private URLs are excluded by policy and scrubbers.
Google Analytics
- Purpose
- Aggregate public-site and product-action analytics.
- Data involved
- Page path, referral attribution, event completion, browser context, and web performance after consent.
- When used
- Optional and consent-based. Google signals and ad-personalization signals are disabled.
PostHog
- Purpose
- Deliberate product-action analytics.
- Data involved
- Privacy-filtered product event properties and, after sign-in, an opaque internal user ID after consent.
- When used
- Optional and consent-based. Autocapture, page-view and page-leave capture, exception capture, and session recording are disabled.
Changes and objections
We update this page before or when a material new processor begins handling Customer Personal Data, except for an urgent replacement needed to protect security or availability. Customers subject to the DPA may object on reasonable data-protection grounds within 15 days by using the privacy contact form. We will assess a practical alternative or the termination right described in the DPA.
Provider documentation
Provider privacy and security terms can change. Procurement teams can request the current contractual provider name, processing location, and transfer mechanism applicable to their proposed order. We will confirm facts in writing rather than infer data residency from a software default or provider marketing page.