Legal & trust

Subprocessor List

These providers and provider categories help DocAccessible deliver infrastructure, AI-assisted analysis, email, billing, diagnostics, and optional analytics.

Effective July 18, 2026Version 2026-07-18

This list distinguishes processors from independent providers and optional tools. Open-source components operated inside DocAccessible infrastructure—such as PostgreSQL, Valkey, MinIO/S3-compatible storage services, ClamAV, and veraPDF—do not receive data as separate third-party SaaS vendors when self-operated.

Current provider roles

Actual use depends on deployment configuration and the customer feature used. Providers receive only data needed for the stated purpose. No listed provider is authorized to use Customer Content for advertising.

Production infrastructure and S3-compatible storage provider

Purpose
Application hosting, database, queue, backup storage, and private object storage.
Data involved
Account, workspace, Customer Content, workflow, log, and operational data required to host the service.
When used
Required. The current legal provider and hosting location are deployment-dependent and are confirmed in a customer order or security response; DocAccessible does not publish an unsupported residency claim.

Anthropic

Purpose
Direct AI-assisted image description, visual transcript reconstruction, eligible PDF structure interpretation, and advisory fidelity comparison.
Data involved
Eligible source PDFs or images, extracted block inventory, and generated analysis. Not every document is sent.
When used
Feature-dependent. Commercial API handling applies; output remains advisory.

OpenAI

Purpose
Direct AI-assisted image description, visual transcript reconstruction, eligible PDF structure interpretation, and advisory fidelity comparison.
Data involved
Eligible source PDFs or images, extracted block inventory, and generated analysis. Not every document is sent.
When used
Feature-dependent and used only when configured. Commercial API handling applies; response storage is disabled by the integration.

OpenRouter and the selected downstream model provider

Purpose
Routing AI-assisted document and image work to the configured model provider.
Data involved
Eligible source PDFs or images, extracted block inventory, routing metadata, and generated analysis. Not every document is sent.
When used
Feature-dependent and used only when configured. Routes deny provider data collection and require Zero Data Retention compatibility by default; the selected downstream provider also processes the request.

Resend

Purpose
Transactional email, invitations, milestones, delivery notices, authentication messages, and contact notifications.
Data involved
Recipient email, message content, delivery metadata, and the minimum workflow context needed for the notice.
When used
Required for configured email delivery. Customer document attachments are not sent in routine transactional email.

Dodo Payments

Purpose
Merchant-of-record checkout, subscription management, invoices, taxes, refunds, and payment processing.
Data involved
Billing contact, selected plan, transaction and subscription identifiers, payment status, and card data collected directly by Dodo.
When used
Required for paid online subscriptions. Dodo may act as an independent controller for payment and legal obligations.

Sentry

Purpose
Application error monitoring and performance diagnostics.
Data involved
Scrubbed error, route, release, device, and performance context. Default PII capture is disabled.
When used
Deployment-dependent. Customer files, credentials, cookies, and private URLs are excluded by policy and scrubbers.

Google Analytics

Purpose
Aggregate public-site and product-action analytics.
Data involved
Page path, referral attribution, event completion, browser context, and web performance after consent.
When used
Optional and consent-based. Google signals and ad-personalization signals are disabled.

PostHog

Purpose
Deliberate product-action analytics.
Data involved
Privacy-filtered product event properties and, after sign-in, an opaque internal user ID after consent.
When used
Optional and consent-based. Autocapture, page-view and page-leave capture, exception capture, and session recording are disabled.

Changes and objections

We update this page before or when a material new processor begins handling Customer Personal Data, except for an urgent replacement needed to protect security or availability. Customers subject to the DPA may object on reasonable data-protection grounds within 15 days by using the privacy contact form. We will assess a practical alternative or the termination right described in the DPA.

Provider documentation

Provider privacy and security terms can change. Procurement teams can request the current contractual provider name, processing location, and transfer mechanism applicable to their proposed order. We will confirm facts in writing rather than infer data residency from a software default or provider marketing page.