DocAccessible

Legal & trust

Subprocessor List

These providers and provider categories help DocAccessible deliver infrastructure, AI-assisted analysis, email, billing, diagnostics, and optional analytics.

Effective July 18, 2026Version 2026-07-18

This list distinguishes processors from independent providers and optional tools. Open-source components operated inside DocAccessible infrastructure—such as PostgreSQL, Valkey, MinIO/S3-compatible storage services, ClamAV, and veraPDF—do not receive data as separate third-party SaaS vendors when self-operated.

Current provider roles

Actual use depends on deployment configuration and the customer feature used. Providers receive only data needed for the stated purpose. No listed provider is authorized to use Customer Content for advertising.

Production infrastructure and S3-compatible storage provider

Purpose
Application hosting, database, queue, backup storage, and private object storage.
Data involved
Account, workspace, Customer Content, workflow, log, and operational data required to host the service.
When used
Required. The current legal provider and hosting location are deployment-dependent and are confirmed in a customer order or security response; DocAccessible does not publish an unsupported residency claim.

Anthropic

Purpose
AI-assisted image description, eligible PDF structure interpretation, and advisory fidelity comparison.
Data involved
Eligible source PDFs or images, extracted block inventory, and generated analysis. Not every document is sent.
When used
Feature-dependent. Commercial API handling applies; output remains advisory.

Resend

Purpose
Transactional email, invitations, milestones, delivery notices, authentication messages, and contact notifications.
Data involved
Recipient email, message content, delivery metadata, and the minimum workflow context needed for the notice.
When used
Required for configured email delivery. Customer document attachments are not sent in routine transactional email.

Dodo Payments

Purpose
Merchant-of-record checkout, subscription management, invoices, taxes, refunds, and payment processing.
Data involved
Billing contact, selected plan, transaction and subscription identifiers, payment status, and card data collected directly by Dodo.
When used
Required for paid online subscriptions. Dodo may act as an independent controller for payment and legal obligations.

Sentry

Purpose
Application error monitoring and performance diagnostics.
Data involved
Scrubbed error, route, release, device, and performance context. Default PII capture is disabled.
When used
Deployment-dependent. Customer files, credentials, cookies, and private URLs are excluded by policy and scrubbers.

Google Analytics

Purpose
Aggregate public-site and product-action analytics.
Data involved
Page path, referral attribution, event completion, browser context, and web performance after consent.
When used
Optional and consent-based. Google signals and ad-personalization signals are disabled.

Changes and objections

We update this page before or when a material new processor begins handling Customer Personal Data, except for an urgent replacement needed to protect security or availability. Customers subject to the DPA may object on reasonable data-protection grounds within 15 days by using the privacy contact form. We will assess a practical alternative or the termination right described in the DPA.

Provider documentation

Provider privacy and security terms can change. Procurement teams can request the current contractual provider name, processing location, and transfer mechanism applicable to their proposed order. We will confirm facts in writing rather than infer data residency from a software default or provider marketing page.