cComplyEU

Data Processing Agreement

Last updated: 30 May 2026

This Data Processing Agreement (“DPA”) is incorporated by reference into the Terms of Service between ComplyEU (“Processor”) and the customer organisation (“Controller”). It applies to all processing of personal data by ComplyEU on behalf of the Controller and is intended to satisfy Article 28 GDPR.

1. Definitions

Terms have the meaning given in the GDPR. “Customer Data” means personal data the Controller, its users, or its connected workspaces submit to the Service.

2. Subject matter and duration

ComplyEU processes Customer Data to provide the Service as described in the Terms, for the duration of the Controller's subscription and any post-termination data-export window, after which Customer Data is deleted.

3. Nature and purpose of processing

Storage, classification, policy generation, analytics, and reporting, performed to help the Controller meet obligations under the EU AI Act, NIS2, and related law.

4. Categories of data subjects and personal data

  • Data subjects: employees, contractors, and administrators of the Controller.
  • Personal data: name, email, role, profile picture, OAuth identifiers, audit-log entries, IP address, browser metadata.

The Service is not designed to process special-category data under Article 9 GDPR. The Controller agrees not to submit such data.

5. Obligations of the Processor

ComplyEU shall:

  • process Customer Data only on the documented instructions of the Controller;
  • ensure that persons authorised to process Customer Data are bound by confidentiality;
  • implement appropriate technical and organisational measures (Annex II);
  • assist the Controller in fulfilling data-subject requests and in DPIAs;
  • notify the Controller without undue delay (and within 72 hours) of any personal data breach;
  • delete or return Customer Data at the end of the engagement, except where retention is required by law.

6. Sub-processors

The Controller authorises ComplyEU to engage the sub-processors listed at /trust. ComplyEU will notify the Controller by email at least 14 days before adding or replacing a sub-processor; the Controller may object on reasonable grounds.

7. International transfers

ComplyEU stores Customer Data in the European Union (Frankfurt region). Where a sub-processor is located outside the EEA, the parties rely on the European Commission's Standard Contractual Clauses (2021/914) and supplementary measures.

8. Audit

ComplyEU will make available all information reasonably necessary to demonstrate compliance with Article 28 GDPR and will allow for audits, conducted by the Controller or a mandated auditor, on reasonable prior notice and at the Controller's cost, subject to confidentiality undertakings.

9. Annex I — Description of processing

As described in Sections 3–4 above.

10. Annex II — Technical and organisational measures

  • Transport encryption: TLS 1.3 only.
  • At-rest encryption: AES-256-GCM for OAuth tokens and credentials; full-disk encryption on production database.
  • Access control: role-based access; least-privilege; admin actions audit-logged.
  • Authentication: Argon2id for password hashing; JWT session tokens with 7-day rotation.
  • Network: backend behind TLS termination; CORS pinned to allowed origins.
  • Backups: daily automated database backups, 30-day retention, encrypted.
  • Logging: centralised structured logs; immutable audit trail of admin and authentication events; 24-month retention.
  • Incident response: 72-hour breach notification commitment.
  • Personnel: confidentiality obligations; access on a need-to-know basis.
  • Vendor due diligence: sub-processors reviewed before onboarding.

11. Contact

To exercise rights under this DPA, contact [email protected].