Preparing your workspace
Preparing your workspace
Last updated: July 2026
This page lists the third-party sub-processors SimpleAudit™ engages to process personal data on behalf of our customers and partners. It is the authoritative, always-current version of the sub-processor list referenced in our Privacy Policy and our Data Processing Agreement. Each sub-processor processes data only as necessary to provide its service.
| Provider | Purpose | Data Processed | Location |
|---|---|---|---|
| Clerk | Authentication, user management, billing; webhook delivery via its subprocessor Svix | Name, email, session tokens, payment info | United States |
| Microsoft Corporation (Azure) | Cloud hosting, database, file storage, transactional email, AI services, security scanning, telemetry — see "Microsoft Azure service detail" below | All application data (encrypted at rest and in transit), including uploaded evidence files, email content, compliance data context for AI processing, and pseudonymous telemetry | United States (East US 2, with geo-redundant replication and backups to the paired region, Central US); AI processing runs on Azure US Data Zone deployments within the United States |
| Stripe | Payment processing (via Clerk Billing) | Billing address, payment method, transaction history | United States |
| Google LLC | Website analytics and advertising conversion tracking (both consent-required) | Page views, device info, IP address (anonymized), conversion events, hashed email, advertising identifiers | United States / global |
| Cloudflare | Bot protection (Turnstile) on sign-up and video hosting (Stream) | Visitor IP addresses | Global (US + edge network) |
| Svix (via Clerk) | Webhook delivery | Webhook event payloads (may include user email addresses) | United States |
All Microsoft services below operate under the same Microsoft Products and Services Data Protection Addendum and within the same Azure trust boundary. Within Microsoft Azure, SimpleAudit uses:
Our AI features run through Microsoft Azure AI Foundry, which hosts the OpenAI and Anthropic models we use, on Azure “Data Zone Standard (US)” deployments (applicable to both the primary and the fallback models). Microsoft acts as the data processor: prompts and outputs are processed within the United States, are not shared with the model providers, and are not used to train any models. For the governing terms, see Microsoft's Azure AI Foundry data-privacy documentation and the Microsoft Products and Services Data Protection Addendum.
We provide at least 30 days’ advance notice of any new or replacement sub-processor, during which customers and partners may object on reasonable data-protection grounds (30-day objection window). To request notification when this list changes, contact privacy@simpleaudit.io.
This change history is maintained by SimpleAudit and is not part of the counsel-supplied document above. We publish each sub-processor change here at least 30 days before it takes effect. To be notified directly when this list changes, contact privacy@simpleaudit.io.
Notice given 2026-08-08
Wording correction to the Microsoft Corporation (Azure) row's Location cell and the Azure AI Foundry service-detail prose: AI processing now runs on Azure Data Zone Standard (US) deployments within the United States (previously disclosed as possibly occurring outside the US). No sub-processor entity was added, removed, or replaced; storage locations unchanged. No advance notice is owed: the published commitment covers new or replacement sub-processors only.
Notice given 2026-07-26
Consolidated the published table from 13 per-service rows to 6 entity-level rows (Clerk, Microsoft Corporation (Azure), Stripe, Google LLC, Cloudflare, Svix), with per-service detail moved to a new Microsoft Azure service detail section below the table. No sub-processor entity was added, removed, or replaced; every purpose, data category, and location was carried over. No advance notice is owed: the published commitment covers new or replacement sub-processors only.
Direct notice sent 2026-07-26 to 0 requesters (email (BCC) per docs/runbooks/subprocessor-change-notification.md - requester registry was empty, so no direct-notice recipients existed. Updated-only change; no advance notice owed. Zero-recipient discharge recorded 2026-08-08 per founder decision.).
Notice given 2026-07-25
Baseline of the published sub-processor list at the date this change history began. No notice is owed for the baseline: it records the roster that was already published, not a change to it. Sub-processor changes made before this date are not backfilled here.