The providers involved in delivering CommsPliant.

CommsPliant keeps a clear record of the third parties that may process client data as part of the service. We review relevant providers for privacy, security, contractual and international-transfer considerations and maintain a client-facing subprocessor list.

Subprocessor Position

DigitalOcean

Purpose
Production infrastructure and hosting
Location
London LON1, United Kingdom
Current

DigitalOcean provides the infrastructure used to host the core CommsPliant production environment.

Amazon Web Services / Amazon SES

Purpose
Transactional email delivery, where selected and enabled
Location
Production region confirmed before live client processing
Planned for production use where selected and enabled

Amazon SES is the intended production email provider for CommsPliant transactional email functionality. Before any live client processing through Amazon SES, the production region, contractual position and international-transfer details are confirmed.

What is not outsourced

Core editor and document generation

The core CommsPliant document editor and generation technology are developed and operated in-house. Client templates and generated communications are not sent to an external document-rendering SaaS provider as part of the core generation process.

In-house

How subprocessors are managed

Relevant providers are reviewed proportionately before they are used for live client processing.

The review considers:

  • what service the provider performs;
  • whether client personal data is processed;
  • where relevant processing takes place;
  • security and contractual safeguards;
  • international-transfer considerations where applicable;
  • whether the provider needs to appear on the client-facing Subprocessor List.

The list is updated when a relevant provider or processing arrangement changes.

Documented and operating

Client transparency

Clients can request the current Subprocessor List during procurement, onboarding or due-diligence review.

Where a service is optional, only the providers relevant to the client's configured service need to apply.

Request current Subprocessor List

FAQ

Still have questions?

If you need more detail about providers, processing locations or subprocessor arrangements, contact us and we'll help.

Request more information

Supporting Records

Resource Availability Action
Supplier Management Policy Controlled · On request Request access
Subprocessor and International Transfer Register Controlled · On request Request access
Client-facing Subprocessor List v1.0 On request / Client onboarding Request access
Data Processing Agreement v1.1 Client onboarding Request access
Security and Privacy Risk Register Controlled · On request Request access

A request does not automatically mean that a full internal record will be provided. Where appropriate, CommsPliant may provide a client-facing version, extract, summary or other controlled evidence instead.