GDPR Article 28 Processor Summary

Last updated: 22/01/2026

1. Parties

This summary describes the data processing activities performed by ComplySafe.io as a data processor on behalf of its customers, who act as data controllers under the EU General Data Protection Regulation.

2. Role of ComplySafe.io

ComplySafe.io acts solely as a data processor and processes personal data only on documented instructions from the customer for the purpose of providing compliance scanning services.

3. Categories of Data

  • Account information such as name and email address
  • Website URLs and publicly accessible content
  • Repository metadata and files provided via integrations
  • Scan results, reports, and compliance findings

4. Purpose of Processing

Personal data is processed exclusively to perform automated compliance analysis, generate reports, and provide related service functionality requested by the customer.

5. Data Retention

Scan data and reports are retained for a limited period as defined in the Privacy Policy or until deletion is requested by the customer, unless legal obligations require longer retention.

6. Subprocessors

ComplySafe.io uses vetted subprocessors for infrastructure and payment processing, including cloud hosting and billing providers. A current list is available upon request.

7. Security Measures

  • Encryption of data in transit and at rest
  • Strict access controls and authentication
  • Regular security updates and monitoring
  • Segregation of customer data

8. Confidentiality

All personnel with access to personal data are bound by confidentiality obligations and receive appropriate data protection training.

9. Data Subject Rights

ComplySafe.io assists customers in fulfilling data subject rights requests, including access, deletion, and rectification, as required by GDPR.

10. No AI Training on Customer Data

Customer data is never used to train machine learning or AI models. Processing is limited strictly to delivering the requested service.

11. Jurisdiction

ComplySafe.io is registered in Estonia and processes personal data in accordance with EU GDPR requirements.

12. Contact

For questions regarding data processing or to request a full Data Processing Agreement, contact:

Email: contact@complysafe.io

ComplySafe.io - Automated Compliance Scanning