Data protection

Subprocessors

This page describes the subprocessor categories MatchAudit may use to provide, secure, maintain, and support the service. Named vendor details can be provided through procurement or legal review where appropriate.

Effective date: May 2, 2026

CategoryPurposeProcessing locations
Cloud hosting and databaseHosting, database, storage, logs, and platform operationEU/EEA and other locations depending on provider configuration
AuthenticationUser authentication, account sessions, and security controlsEU/EEA and other locations depending on provider configuration
Payment processingCheckout, subscription administration, invoices, and payment statusEU/EEA, UK, US, and other locations covered by transfer safeguards
Email and support toolingTransactional email, support requests, and customer communicationsEU/EEA, UK, US, and other locations covered by transfer safeguards
AI processing where enabledKYC extraction, reviewer assistance, and documentation draftingProvider-controlled processing locations covered by transfer safeguards

Transfer safeguards

Where personal data is transferred outside the EEA, MatchAudit uses appropriate transfer mechanisms where required, such as adequacy decisions, standard contractual clauses, or equivalent safeguards.

Customers may object to a materially new subprocessor on documented data-protection grounds as described in the Data Processing Addendum.