Preparing your workspace
Preparing your workspace
Last updated: July 2026
This page lists the third-party sub-processors SimpleAudit™ engages to process personal data on behalf of our customers and partners. It is the authoritative, always-current version of the sub-processor list referenced in our Privacy Policy and our Data Processing Agreement. Each sub-processor processes data only as necessary to provide its service.
| Provider | Purpose | Data Processed | Location |
|---|---|---|---|
| Clerk | Authentication, user management, billing; webhook delivery via its subprocessor Svix | Name, email, session tokens, payment info | United States |
| Microsoft Corporation (Azure) | Cloud hosting, database, file storage, transactional email, AI services, security scanning, telemetry — see "Microsoft Azure service detail" below | All application data (encrypted at rest and in transit), including uploaded evidence files, email content, compliance data context for AI processing, and pseudonymous telemetry | United States (East US 2, with geo-redundant replication and backups to the paired region, Central US); some AI processing may occur outside the United States |
| Stripe | Payment processing (via Clerk Billing) | Billing address, payment method, transaction history | United States |
| Google LLC | Website analytics and advertising conversion tracking (both consent-required) | Page views, device info, IP address (anonymized), conversion events, hashed email, advertising identifiers | United States / global |
| Cloudflare | Bot protection (Turnstile) on sign-up and video hosting (Stream) | Visitor IP addresses | Global (US + edge network) |
| Svix (via Clerk) | Webhook delivery | Webhook event payloads (may include user email addresses) | United States |
All Microsoft services below operate under the same Microsoft Products and Services Data Protection Addendum and within the same Azure trust boundary. Within Microsoft Azure, SimpleAudit uses:
Our AI features run through Microsoft Azure AI Foundry, which hosts the OpenAI and Anthropic models we use. Microsoft acts as the data processor: prompts and outputs are processed within Microsoft's Azure environment, are not shared with the model providers, and are not used to train any models. For the governing terms, see Microsoft's Azure AI Foundry data-privacy documentation and the Microsoft Products and Services Data Protection Addendum.
We provide at least 30 days’ advance notice of any new or replacement sub-processor, during which customers and partners may object on reasonable data-protection grounds (30-day objection window). To request notification when this list changes, contact privacy@simpleaudit.io.
This change history is maintained by SimpleAudit and is not part of the counsel-supplied document above. We publish each sub-processor change here at least 30 days before it takes effect. To be notified directly when this list changes, contact privacy@simpleaudit.io.
Notice given 2026-07-26
Consolidated the published table from 13 per-service rows to 6 entity-level rows (Clerk, Microsoft Corporation (Azure), Stripe, Google LLC, Cloudflare, Svix), with per-service detail moved to a new Microsoft Azure service detail section below the table. No sub-processor entity was added, removed, or replaced; every purpose, data category, and location was carried over. No advance notice is owed: the published commitment covers new or replacement sub-processors only.
Notice given 2026-07-25
Baseline of the published sub-processor list at the date this change history began. No notice is owed for the baseline: it records the roster that was already published, not a change to it. Sub-processor changes made before this date are not backfilled here.