ComplyBar logoComplyBar

Data Processing Agreement

GDPR Article 28 compliant DPA for ComplyBar customers.

Last updated: July 13, 2026

1. Definitions

In this Data Processing Agreement, the following terms have the meanings set forth below:

  • Controller means the individual or organization that determines the purposes and means of processing personal data. The customer is the Controller.
  • Processor means the individual or organization that processes personal data on behalf of the Controller. 30A Technologies, LLC, doing business as ComplyBar ("ComplyBar"), is the Processor.
  • Sub-Processor means an individual or organization engaged by the Processor to process personal data on behalf of the Controller.

2. Subject Matter and Duration

ComplyBar processes personal data on behalf of the customer for the purpose of delivering the ComplyBar SaaS service, specifically month-end accounting close management and task coordination.

Processing shall commence on the date the customer's organization account is created and shall continue until the customer's subscription is terminated. ComplyBar shall continue to process personal data only as necessary for 90 days following subscription termination for the purposes of secure deletion.

3. Nature and Purpose

ComplyBar processes accounting close data and task records necessary to deliver the SaaS service. Processing includes:

  • Storing and retrieving tasks, documents, and audit records in the customer's account.
  • Authenticating users and managing account access.
  • Providing aggregated, anonymized analytics to improve the ComplyBar service. ComplyBar does not use personal data for any commercial purpose beyond service improvement and does not sell personal data.

4. Categories of Data Subjects

The personal data processed relates to the following categories of data subjects:

  • Employees of the customer organization, specifically members of the accounting and finance team.
  • Any other individuals authorized by the customer to access the ComplyBar platform (e.g., auditors, external partners).

5. Types of Personal Data

ComplyBar processes the following categories of personal data:

  • Identity: Full name, work email address, phone number (optional).
  • Role and Organizational Data: Job title, department, role within ComplyBar (e.g., preparer, reviewer, controller).
  • Activity Records: Log-in timestamps, task assignments, task status changes, task comments, and document uploads.
  • Technical Data: IP address, browser type, operating system (collected for security and error logging purposes).

6. Processor Obligations

ComplyBar commits to the following obligations as a Processor under GDPR Article 28:

  • Process Only on Instructions: ComplyBar shall process personal data only on documented instructions from the Controller, unless required by applicable law.
  • Confidentiality: ComplyBar ensures that persons authorized to process personal data have committed to confidentiality and have received appropriate training.
  • Security Measures: ComplyBar implements technical and organizational security measures to protect personal data. See our Security page for details.
  • Sub-Processor Management: ComplyBar informs the Controller of all Sub-Processors and obtains prior written consent before engaging new Sub-Processors or changing existing ones.
  • Data Subject Rights Assistance: ComplyBar provides reasonable assistance to the Controller in responding to requests from data subjects exercising their GDPR rights (access, correction, deletion, etc.).
  • Deletion on Termination: ComplyBar deletes or returns personal data to the Controller within 90 days of subscription termination, as detailed in Section 10.
  • Audit Support: ComplyBar maintains audit logs and provides the Controller with access to audit reports or questionnaires upon request.

7. Sub-Processors

ComplyBar currently engages the following Sub-Processors to assist in delivering the service:

  • Supabase – Hosts the database and manages authentication and user sessions. Supabase is certified under SOC 2 Type II.
  • Vercel – Hosts the web application and provides CDN and deployment infrastructure. Vercel is SOC 2 Type II certified.
  • Stripe – Processes and stores billing and payment information. Stripe is PCI DSS compliant and handles payment card data.
  • Resend – Sends transactional emails (password resets, notifications, billing updates). Resend is GDPR compliant.
  • PostHog – Provides aggregated product analytics and feature usage data. PostHog processes data in a privacy-respecting manner and does not link data to personal identity without explicit consent.
  • Sentry – Captures error logs and performance metrics to monitor service stability. Sentry is GDPR compliant.

ComplyBar will notify the Controller of any changes to Sub-Processors at least 30 days in advance. If the Controller objects to a Sub-Processor change, the Controller may terminate the agreement without penalty.

8. Audit Rights

The Controller has the right to audit ComplyBar's compliance with this Agreement and applicable data protection laws:

  • Frequency: Audits may be conducted once per calendar year.
  • Form: ComplyBar will provide either an independent SOC 2 Type II audit report or a questionnaire-based audit, at ComplyBar's discretion.
  • Timeline: ComplyBar will respond to audit requests or questionnaires within 30 business days.
  • On-Site Audits: On-site audits require 60 days' notice and may include reasonable security precautions. All reasonable costs of on-site audits shall be borne by the Controller.

9. Deletion on Termination

Within 90 days of subscription termination, ComplyBar shall securely delete all personal data unless required by applicable law to retain it. At the Controller's written request, ComplyBar shall provide a certificate of deletion confirming that personal data has been destroyed.

The Controller may request a data export prior to termination to migrate data to another system or archive.

10. Contact

Questions regarding this Data Processing Agreement or data protection should be directed to privacy@complybar.com. We will respond within 5 business days.