DOCSUPRA Open the Enterprise Studio

DOCSUPRATrust center › Sub-processors

Sub-processors · reviewed 18 September 2026

Who touches which data.

No sub-processor ever receives document content: documents are corrected on your own device and are never sent to us. These are the companies that process personal data on DocVerifyPro’s behalf, what each one receives and why.

Sub-processorPurposeData receivedLocation
Stripe, Inc.Payment processing, invoices, subscription managementBilling details, email, plan, amount; card data entered directly into Stripe’s own formUnited States
Cloudflare, Inc.Hosting of the application, licence API, KV storage of licence and seat records, edge logs, cookie-free page-view counter, inbound email routingConnection data (IP, time, path, user agent); a daily-salted hash of the IP for abuse limits; licence tokens and seat identifiers; email sent to our support and security addressesGlobal edge; United States
Cloudflare, Inc. (Workers AI)Drafting first replies to support email and answering the on-site assistantThe text of the email or question you send — never a documentGlobal edge; United States
Google LLC (Gmail)The support inbox: email sent to our addresses is forwarded thereThe email you send usUnited States
Resend, Inc.Operator alert emails when the licence service errors; sign-in links and invitations for Team and Studio membersRoute, error message and stack trace of a server error — never a document, token or customer email. For sign-in emails: the recipient address and the one-time linkUnited States

What is deliberately absent

Change notice

Before adding or replacing a sub-processor we email the billing contact of every Professional Team and Corporate Studio subscription at least 30 days ahead, naming the company, purpose and data involved. A customer who objects on reasonable data-protection grounds may terminate the affected subscription at the end of the current paid period; no further charge is taken.

Verification

The hosts the application is allowed to contact are enforced by its Content Security Policy and listed on the security page. Any host not on that list is blocked by your own browser.