Opencomplai

Trust

Trust

Plain facts about where data goes, who processes it, and how to get it out or have it removed.

Data flow

SetupWhat happens to your data
CLI on its ownNothing leaves your environment. The CLI runs in your CI or on your machine.
CLI connected to the hosted serviceA closed list of metadata fields, documented in the docs. No source code. The hosted service accepts a push only with a project API key.
Hosted serviceHosted on Vercel in Frankfurt, data stored on Neon in Frankfurt, and transactional email sent through Brevo in the EU.

Sub-processors

NameServiceLocation
VercelHosting of the web application and APIs, including the ingestion APIFrankfurt, Germany (fra1 region); requests pass through Vercel's global edge network
NeonManaged Postgres database that stores Service dataFrankfurt, Germany (AWS eu-central-1)
BrevoTransactional email: sign-in links, invitations, welcome emails and support-ticket notificationsEuropean Union

Changes are published in two places: the sub-processor change feed and the email notice described in the DPA. The full list is in DPA Annex 3, and the notice terms are in section 6 of the DPA.

Deletion and export

  • Export. An organisation admin can download an export of the organisation's data as a zip file: one NDJSON file per tenant table plus a manifest.
  • Close. An organisation admin can close the organisation. API keys stop working at once and ingest answers 401. A platform operator can restore a closed organisation.
  • Purge. A platform operator purges a closed organisation after a typed confirmation, which deletes the organisation's rows. The 30-day purge due date shown to operators is informational: no purge runs on a schedule.
  • Audit records. Audit records are kept after a purge. They are append-only and carry the organisation id and the operator's typed reason, not names or emails.
  • User erasure and retention. User erasure and a retention purge are run by an operator on request, dry run first.

To request any of these, write to hello@opencomplai.com.

Security contact

Report a vulnerability as described in our security.txt. Our general security practices are on the security page.

Support

What to expect from support is on the support policy page.

Contact