ROPAi is a compliance tool. We treat the controls on our own platform the way we expect you to treat yours: documented, evidenced, reviewable.
The shortest version of our security and trust posture. Each item is explained in detail below.
ROPAi is a single-file web application backed by managed EU infrastructure. We have deliberately chosen a small, audited set of providers.
We distinguish between the assurances held by our infrastructure providers and the certifications held by ROPAi itself. We do not present a provider's certification as if it were our own.
Complete list of third parties that may process customer personal data on our behalf. We will notify customers of any material change at least 30 days before it takes effect.
| Sub-processor | Purpose | Data location | Status |
|---|---|---|---|
| Supabase Inc. Database, auth, storage |
Primary data store for ROPA entries, DSAR cases, DPIA records, audit trail, organisation membership. | Ireland (EU) | Core |
| Netlify, Inc. Web hosting & serverless |
Static site delivery and Netlify Functions for Stripe verification, billing portal, and AI intake routing. | EU region (edge) + US origin failover | Core |
| Anthropic, PBC Claude LLM API |
AI-generated ROPA drafting, DPIA screening suggestions, and DSAR classification. Prompts are server-side only. | United States (with SCCs & UK addendum) | Core |
| Stripe Payments Europe Ltd. Billing & payments |
Subscription billing, checkout, and self-service customer portal. Card details handled by Stripe only. | Ireland (EU) | Core |
| Resend (Plus Five Five, Inc.) Transactional email |
Delivers DSAR colleague-query notifications. The email carries no subject personal data, only a recipient address and a secure link. The recipient's email address is the only personal data processed. | United States (with SCCs & UK addendum) | Core |
The controls we have in place today. We will publish our first independent audit on the roadmap below.
deleted_at timestamp. Changes are written to an activity log for audit reconstruction.AI is useful for privacy teams only if you can defend how it processes your data. This is the posture.
The commitment we make to you as a controller.
ROPAi is a processor for the customer data you upload to us. For your account data (your name, email, organisation), ROPAi Ltd is the controller. You can exercise your UK GDPR rights by emailing [email protected].
We provide a Data Processing Agreement to every paying customer on request. Click below and we will send you the current template within one business day.