Subprocessors & third-party suppliers
Last updated: 7 September 2026
Overview
Under Article 28 GDPR, Northdocs maintains this register of sub-processors that process personal data on our behalf to deliver the Service. This list is incorporated into our Data Processing Addendum as Schedule 1. For privacy questions see the Privacy Policy. Data Processing Addendum · Privacy Policy.
Identity uses Clerk. Self-serve checkout and invoices use Stripe (card numbers stay with Stripe). Transactional email (Scaleway TEM) is limited to recipient addresses and operational notification text. Uploaded documents, document filenames, extracted text, detections, and case contents are not sent through email.
Northdocs-engaged sub-processors
OVHcloud
- Purpose
- Hosting of the Northdocs application, API, databases, S3-compatible object storage, backups, and related compute in Frankfurt, Germany (OVHcloud). TLS terminates at the Northdocs edge inside that boundary, and the PDF/OCR engine runs on a private network with no outbound internet access. Optional Enterprise private connectors run over a self-hosted, open-source overlay network on the same OVH infrastructure (customer document traffic stays on the mesh Northdocs operates; no third-party VPN service is used).
- Personal data
- Account identifiers, uploaded documents and extracted text/detections, audit metadata, IP addresses in access logs
- Location
- Germany / European Union (Frankfurt, default data region eu-de)
- Transfer mechanism
- EU processing for application data under OVHcloud DPA / SCCs as applicable
Scaleway
- Purpose
- Transactional email delivery (Scaleway Transactional Email). Used for trial notices, support reply notifications, ops alerts, and Clerk authentication and invitation messages.
- Personal data
- Recipient email addresses; organization name on trial, welcome, and onboarding notices; given name and authentication codes or links on Clerk templates; operational identifiers (ticket id, feature-request id); optional feature-request titles the requester wrote. Uploaded documents, document filenames, extracted text, detections, case names, case file contents, and document attachments are not sent to Scaleway.
- Location
- European Union (France)
- Transfer mechanism
- EU processing under Scaleway DPA
- Notes
- Configured per environment via the Scaleway TEM API (SMTP relay as fallback). Clerk has no custom SMTP; staging/production templates set Delivered by Clerk off and the app sends email.created through TEM. Local development may use Mailpit or no-op sending when TEM/SMTP is unset. TEM messages do not include document filenames, extracted text, detections, or case contents.
Clerk, Inc.
- Purpose
- Authentication, organization/membership management, SSO/SAML (Enterprise), and session management.
- Personal data
- Name, email, organization membership and roles, authentication events, and plan metadata needed to sign users in
- Location
- United States / EU (Clerk infrastructure)
- Transfer mechanism
- Standard Contractual Clauses (SCCs) and Clerk DPA
Stripe, Inc.
- Purpose
- Payment processing for self-serve subscriptions: Checkout, invoices, tax handling where configured, and the customer billing portal. Enterprise invoice licensing may be administered without Stripe Checkout.
- Personal data
- Name, email, organization billing references, subscription amounts and plan, and payment-method tokens. Card numbers are handled by Stripe and are not stored by Northdocs. Customer documents, detections, and case contents are not sent to Stripe.
- Location
- United States / European Union (Stripe infrastructure)
- Transfer mechanism
- Standard Contractual Clauses (SCCs) and Stripe DPA
OVHcloud
- Purpose
- Optional AI assistance when enabled for the organization: semantic named-entity recognition (NER), Magic Redact filters, identity attribute linking, case cover summaries, Prompt Guard name detection, Outbound Guard person and organization names, Conversation Redact speech-to-text for audio without a caption sidecar, and deterministic rule suggestions from sample text. Inference uses OVHcloud AI Endpoints (OpenAI-compatible) from the EU-hosted application.
- Personal data
- Page text, detection values (for example names, contact details, and identifiers), case metadata (names and redaction category counts), optional sample text for rule lint, Outlook compose snippets when cloud scan and AI names are enabled, and audio for speech-to-text when Conversation Redact transcribes a recording without captions. Only when AI / ML detection is enabled for the organization.
- Location
- European Union (OVHcloud AI Endpoints)
- Transfer mechanism
- EU processing under the OVHcloud DPA. Northdocs calls OVHcloud AI Endpoints over HTTPS from the EU-hosted application. Staging and production customer inference does not use OpenAI or Mistral.
- Notes
- Production AI provider. Organization administrators can disable AI / ML detection under Settings → Organization. When AI is disabled, detection uses on-platform pattern and rule engines only; document content and detection text are not sent to any AI provider (including identity linking, cover summaries, Magic validation, Prompt Guard names, Outbound Guard names, and rule suggestions). Conversation Redact speech-to-text is also off in that posture: upload a WebVTT or SubRip sidecar with the recording. See the public Enterprise AI Policy (https://northdocs.com/ai-policy) and Architecture (https://northdocs.com/architecture). Additional security questionnaire materials are available on request from legal@northdocs.com or sales@northdocs.com.
Customer-configured integrations
The following vendors are available as optional connectors. They process data only when you authorize a connection and select content. They are engaged under your instructions and vendor agreements, not as default Northdocs sub-processors.
Optional DMS import/export when the customer authorizes a Microsoft connector. When Outbound Guard is deployed, the Outlook add-in also runs in the customer's Microsoft 365 tenant (compose snippets may be sent to the EU app for cloud scan; mail bodies are not stored).
Location: As configured in the customer's Microsoft tenant. Vendor site (opens in a new tab)
Optional Enterprise Azure Key Vault BYOK: customer CMK wraps the Northdocs organization encryption key via wrapKey/unwrapKey when the customer activates BYOK.
Location: As configured in the customer's Azure subscription (EU vault regions recommended). Vendor site (opens in a new tab)
Optional DMS connector for law-firm document libraries.
Location: As configured by the customer / iManage cloud or on-prem. Vendor site (opens in a new tab)
Optional matter workspace / collaboration connector.
Location: As configured by the customer. Vendor site (opens in a new tab)
Optional virtual data room (VDR) import/export for diligence workflows.
Location: As configured by the customer / Datasite. Vendor site (opens in a new tab)
Change policy
Northdocs will publish updates to this list before authorizing a new subprocessor to process Customer Personal Data (other than emergency replacements needed to maintain security or continuity). Customers may subscribe to notices by emailing legal@northdocs.com with subject “Subprocessor notices”. If a customer reasonably objects to a new subprocessor on documented data-protection grounds within 30 days of notice, the parties will discuss alternatives in good faith; if no resolution is reached, the customer may terminate the affected services as its sole remedy.
To request the current list as a PDF attachment for your vendor file, email legal@northdocs.com.