Comtech Solutions Limited
Corbiere platform terms and conditions
v2.0, 5 September 2026
1.These Terms and who we are
1.1These Terms and Conditions (the “Terms”) govern access to and use of Corbiere, a data subject access request management platform (the “Platform”) operated by Comtech Solutions Limited, a company incorporated in Jersey under the Companies (Jersey) Law 1991 with registered number 101874 and registered office at 9 Hope Street, St Helier, Jersey (“Comtech”, “we”, “us”).
1.2The Platform is provided to business customers only. By creating an organisation account, accepting an invitation issued under an organisation account, or otherwise using the Platform, the organisation on whose behalf the account is operated (the “Customer”) agrees to these Terms. The individual accepting these Terms warrants that they have authority to bind the Customer. The Platform is not offered to consumers, and nothing in these Terms grants rights to any individual acting outside a business, professional or public function.
1.3These Terms comprise the main body (clauses 1 to 17), the Data Processing Terms at Schedule 1, the Processing Particulars at Schedule 2 and the Approved Sub-processors list at Schedule 3 (together, the “Agreement”). If there is a conflict, Schedule 1 prevails over the main body in respect of the Processing of Case Content, and the main body prevails otherwise.
2.Definitions
2.1In this Agreement: “Account Data” means personal data relating to the Customer’s Users and billing contacts that Comtech processes as controller, as described in the Corbiere Privacy Notice; “AI Feature” means the optional artificial-intelligence assistance feature described in clause 6; “Case” means a data subject request record created in the Platform by or for the Customer; “Case Allowance” means the maximum number of Cases that may be created under the Customer’s Plan in the relevant Plan Year, as stated on the Platform’s pricing page or in the applicable order; “Case Credit” means a credit entitling the Customer to create one additional Case, purchased under clause 7.3 or as a Single Case Purchase; “Case Content” means the content of Cases, including requester details, identity documents, uploaded evidence, review decisions, redactions, correspondence and disclosure bundles; “Data Protection Law” means the Data Protection (Jersey) Law 2018 (“DPJL 2018”) and, to the extent applicable to the Processing concerned, the Data Protection (Bailiwick of Guernsey) Law, 2017, the UK GDPR and Data Protection Act 2018, and the EU GDPR, in each case as amended; “Fees” means the subscription and any other charges for the Platform; “Plan” means the subscription tier selected by the Customer, which determines the features, Case Allowance, number of permitted Users and other limits applicable to the Customer’s use of the Platform; “Plan Year” means each successive period of 12 months from the date the Customer’s subscription commences (or its anniversary), to which the Case Allowance applies regardless of whether Fees are billed monthly or annually; “Single Case Purchase” means a one-time purchase of a single Case Credit without a subscription, as described in clause 7.6; “Processing”, “controller”, “processor”, “personal data”, “data subject” and “personal data breach” have the meanings given in the DPJL 2018; “Users” means the individuals the Customer authorises to access its organisation account.
3.The Platform and licence
3.1Subject to payment of the Fees and compliance with this Agreement, Comtech grants the Customer a non-exclusive, non-transferable right for its Users to access and use the Platform during the Term, within the features, Case Allowance and other limits of the Customer’s Plan, for the purpose of managing data subject requests in the course of the Customer’s business, including where the Customer is a professional adviser managing requests on behalf of its own clients.
3.2Comtech will provide the Platform with reasonable skill and care and will use reasonable endeavours to make it available continuously, save for planned maintenance and circumstances beyond Comtech’s reasonable control. The Platform is provided on a software-as-a-service basis; Comtech may improve or modify features from time to time provided the core functionality of the Platform is not materially reduced during a paid subscription period.
3.3The Customer acknowledges that the Platform is a tool that supports the Customer’s own compliance processes. Comtech does not provide legal advice, and use of the Platform does not of itself discharge the Customer’s obligations under Data Protection Law, including its duty to respond to data subject requests within the statutory period.
4.Accounts, Users and security obligations of the Customer
4.1The Customer is responsible for its Users, for maintaining the accuracy of its account information, and for all activity under its organisation account. The Customer shall not exceed the number of Users permitted by its Plan and shall ensure that each User keeps their credentials confidential, completes the sign-in verification steps required by the Platform, and does not share accounts, including to circumvent Plan User limits.
4.2The Customer shall promptly disable Users who no longer require access, using the administrative functions provided, and shall notify Comtech without undue delay at dpo@comtech-solutions.co.uk if it suspects unauthorised access to its account.
4.3The Customer shall not, and shall ensure its Users do not: use the Platform for any unlawful purpose; upload material that infringes third-party rights or contains malicious code; attempt to access another organisation’s data or circumvent the Platform’s tenant isolation, authentication or other security controls; resell or provide access to the Platform to third parties except to its own clients’ matters as contemplated by clause 3.1; or use the Platform to store data not reasonably related to the management of data subject requests.
5.Roles of the parties for personal data
5.1The parties acknowledge that, in respect of Case Content, the Customer (or, where the Customer is a professional adviser acting for a client, that client) is the controller, and Comtech is a processor acting on the Customer’s documented instructions. Schedule 1 applies to that Processing and is entered into pursuant to Article 19(2) of the DPJL 2018.
5.2Where the Customer uses the Platform on behalf of a client, the Customer warrants that it is authorised by the relevant controller to instruct Comtech in respect of the Processing of that controller’s Case Content, and the Customer shall be responsible to Comtech for the acts and omissions of that controller as if they were its own.
5.3In respect of Account Data, Comtech is an independent controller and shall process such data in accordance with Data Protection Law and the Corbiere Privacy Notice. Nothing in Schedule 1 applies to Account Data.
5.4Each party shall comply with Data Protection Law in respect of its own obligations arising from this Agreement. The Customer is solely responsible for the lawfulness of the Case Content it processes on the Platform, including establishing a lawful basis, providing transparency information to data subjects, verifying requester identity decisions, applying exemptions, and setting and operating retention periods for Case Content. The Customer acknowledges that the Platform provides deletion functions but does not apply an automatic retention schedule to Case Content.
6.AI Feature
6.1The AI Feature is disabled by default and operates only where the Customer’s administrator expressly enables it for the Customer’s organisation. Where it is not enabled, no Case Content is transmitted to any artificial-intelligence provider. The Customer may also disable the AI Feature for any individual Case, with a reason recorded in the audit trail, whatever the organisation-level setting says.
6.2Where the AI Feature is enabled, the Customer’s administrator selects one of four model-and-region configurations offered by the Platform: Claude Sonnet 4.5 on Amazon Bedrock in the EU (Ireland), provided by Amazon Web Services EMEA SARL; Claude Sonnet 4.5 on the direct Anthropic API, provided by Anthropic, PBC and processed in the United States; or GPT-4.1 on the Azure OpenAI Service in UK South or EU (Sweden Central), provided by the Microsoft contracting entity on the Customer’s Azure agreement. Anthropic does not offer a European or United Kingdom regional endpoint for Claude, and Comtech makes no representation that it does. No other configuration is reachable from the Platform. Comtech shall send AI requests only to the configuration so selected and shall not route them to another provider or region for capacity, failover or load balancing. The residency, subprocessor, transfer, retention and onward-transfer position for each configuration is set out in the AI data residency and subprocessor policy published at corbiere-data.com/ai-residency, which forms part of this Agreement.
6.3Only the passage or document the User is working on, together with the instruction for the relevant feature, is transmitted through Comtech’s server-side proxy to the selected provider as a sub-processor. Whole Case files are not uploaded to the provider, vault credentials are never transmitted, and material marked out of scope is excluded. No broker, router, evaluation, benchmarking or analytics service receives prompts or responses, and under the Azure configurations OpenAI receives no data because the model runs within Microsoft’s own tenancy.
6.4Retention by the AI provider differs by configuration and is not zero in every case. Under the Amazon Bedrock configuration, prompts and outputs are not stored after the response is returned and Bedrock model invocation logging is not enabled. Under the direct Anthropic configuration, inputs and outputs are deleted within 30 days by default; zero data retention is a separate agreement between the Customer and Anthropic, is available only for eligible products, and is subject to Anthropic’s own carve-outs, including retention of prompts and outputs for certain covered models and longer retention of content flagged by trust and safety processes. Under the Azure configurations, prompts and generated content are stored for up to 30 days for abuse monitoring and flagged content may be reviewed by authorised Microsoft staff, unless Microsoft has approved modified abuse monitoring for the resource. Under no configuration is submitted data used to train a model. The Platform does not store AI prompts or responses; it records only usage metadata (model, region, User, organisation and timestamp) for metering and accountability, retained for 24 months.
6.5AI-generated output is suggestive only. The Customer shall ensure that a human reviewer assesses any AI output before it influences a decision about a data subject and acknowledges that responsibility for decisions on Cases rests entirely with the Customer. Enabling the AI Feature, and selecting a configuration, constitutes the Customer’s documented instruction to engage the provider named against that configuration as a sub-processor for its organisation. The Customer remains responsible for satisfying itself that the region it selects is lawful for its own transfers under the Data Protection Law applicable to it, and for recording that assessment.
6.6Each change of model or region is available only to an administrator and is written to the audit trail with the person, time, previous value and new value. Comtech shall give notice of any change to the list of available configurations in accordance with paragraph 7 of Schedule 1.
6.7The AI Feature is subject to fair-use limits to protect the integrity and cost of the service, currently a rate limit of 5 requests per minute per organisation and a default cap of 25 requests per User per day, or such other limits as are stated for the Customer’s Plan. Comtech may vary these limits on reasonable notice and may throttle or temporarily suspend the AI Feature where usage materially exceeds them or degrades the service for other customers. Exceeding a fair-use limit pauses the AI Feature until the limit resets; it does not affect access to the rest of the Platform.
7.Fees and payment
7.1Fees are determined by the Customer’s Plan and are as set out in the applicable order or the Platform’s pricing page at the point of subscription or renewal, are stated in pounds sterling, are exclusive of GST or other applicable taxes, and are payable in advance (monthly or annually, as selected) by the payment methods supported by the Platform. Payments are processed by Stripe; Comtech does not receive or store card numbers.
7.2Each Plan includes a Case Allowance for each Plan Year and a maximum number of Users, each as stated on the pricing page. The Case Allowance applies per Plan Year even where Fees are billed monthly. Unused Case Allowance and unused Case Credits do not roll over into a subsequent Plan Year. Case Credits purchased under clause 7.3 remain valid for 6 months from purchase. Comtech shall not delete or suspend access to existing Cases, or to export functions, by reason only of a Case Allowance being exhausted or a Plan’s User limit being reached.
7.3When the Customer’s Case Allowance for a Plan Year is exhausted, the Customer may create further Cases by purchasing additional Case Credits at the per-case rate applicable to its Plan as stated on the pricing page, or by upgrading its Plan. Case Credit purchases are payable at the point of purchase.
7.4The Customer may upgrade its Plan at any time, with the change taking effect immediately and the subscription Fees prorated for the remainder of the current billing period. Downgrades take effect from the start of the next billing period, and the Customer is responsible for ensuring its usage, including its number of active Users, fits within the lower Plan’s limits from that date.
7.5Subscriptions renew automatically for successive billing periods unless cancelled before renewal. Except where this Agreement expressly provides for a refund (including paragraph 7 of Schedule 1 and clause 14.1), Fees and Case Credits are non-refundable and cancellation takes effect from the end of the current billing period, during which the Platform remains available.
7.6A Single Case Purchase provides one Case Credit and access to the Platform for the management of that Case only, without a subscription and without automatic renewal. Access under a Single Case Purchase continues until the earlier of the closure of the Case and 12 months from purchase, followed by the export wind-down period in clause 13.4. These Terms, including Schedule 1, apply to a Single Case Purchase as if references to the Term were to that access period, and clause 7.5 (non-refundability) applies from the point the Case is created.
7.7Comtech may revise Fees, Case Credit rates or Plan limits on not less than 30 days’ notice, taking effect from the next renewal (or, for Case Credit rates, for purchases made after the notice period). If undisputed Fees remain unpaid 21 days after they fall due, Comtech may suspend access on 7 days’ further notice until payment is made.
8.Intellectual property
8.1Comtech and its licensors own all intellectual property rights in the Platform. No rights are granted to the Customer other than the right of use in clause 3.1.
8.2The Customer and its clients retain all rights in Case Content. The Customer grants Comtech a non-exclusive licence to host, transmit, display and otherwise process Case Content solely as necessary to provide the Platform in accordance with this Agreement.
8.3Comtech may use aggregated, anonymised usage statistics that do not identify any individual, the Customer or any Case for the purpose of operating and improving the Platform. For the avoidance of doubt, Comtech shall not use Case Content to develop or train artificial-intelligence models.
9.Confidentiality
9.1Each party shall keep confidential all non-public information received from the other in connection with this Agreement, use it only to perform this Agreement, and disclose it only to personnel and advisers who need it and are bound by duties of confidence, or where disclosure is required by law or a competent authority. This clause survives termination for 5 years, and indefinitely for Case Content.
10.Security
10.1Comtech shall implement and maintain appropriate technical and organisational measures to protect personal data on the Platform as required by Article 21 of the DPJL 2018, including the measures described in paragraph 5 of Schedule 1. The Customer acknowledges that the Platform is architected so that Comtech personnel have no application-level means of reading Case Content, and that certain protections (including User credential hygiene, second-factor enrolment, permission assignment and retention operation) depend on the Customer’s own administration.
11.Warranties and disclaimers
11.1Each party warrants that it has the power and authority to enter into this Agreement. Comtech warrants that the Platform will perform materially as described in its documentation. Except as expressly stated in this Agreement, all other warranties, conditions and terms implied by law are excluded to the fullest extent permitted by Jersey law.
11.2Comtech does not warrant that the Platform will be uninterrupted or error-free, nor that use of the Platform will ensure the Customer’s compliance with Data Protection Law or any other law.
12.Liability
12.1Nothing in this Agreement excludes or limits either party’s liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for any other liability that cannot be excluded or limited under Jersey law. Nothing in this Agreement excludes or limits any liability of either party to data subjects or to the Data Protection Authority under the DPJL 2018, nor affects any right of contribution between the parties in respect of such liability.
12.2Subject to clause 12.1, neither party shall be liable for loss of profits, loss of business, loss of anticipated savings, or any indirect or consequential loss.
12.3Subject to clauses 12.1 and 12.2, each party’s total aggregate liability arising out of or in connection with this Agreement in any 12-month period shall not exceed the greater of £10,000 and 125% of the Fees paid or payable by the Customer in that period.
12.4The Customer shall indemnify Comtech against losses arising from claims that Case Content uploaded by the Customer infringes third-party rights or was processed on the Platform without a lawful basis or necessary authority, except to the extent caused by Comtech’s breach of this Agreement.
13.Suspension, term and termination
13.1This Agreement commences when the Customer’s organisation account is created and continues until terminated in accordance with this clause (the “Term”).
13.2Comtech may suspend access immediately where reasonably necessary to protect the security or integrity of the Platform or other customers’ data, or where required by law, giving notice as soon as practicable.
13.3Either party may terminate on notice with effect from the end of the current subscription period, and either party may terminate immediately on written notice if the other commits a material breach that is not remedied within 30 days of notice, or becomes insolvent, is declared en désastre, or enters any analogous procedure in any jurisdiction.
13.4On termination or expiry, the Customer may export Case Content using the Platform’s export functions during a wind-down period of 30 days, after which paragraph 10 of Schedule 1 (deletion) applies. Clauses which by their nature should survive termination, including clauses 8, 9, 12 and 16, shall survive.
14.Changes to these Terms
14.1Comtech may amend these Terms by giving the Customer not less than 30 days’ notice by email or in-Platform notice. Amendments take effect from the next renewal, except amendments required by law or necessary for security, which may take effect sooner. If an amendment materially disadvantages the Customer, the Customer may terminate at the end of the notice period without penalty. Changes to Schedule 3 are governed by paragraph 7 of Schedule 1, not this clause.
15.Notices
15.1Notices under this Agreement shall be in writing and sent, in the case of the Customer, to the administrator email address on the account and, in the case of Comtech, to dpo@comtech-solutions.co.uk or its registered office. Notices sent by email are deemed received on the next business day in Jersey.
16.General
16.1This Agreement constitutes the entire agreement between the parties in relation to the Platform and supersedes all prior arrangements. Neither party has relied on any statement not set out in this Agreement, provided that nothing limits liability for fraudulent misrepresentation. The Customer may not assign this Agreement without Comtech’s prior written consent, not to be unreasonably withheld; Comtech may assign to an affiliate or in connection with a transfer of the business. No failure to exercise a right is a waiver of it. If any provision is found invalid, the remainder continues in force. A person who is not a party has no right to enforce any term of this Agreement. Nothing in this Agreement creates a partnership or agency between the parties.
17.Governing law and jurisdiction
17.1This Agreement and any non-contractual obligations arising out of or in connection with it are governed by the law of Jersey, and the parties submit to the exclusive jurisdiction of the courts of Jersey, save that Comtech may seek injunctive relief in any court of competent jurisdiction to protect its intellectual property or the security of the Platform.
Schedule 1 — Data Processing Terms
These terms apply to Comtech’s Processing of Case Content as processor for the Customer (or the controller the Customer represents) and are intended to satisfy Articles 19, 22 and 23 of the DPJL 2018 and the equivalent requirements of the other frameworks within Data Protection Law.
1. Instructions. Comtech shall process Case Content only on the Customer’s documented instructions, which comprise this Agreement, the Customer’s configuration of and actions within the Platform (including enabling or disabling the AI Feature), and any further written instructions agreed between the parties, unless Processing is required by a law to which Comtech is subject, in which case Comtech shall inform the Customer of that requirement before Processing unless that law prohibits it. Comtech shall inform the Customer if, in its opinion, an instruction infringes Data Protection Law.
2. Scope. The subject matter, duration, nature and purposes of the Processing, and the categories of personal data and data subjects, are set out in Schedule 2.
3. Confidentiality of personnel. Comtech shall ensure that persons it authorises to process Case Content are subject to binding obligations of confidentiality. The Customer acknowledges that the Platform is designed so that Comtech personnel have no application-level access to Case Content in the ordinary course.
4. Records and cooperation. Comtech shall maintain the records required of a processor under Data Protection Law and shall cooperate, on request, with the Jersey Data Protection Authority (and any other supervisory authority with competence over the Processing) in the performance of its tasks.
5. Security. Comtech shall implement and maintain appropriate technical and organisational measures under Article 21 of the DPJL 2018, having regard to the state of the art, the costs of implementation and the nature, scope, context and purposes of the Processing and the risks to data subjects. As at the date of this Agreement these measures include: tenant isolation enforced by row-level security on all application tables with no cross-tenant administrative access; server-side verification of identity and organisation membership on every request; two-stage sign-in with a second verification factor; signed, HttpOnly, SameSite session cookies with inactivity and absolute session limits; encryption of data in transit (TLS) and at rest, with additional application-layer encryption of reviewer working material; private storage with short-lived signed URLs for file access; client-side text extraction so that document content is not sent to extraction services; redactions burned permanently into disclosure documents; an append-only, tamper-evident audit trail recording actions and identifiers but never Case Content; and rate limiting and input validation at the application boundary. Comtech may update these measures from time to time provided the overall level of protection is not materially reduced.
6. Assistance. Taking into account the nature of the Processing, Comtech shall assist the Customer by appropriate technical and organisational measures, insofar as reasonably possible, in fulfilling the Customer’s obligations to respond to data subjects exercising their rights under Part 6 of the DPJL 2018 (or equivalent provisions of other applicable Data Protection Law), and shall assist the Customer in ensuring compliance with the Customer’s obligations regarding security, breach notification, data protection impact assessments under Article 16 of the DPJL 2018 and prior consultation, taking into account the information available to Comtech. Comtech shall not respond directly to a data subject request concerning Case Content except on the Customer’s documented instruction and shall refer any such request it receives to the Customer without undue delay.
7. Sub-processors. The Customer provides general written authorisation for the sub-processors listed in Schedule 3. Comtech shall give the Customer not less than 30 days’ notice of any intended addition or replacement, by email to the account administrator or in-Platform notice. If the Customer reasonably objects on data protection grounds within that period and the parties cannot resolve the objection, the Customer may terminate the affected subscription without penalty, with a pro-rata refund of prepaid Fees for the unexpired period. Comtech shall impose on each sub-processor, by written contract, data protection obligations providing materially the same level of protection as this Schedule and shall remain fully liable to the Customer for the performance of each sub-processor’s obligations.
8. Personal data breach. Comtech shall notify the Customer without undue delay after becoming aware of a personal data breach affecting Case Content, and in any event within 48 hours of becoming aware, providing (in stages if necessary) the information reasonably required to enable the Customer or the relevant controller to meet its own obligations under Article 20 of the DPJL 2018, including the notification to the Data Protection Authority without undue delay and, where feasible, not later than 72 hours after the controller becomes aware. Comtech shall take reasonable steps to contain and remediate the breach and shall not notify any supervisory authority or data subject of a breach affecting Case Content on the Customer’s behalf unless instructed or required by law.
9. Transfers. Comtech shall not transfer Case Content outside Jersey except to the sub-processors in Schedule 3 in accordance with this paragraph, or on the Customer’s documented instructions. Any transfer to a jurisdiction not providing an adequate level of protection shall be made only in accordance with Articles 66 and 67 of the DPJL 2018 and the equivalent transfer provisions of other applicable Data Protection Law, using standard data protection clauses or other appropriate safeguards, as identified for each sub-processor in Schedule 3.
10. Deletion and return. On termination or expiry of the Agreement and following the wind-down period in clause 13.4, Comtech shall delete Case Content and existing copies within 30 days, save to the extent retention is required by a law to which Comtech is subject, in which case Comtech shall protect the retained data and process it for no other purpose. During the Term, deletion of Cases is effected by the Customer through the Platform’s deletion functions, and the Customer remains responsible for operating its own retention schedule as set out in clause 5.4.
11. Audit and information. Comtech shall make available to the Customer information reasonably necessary to demonstrate compliance with this Schedule, including summaries of its security measures, sub-processor terms and, where held, third-party assessments. Where such information is reasonably insufficient, Comtech shall permit an audit by the Customer or its independent auditor, not more than once in any 12-month period except following a personal data breach or at a supervisory authority’s requirement, on not less than 30 days’ notice, during business hours, without access to other customers’ data, and at the Customer’s cost.
Schedule 2 — Processing Particulars
Subject matter: the hosting and Processing of Case Content on the Corbiere platform to enable the Customer to manage data subject requests.
Duration: the Term plus the wind-down and deletion periods in clause 13.4 and paragraph 10 of Schedule 1.
Nature of Processing: storage, retrieval, structuring, display to the Customer’s Users, transmission within the Platform, redaction and disclosure-bundle generation, deletion; and, only where the AI Feature is enabled, transmission of the passage or document a User is working on to the provider of the model-and-region configuration selected by the Customer under clause 6, in the region so selected, for the generation of analysis suggestions.
Purpose: the provision of the Platform in accordance with the Agreement; Comtech shall not process Case Content for its own purposes.
Categories of data subjects: requesters and their representatives; individuals appearing in evidence or correspondence uploaded to Cases, who may include employees, customers, complainants, children and other third parties.
Categories of personal data: identity and contact details; identity verification documents; correspondence; and any personal data appearing in uploaded evidence, which may include special category data within Article 2 of the DPJL 2018 (including health data), data relating to criminal convictions and offences, and legally privileged material. The Customer is responsible for ensuring the conditions for processing any such data are met at controller level.
Schedule 3 — Approved Sub-processors
The Customer authorises the sub-processors of Case Content listed in the table below. For the purposes of this Schedule, transfers are assessed from Jersey under Articles 66 and 67 of the DPJL 2018 (and, where the Customer or the relevant controller is subject to the EU GDPR, UK GDPR or the Guernsey Law, under the equivalent transfer provisions of that framework). European Union and EEA member states, the United Kingdom and Guernsey are each treated as providing an adequate level of protection from a Jersey perspective, so no additional transfer mechanism is required for data remaining in those jurisdictions.
| Sub-processor | Role (Case Content processed) | Data hosting location | Transfer outside the EU/EEA and Jersey? | Transfer mechanism relied upon |
|---|---|---|---|---|
| Supabase, Inc. (provisioned via Lovable Cloud) | Database, authentication and file storage — all Case records and evidence files | EU region is selected; primary storage remains in the EU | None | Adequacy (EU member state) |
| Lovable Labs Incorporated | Application hosting and edge functions; gateway for transactional email dispatch | EU region is selected; primary storage remains in the EU | None | Adequacy (EU member state) |
| Resend, Inc. | Transactional email delivery — recipient addresses, invitation and verification content only; no Case evidence | United States | Yes | EU Standard Contractual Clauses in vendor DPA / UK Addendum / DPF certification |
| Amazon Web Services EMEA SARL (Amazon Bedrock — Claude) | AI Feature only, and only where the Customer has selected Claude on Amazon Bedrock — the passage or document a User is working on; prompts and outputs are not stored after the response and are not used for training; Anthropic receives no data (clause 6) | Ireland (EU), region eu-west-1 | No, save for AWS support access | Adequacy (European Union), with standard contractual clauses in the AWS Data Processing Addendum covering support access |
| Anthropic, PBC | AI Feature only, and only where the Customer has selected the direct Anthropic API — the passage or document a User is working on. Anthropic offers no European regional endpoint; inference runs in the United States and inputs and outputs are deleted within 30 days by default, unless the Customer holds a zero data retention agreement directly with Anthropic (clause 6) | United States | Yes | Standard contractual clauses in Anthropic’s data processing addendum; EU-US Data Privacy Framework certification and UK extension; Customer transfer risk assessment required |
| Microsoft (Azure OpenAI Service) — Microsoft Ireland Operations Limited where the Customer is contracted in Europe | AI Feature only, and only where the Customer has selected an Azure region — the passage or document a User is working on; OpenAI receives no data; prompts and generated content are stored up to 30 days for abuse monitoring, with review of flagged content by authorised Microsoft staff, unless Microsoft has approved modified abuse monitoring for the resource (clause 6) | UK South (UK) or Sweden Central (EU), as selected by the Customer’s administrator | No, save for Microsoft support access | Adequacy (United Kingdom or European Union), under the Microsoft Products and Services Data Protection Addendum, which incorporates standard contractual clauses for support access |
Only one AI sub-processor processes Case Content at any time for a given organisation: the one named against the model-and-region configuration that organisation has selected under clause 6. Where the AI Feature is not enabled, no AI sub-processor processes that organisation’s Case Content at all. Stripe processes billing data for which Comtech is controller and is not a sub-processor of Case Content. Comtech shall keep this Schedule up to date on the Platform and changes to it are governed by paragraph 7 of Schedule 1.