Doc 06 — Subprocessor and Service Provider Notice
| Document | 06 — Subprocessor and Service Provider Notice |
| Version | 06-subprocessor-notice-2026-08 (in force on publication) |
| Party / entity | DPW Pte. Ltd. (UEN 202017982R), 247B Victoria St, Singapore 188033 ("DPW", "we") |
| Audience | Customers, Users, Participating Firms, and individuals whose personal data is processed on the Platform |
1. Purpose and scope
1.1 This Notice is the maintained register of the third-party providers DPW uses to operate the Platform and to process personal data. It supports Doc 04 — Privacy Notice (Section 8) and serves as the subprocessor annex (the "Annex III equivalent") to Doc 05 — Data Processing Addendum ("DPA") for every Customer Controller under the DPA — each Participating Firm and each Business Customer — read with Doc 13 — Security / Data-Protection Schedule ("Security Schedule").
1.2 This register covers processing of personal data in connection with: platform accounts and authentication; document collection and storage; AI-assisted classification, extraction, summarisation, drafting and triage; AML screening coordination; identity verification (when activated); e-signature coordination; email and messaging; payments; hosting, caching and error monitoring.
1.3 Three kinds of recipient — only one is a "subprocessor" here:
- Subprocessor / data intermediary — a provider that processes personal data on DPW's instructions (and, for Engagement/CDD data, ultimately on the Participating Firm's instructions through DPW). These appear in the register below.
- Independent controller / independent organisation — a provider that determines its own purposes for some processing (for example, a payment processor's own regulatory compliance). Where a provider acts partly in this capacity, the register notes it; that processing is governed by the provider's own privacy notice.
- Participating Firm — never a subprocessor. The Firm is the responsible organisation for Engagement and CDD data; DPW processes for the Firm, not the reverse. Disclosures to Firms are described in Doc 04 Section 7.
2. The register
Status markers: ACTIVE — in production use; REDACTED-ONLY — receives sanitised data only; CONFIG-GATED — in code but inactive unless keys/configuration set; [EVIDENCE_GATED] — a contractual or evidentiary precondition is not yet satisfied and must be closed before publication or activation.
| PROVIDER | FUNCTION | DATA CATEGORIES | LOCATION/REGION | TRANSFER MECHANISM | STATUS |
|---|---|---|---|---|---|
| Anthropic | Foundation-model AI provider: classification, document/email extraction, summaries, drafting, triage | For one extraction task: raw identity data from documents/emails. All other tasks: redacted text (NRIC/FIN, passport, email, phone, DOB, address replaced; names not redacted) | United States | [CONTRACTUAL DATA PROTECTION CLAUSES — TO BE CONFIRMED] | ACTIVE — raw-PII path limited to the single guarded extraction task (fail-closed guard). Account-level DPA/no-train status [EVIDENCE_GATED — PROVIDER DPA CONFIRMATION REQUIRED BEFORE PRODUCTION] |
| OpenRouter | Secondary AI model gateway | Redacted classification prompts only — no raw identifiers | United States | [TO BE CONFIRMED] | ACTIVE (optional) — REDACTED-ONLY; deployment guard blocks raw-PII tasks to this provider |
| NameScan | AML/sanctions/PEP screening | Name; optional date of birth and nationality. Not NRIC. Screening results returned and stored encrypted | [LOCATION TO VERIFY] | [TO BE CONFIRMED] | ACTIVE — fail-closed on errors/missing keys; any match or error creates a mandatory human task |
| Veriff OÜ | Video identity verification | Identity document images, face/video verification data, extracted identity attributes | Estonia (EU) | [TO BE CONFIRMED] | CONFIG-GATED — integration stub unless keys set; DPA not signed [EVIDENCE_GATED — DO NOT ACTIVATE OR PUBLISH ROW AS ACTIVE UNTIL DPA SIGNED] |
| Documenso | Electronic signature coordination | Signatory names, email addresses, signed documents | [LOCATION TO VERIFY] (cloud-hosted) | [TO BE CONFIRMED] | ACTIVE |
| Resend | Transactional email delivery | Recipient name/email, message content | United States | [TO BE CONFIRMED] | ACTIVE |
| Intake mailbox (Gmail API): receipt and processing of inbound email | Full email contents and attachments sent to the intake address, sender details | United States / global | [TO BE CONFIRMED] | ACTIVE | |
| Twilio | WhatsApp messaging | Phone numbers, message content | United States / global | [TO BE CONFIRMED] | ACTIVE |
| Stripe | Payment processing | Billing details, transaction data; card data held by Stripe, not DPW | United States / global | [TO BE CONFIRMED] | ACTIVE — Stripe also acts as an independent organisation for its own regulatory obligations |
| Supabase | Database, storage, authentication (primary data store) | All platform-held personal data, including field-level-encrypted identity data; identity documents in private buckets | Singapore region (ap-southeast-1, operational; operator US-headquartered) [REGION ASSERTION TO VERIFY AT PUBLICATION] | [TO BE CONFIRMED] | ACTIVE |
| Vercel | Application hosting and delivery | Request data, technical data transiting the application layer | United States / global — region unpinned | [TO BE CONFIRMED] | ACTIVE |
| Upstash | Cache / queue (Redis) | Transient operational data, which may include personal data in queued jobs | [REGION TO VERIFY] | [TO BE CONFIRMED] | ACTIVE |
| Sentry | Error monitoring | Technical error/diagnostic data — PII-send disabled in configuration | United States | [TO BE CONFIRMED] | ACTIVE — PII-send disabled [VERIFY CONFIGURATION AT EACH REVIEW] |
Excluded — MyInfo/Singpass: the Platform has no MyInfo/Singpass integration (a code stub only exists). It is excluded from this register, and no government identity-data flow exists. Any claim of Singpass integration anywhere is incorrect.
Excluded — analytics/marketing: no third-party analytics or marketing trackers are set on the web application (see Doc 07 — Cookie Notice).
3. Intra-group processing
DPW Pte. Ltd. is currently a single entity. No affiliate or group company processes personal data, and there are no intra-group transfers. If that changes, affected entities will be added to this register under the change mechanism in Section 4.
4. Change mechanism
4.1 Notice. Before adding a new subprocessor, replacing an existing one, or materially changing an existing provider's function, data categories or processing location, we will give at least 30 days' notice before the change takes effect, in both of the following ways: (a) by updating this register; and (b) by direct notice — email or in-platform notice — to Participating Firms and to affected Business Customers, in accordance with clause 4.2 of the DPA (Doc 05). A register update alone is not sufficient notice of a subprocessor addition or replacement.
4.2 Objection. A Participating Firm or Customer may object on reasonable data-protection grounds within 14 days of notice, by writing to privacy@csfile.ai.
4.3 Resolution. On receiving a valid objection we will work in good faith to resolve it — for example, by offering a configuration that avoids the new provider for the objector's data, or additional safeguards. If we cannot offer a reasonable alternative within the 14-Business-Day alternative window in Doc 02 — Platform Terms of Service, Section 17.3, a Customer may terminate the affected services under the subprocessor-objection termination right in that Section, with a pro-rata refund of prepaid, unused fees under Doc 10 — Payment, Cancellation and Refund Terms, clause 11.2. A Participating Firm's objection and termination route is clause 4.2 of the DPA (Doc 05). Statutory retention obligations survive termination.
4.4 Emergency changes. Where an immediate change is required for security, legal compliance or service continuity, we may implement it first and give notice as soon as practicable; the objection process then applies retrospectively.
4.5 Subprocessor obligations. Each register provider is (or, where [EVIDENCE_GATED], must be before activation) bound by written terms imposing data protection obligations no less protective than those DPW owes under Doc 05 and the PDPA, including for overseas transfers under section 26 of the PDPA.
5. Versioning and archive
5.1 Each published version of this Notice carries a version identifier and effective date. Superseded versions are archived and available on request to privacy@csfile.ai and at [ARCHIVE URL — TO BE ESTABLISHED AT PUBLICATION].
5.2 Change log:
| Version | Date | Change |
|---|---|---|
| draft-2026-08-18 | 2026-08-18 | Initial draft register |
6. Relationship to other documents
- Doc 04 — Privacy Notice: individual-facing description of these disclosures; this register prevails on provider detail.
- Doc 05 — DPA: this register is the agreed subprocessor list (Annex III equivalent) for every Customer Controller under the DPA — each Participating Firm and each Business Customer.
- Doc 13 — Security Schedule: technical and organisational measures applying to DPW and flowed down to subprocessors.
- Doc 07 — Cookie Notice: client-side technologies (no third-party trackers currently set).