Skip to main content

Doc 06 — Subprocessor and Service Provider Notice

Document06 — Subprocessor and Service Provider Notice
Version06-subprocessor-notice-2026-08 (in force on publication)
Party / entityDPW Pte. Ltd. (UEN 202017982R), 247B Victoria St, Singapore 188033 ("DPW", "we")
AudienceCustomers, Users, Participating Firms, and individuals whose personal data is processed on the Platform

1. Purpose and scope

1.1 This Notice is the maintained register of the third-party providers DPW uses to operate the Platform and to process personal data. It supports Doc 04 — Privacy Notice (Section 8) and serves as the subprocessor annex (the "Annex III equivalent") to Doc 05 — Data Processing Addendum ("DPA") for every Customer Controller under the DPA — each Participating Firm and each Business Customer — read with Doc 13 — Security / Data-Protection Schedule ("Security Schedule").

1.2 This register covers processing of personal data in connection with: platform accounts and authentication; document collection and storage; AI-assisted classification, extraction, summarisation, drafting and triage; AML screening coordination; identity verification (when activated); e-signature coordination; email and messaging; payments; hosting, caching and error monitoring.

1.3 Three kinds of recipient — only one is a "subprocessor" here:

  • Subprocessor / data intermediary — a provider that processes personal data on DPW's instructions (and, for Engagement/CDD data, ultimately on the Participating Firm's instructions through DPW). These appear in the register below.
  • Independent controller / independent organisation — a provider that determines its own purposes for some processing (for example, a payment processor's own regulatory compliance). Where a provider acts partly in this capacity, the register notes it; that processing is governed by the provider's own privacy notice.
  • Participating Firm — never a subprocessor. The Firm is the responsible organisation for Engagement and CDD data; DPW processes for the Firm, not the reverse. Disclosures to Firms are described in Doc 04 Section 7.

2. The register

Status markers: ACTIVE — in production use; REDACTED-ONLY — receives sanitised data only; CONFIG-GATED — in code but inactive unless keys/configuration set; [EVIDENCE_GATED] — a contractual or evidentiary precondition is not yet satisfied and must be closed before publication or activation.

PROVIDERFUNCTIONDATA CATEGORIESLOCATION/REGIONTRANSFER MECHANISMSTATUS
AnthropicFoundation-model AI provider: classification, document/email extraction, summaries, drafting, triageFor one extraction task: raw identity data from documents/emails. All other tasks: redacted text (NRIC/FIN, passport, email, phone, DOB, address replaced; names not redacted)United States[CONTRACTUAL DATA PROTECTION CLAUSES — TO BE CONFIRMED]ACTIVE — raw-PII path limited to the single guarded extraction task (fail-closed guard). Account-level DPA/no-train status [EVIDENCE_GATED — PROVIDER DPA CONFIRMATION REQUIRED BEFORE PRODUCTION]
OpenRouterSecondary AI model gatewayRedacted classification prompts only — no raw identifiersUnited States[TO BE CONFIRMED]ACTIVE (optional) — REDACTED-ONLY; deployment guard blocks raw-PII tasks to this provider
NameScanAML/sanctions/PEP screeningName; optional date of birth and nationality. Not NRIC. Screening results returned and stored encrypted[LOCATION TO VERIFY][TO BE CONFIRMED]ACTIVE — fail-closed on errors/missing keys; any match or error creates a mandatory human task
Veriff OÜVideo identity verificationIdentity document images, face/video verification data, extracted identity attributesEstonia (EU)[TO BE CONFIRMED]CONFIG-GATED — integration stub unless keys set; DPA not signed [EVIDENCE_GATED — DO NOT ACTIVATE OR PUBLISH ROW AS ACTIVE UNTIL DPA SIGNED]
DocumensoElectronic signature coordinationSignatory names, email addresses, signed documents[LOCATION TO VERIFY] (cloud-hosted)[TO BE CONFIRMED]ACTIVE
ResendTransactional email deliveryRecipient name/email, message contentUnited States[TO BE CONFIRMED]ACTIVE
GoogleIntake mailbox (Gmail API): receipt and processing of inbound emailFull email contents and attachments sent to the intake address, sender detailsUnited States / global[TO BE CONFIRMED]ACTIVE
TwilioWhatsApp messagingPhone numbers, message contentUnited States / global[TO BE CONFIRMED]ACTIVE
StripePayment processingBilling details, transaction data; card data held by Stripe, not DPWUnited States / global[TO BE CONFIRMED]ACTIVE — Stripe also acts as an independent organisation for its own regulatory obligations
SupabaseDatabase, storage, authentication (primary data store)All platform-held personal data, including field-level-encrypted identity data; identity documents in private bucketsSingapore region (ap-southeast-1, operational; operator US-headquartered) [REGION ASSERTION TO VERIFY AT PUBLICATION][TO BE CONFIRMED]ACTIVE
VercelApplication hosting and deliveryRequest data, technical data transiting the application layerUnited States / global — region unpinned[TO BE CONFIRMED]ACTIVE
UpstashCache / queue (Redis)Transient operational data, which may include personal data in queued jobs[REGION TO VERIFY][TO BE CONFIRMED]ACTIVE
SentryError monitoringTechnical error/diagnostic data — PII-send disabled in configurationUnited States[TO BE CONFIRMED]ACTIVE — PII-send disabled [VERIFY CONFIGURATION AT EACH REVIEW]

Excluded — MyInfo/Singpass: the Platform has no MyInfo/Singpass integration (a code stub only exists). It is excluded from this register, and no government identity-data flow exists. Any claim of Singpass integration anywhere is incorrect.

Excluded — analytics/marketing: no third-party analytics or marketing trackers are set on the web application (see Doc 07 — Cookie Notice).

3. Intra-group processing

DPW Pte. Ltd. is currently a single entity. No affiliate or group company processes personal data, and there are no intra-group transfers. If that changes, affected entities will be added to this register under the change mechanism in Section 4.

4. Change mechanism

4.1 Notice. Before adding a new subprocessor, replacing an existing one, or materially changing an existing provider's function, data categories or processing location, we will give at least 30 days' notice before the change takes effect, in both of the following ways: (a) by updating this register; and (b) by direct notice — email or in-platform notice — to Participating Firms and to affected Business Customers, in accordance with clause 4.2 of the DPA (Doc 05). A register update alone is not sufficient notice of a subprocessor addition or replacement.

4.2 Objection. A Participating Firm or Customer may object on reasonable data-protection grounds within 14 days of notice, by writing to privacy@csfile.ai.

4.3 Resolution. On receiving a valid objection we will work in good faith to resolve it — for example, by offering a configuration that avoids the new provider for the objector's data, or additional safeguards. If we cannot offer a reasonable alternative within the 14-Business-Day alternative window in Doc 02 — Platform Terms of Service, Section 17.3, a Customer may terminate the affected services under the subprocessor-objection termination right in that Section, with a pro-rata refund of prepaid, unused fees under Doc 10 — Payment, Cancellation and Refund Terms, clause 11.2. A Participating Firm's objection and termination route is clause 4.2 of the DPA (Doc 05). Statutory retention obligations survive termination.

4.4 Emergency changes. Where an immediate change is required for security, legal compliance or service continuity, we may implement it first and give notice as soon as practicable; the objection process then applies retrospectively.

4.5 Subprocessor obligations. Each register provider is (or, where [EVIDENCE_GATED], must be before activation) bound by written terms imposing data protection obligations no less protective than those DPW owes under Doc 05 and the PDPA, including for overseas transfers under section 26 of the PDPA.

5. Versioning and archive

5.1 Each published version of this Notice carries a version identifier and effective date. Superseded versions are archived and available on request to privacy@csfile.ai and at [ARCHIVE URL — TO BE ESTABLISHED AT PUBLICATION].

5.2 Change log:

VersionDateChange
draft-2026-08-182026-08-18Initial draft register

6. Relationship to other documents

  • Doc 04 — Privacy Notice: individual-facing description of these disclosures; this register prevails on provider detail.
  • Doc 05 — DPA: this register is the agreed subprocessor list (Annex III equivalent) for every Customer Controller under the DPA — each Participating Firm and each Business Customer.
  • Doc 13 — Security Schedule: technical and organisational measures applying to DPW and flowed down to subprocessors.
  • Doc 07 — Cookie Notice: client-side technologies (no third-party trackers currently set).

Version: 06-subprocessor-notice-2026-08 · Approval: management-attested