Back to Trust Center
Effective: 2026-07-23

Register of Processing Activities (RoPA) — ISMS Copilot

Overview

This Register of Processing Activities (RoPA) documents all personal data processing activities carried out by the ISMS Copilot platform in compliance with Article 30 of the General Data Protection Regulation (GDPR). It serves as a comprehensive record of how personal data is collected, processed, stored, and protected within the platform.

This RoPA is maintained by ISMS Copilot and updated regularly to reflect changes in data processing activities. Effective Date: 2026-07-23. The AI Routing section reflects the unified non-ADP envelope: any non-ADP plan (Free, Essential, Plus, Standard, Pro, Business, or an app-managed Plus trial) with ADP off may be served by Anthropic or by the closed OpenRouter allowlist (the seven glm-4.7 hosts plus xAI via the "xAI (ZDR)" endpoint for the Grok models), for any chat mode (fast, think, or agentic/Beyond). For paid plans (Plus and above) in the chat Fast and Think modes and the Beyond assistant, xAI via the "xAI (ZDR)" endpoint is the current default destination and Anthropic is the automatic pre-first-token failover; ISMS Copilot may serve any non-ADP paid request, in any mode, via any of the eight allowlisted underlying providers or Anthropic, and may move any cohort or mode between these destinations over time (such moves within the disclosed envelope are control-neutral under DPA §2.4: no advance notice, publication-only). Anthropic otherwise remains a disclosed non-ADP provider and the circuit-breaker failover context. Authenticated web-search processing (now live in production) and the separate pending future Brave-direct recipient are recorded under Activity #2.

Who This Is For

This document is intended for:

  • Data Protection Officers (DPOs) evaluating ISMS Copilot
  • Compliance teams conducting vendor risk assessments
  • Organizations requiring sub-processor documentation
  • Legal and security teams performing due diligence
  • Auditors assessing GDPR compliance

This is the audit-grade companion to the Data Processing Agreement (DPA). The DPA states the contractual obligations; this RoPA documents the per-activity processing inventory.

GDPR Compliance Overview

ISMS Copilot is a B2B SaaS tool for compliance professionals. We process data primarily in the EU using Supabase (EU region) for storage and authentication. We minimize data collection, ensure user control, and contractually prohibit any AI provider from training on user data. As a small company, we focus on pragmatic, high-impact controls while pursuing formal certifications (ISO 27001 in progress) and implementing AI security controls including layered account-level enforcement at our routing aggregator.

Data Controller Information

  • Name: ISMS Copilot (operated by Better ISMS EURL)
  • Jurisdiction: France (European Union)
  • Primary Data Location: Frankfurt, Germany (AWS EU-Central-1)
  • Supervisory Authority: Commission Nationale de l'Informatique et des Libertés (CNIL)
  • Privacy Contact: privacy@ismscopilot.com

Primary data processing occurs within the European Union (Frankfurt, Germany). Some limited transfers to the United States occur for AI processing (configurable via Advanced Data Protection Mode) and email communications (SendGrid, Kit), with appropriate safeguards including Standard Contractual Clauses, EU-US Data Privacy Framework certification (where applicable), and account-level enforcement controls at the OpenRouter routing aggregator.

AI Routing — Foundational Concepts

Before reading the per-activity sections below, the following routing decision is invoked at the start of every chat request. It is implemented in selectChatModel(adpEnabled, userPlan) and determines which AI sub-processor handles the request:

Routing pathTriggerAI providerLocationRetentionTraining
ADP pathAdvanced Data Protection enabled (any plan)Mistral AIEU (Frankfurt)Zero retentionNo training (per Mistral's commercial API terms)
Paid path (Plus and above)Plus, Standard, Pro, or Business, or an app-managed 7-day Plus trial (which routes on this paid path), + ADP off, any chat modexAI (Grok) via OpenRouter's "xAI (ZDR)" endpoint is the current default for the Fast and Think modes and the Beyond assistant, with Anthropic Claude (Opus for Think, Sonnet for Fast) as the automatic failover; in any chat mode ISMS Copilot may serve a non-ADP paid request via any of the eight allowlisted underlying providers (including xAI) or Anthropic Claude, and may move any cohort or mode between these destinations over time (control-neutral under DPA §2.4, publication-only)United States, or EU for the EU-based hosts (Inceptron in Sweden, Nebius in Netherlands); a default deployment posture, not contractual residency, so use ADP for a guaranteed single EU destinationAnthropic-served traffic: retention under Anthropic's standard commercial API terms (inputs/outputs ordinarily deleted within ~30 days; safety-flagged content up to 2 years; safety-classification scores up to 7 years; never used for training). OpenRouter-served traffic: zero retention. Customers needing zero retention everywhere can enable ADP.No training (Anthropic commercial API terms / OpenRouter account level)
Default path (Essential)Essential plan + ADP offOpenRouter aggregator → closed two-provider subset (Google Vertex, Cerebras)United StatesZero retention (mandatory at OpenRouter account level)No training (set at OpenRouter account level)
Default path (free)Free or null plan + ADP offOpenRouter aggregator → one of seven allowlisted underlying providers (Inceptron, DeepInfra, Cerebras, Google Vertex, Together AI, Fireworks AI, Nebius)United States, or EU for the EU-based hosts (Inceptron in Sweden, Nebius in Netherlands); inference region not pinnable via OpenRouterZero retention (mandatory at OpenRouter account level)No training (set at OpenRouter account level)

Unified non-ADP envelope. The three ADP-off rows above are the current routing snapshot within a single non-ADP envelope, not fixed per-plan limits: any non-ADP plan (Free, Essential, Plus and above, or an app-managed Plus trial) may be served by Anthropic (United States, standard commercial API terms) or by the OpenRouter allowlist (zero retention: no persistent retention beyond serving the request; transient in-memory caching only), and ISMS Copilot may move cohorts between them over time. For paid plans (Plus and above) in the Fast and Think modes and the Beyond assistant the default is xAI (Grok) via the "xAI (ZDR)" endpoint, with Anthropic as the automatic pre-first-token failover. This is classified control-neutral (no new sub-processor; unchanged controls, allowlist, and the ADP EU/zero-retention guarantee), so it does not require advance sub-processor notice.

Failover. Paid Fast/Think/Beyond failover. For the paid plans (Plus and above) Fast and Think chat modes and the Beyond assistant, which default to xAI via OpenRouter's "xAI (ZDR)" endpoint, if that route does not begin responding within a short pre-first-token timeout the request is re-served by Anthropic (Opus for Think, Sonnet for Fast); if Anthropic's circuit breaker is open, the request fails over to Mistral AI in Frankfurt (EU). The xAI attempt is zero-retention, so where a single request transits two destinations the first leg holds no persistent content. For paid traffic served by Anthropic, if Anthropic is unavailable, requests automatically fail over to Mistral AI in Frankfurt via a circuit-breaker controller. On the OpenRouter-served paths (Essential, free, and paid plans), OpenRouter's aggregator-level fallback walks the allowlisted providers automatically (for Essential, between Google Vertex and Cerebras; for the free and paid plans, across the allowlisted providers, the seven glm-4.7 hosts with xAI as the paid Fast/Think/Beyond default); OpenRouter itself is the single point of dependency for those paths.

Paid-plan provider flexibility (Plus and above). For paid plans (Plus, Standard, Pro, Business) with ADP off, the closed OpenRouter allowlist (eight providers including xAI via the "xAI (ZDR)" endpoint) is a permitted AI-routing destination alongside Anthropic; for the Fast and Think modes and the Beyond assistant xAI via the "xAI (ZDR)" endpoint is the current default and Anthropic is the automatic pre-first-token failover; in any chat mode ISMS Copilot may serve a paid request via any of the eight allowlisted underlying providers or Anthropic, mirroring the free / null-plan path, and may move any paid cohort or mode between these destinations over time (such moves within the disclosed envelope are control-neutral under DPA §2.4: no advance notice, publication-only). The OpenRouter routing is under unchanged account-level controls (mandatory ZDR, training-disallowed, publication-disallowed, allowlist, PRC-blocklist) and the same underlying-provider transfer mechanism; every allowlisted provider is equal to or stronger than Anthropic on retention, training, and jurisdiction. The specific allowlisted provider that serves a given paid request is selected at routing time and is not individually disclosed per request; a Customer requiring a deterministic, single EU destination should enable Advanced Data Protection (Mistral, EU). A Customer may keep all of the organization's AI processing in the EU by enabling Advanced Data Protection at the organization level, which routes to Mistral (EU); ADP is the account-level EU-residency guarantee. The change is classified as control-neutral under DPA §2.4 because no new sub-processor is introduced and the underlying-provider allowlist, account-level controls, and transfer mechanism are unchanged.

OpenRouter account-level controls (enforced by Better ISMS as the OpenRouter account holder, applied to every request, applicable to all eight allowlisted underlying providers):

  • Zero Data Retention is mandatory: per OpenRouter's published policy, ZDR-mandatory accounts can only route to endpoints with a Zero Data Retention policy. Zero Data Retention here means no persistent retention of request content beyond serving the request; a provider may still hold content transiently in memory for the duration of processing, as is inherent to serving an inference request.
  • Free Training Disallowed and Paid Training Disallowed are both set.
  • Free Publication Disallowed is set; the model-publication channel is closed.
  • Closed eight-provider allowlist. The seven glm-4.7 hosts (Inceptron, DeepInfra, Cerebras, Google Vertex, Together AI, Fireworks AI, and Nebius) plus xAI via the "xAI (ZDR)" endpoint for the Grok models may serve our requests. (The seven glm-4.7 hosts were expanded from 4 to 7 on 2026-05-25; xAI was activated for paid Customer-Content on 2026-07-21; see the sub-processor amendment notice and change log.)
  • PRC-jurisdiction blocklist — Alibaba Cloud International, Baidu Qianfan, DeepSeek, Moonshot AI, Xiaomi, and Z.AI are all blocked. This is a Schrems II–style supplementary measure aligned with EDPB Recommendations 01/2020.

Configuration-integrity caveat. OpenRouter account-level controls are configured per the policies above. Better ISMS does not currently rely on an OpenRouter API or signed attestation for real-time integrity. Evidence of the configuration is two-fold: (a) this RoPA is itself a contemporaneous record of the configured controls as of its effective date, and (b) Better ISMS will demonstrate the live OpenRouter account configuration via a guided dashboard walkthrough on customer request (typically a recorded screen-share session). Ad-hoc screenshots may be captured on specific customer request or when controls materially change.


Processing Activity #1: User Authentication & Account Management

Purpose of Processing

To provide secure user authentication, session management, and account access control for the ISMS Copilot platform.

  • Primary: Contract Performance (Article 6(1)(b) GDPR) — necessary to provide the service
  • Secondary: Legitimate Interest (Article 6(1)(f) GDPR) — security and fraud prevention

Categories of Data Subjects

  • Platform users (compliance professionals, consultants, security teams)
  • Trial users and prospective customers
  • Workspace members and collaborators

Categories of Personal Data

  • Email addresses
  • Password hashes (encrypted, not reversible)
  • Authentication tokens and session identifiers
  • User unique identifiers (UUIDs)
  • Password reset tokens (temporary)
  • Account creation timestamps
  • Last login timestamps

Data Processors

ProcessorRoleLocationMechanism
Supabase AuthPostgreSQL-based authentication, session managementEU (Frankfurt)GDPR-compliant DPA

Retention Period

  • Active accounts: Retained while account is active
  • After account deletion: Permanently deleted within 30 days
  • Session tokens: Expire automatically after inactivity period
  • Password reset tokens: Expire after 24 hours or first use

Security Measures

  • Password hashing using industry-standard algorithms
  • Encrypted data transmission (TLS 1.3)
  • Row-level security in database
  • Multi-factor authentication (MFA) available
  • Session timeout controls

Processing Activity #2: AI Chat Processing & Conversation Management

Purpose of Processing

To provide AI-powered compliance assistance, generate responses to user queries, maintain conversation context, and, where plan and Customer policy permit, ground current or company-specific claims in request-scoped external evidence. Retrieval establishes the external source material supplied to the answering model; the model then reasons and writes using that evidence and separately maintained framework knowledge.

Primary: Contract Performance (Article 6(1)(b) GDPR) — core service functionality

Categories of Data Subjects

  • Authenticated platform users
  • Individuals mentioned in user queries (indirect data subjects)

Categories of Personal Data

  • User messages and queries
  • AI-generated responses
  • Conversation thread metadata (titles, timestamps, status)
  • User workspace configurations
  • Custom instructions and personas
  • Potentially sensitive compliance data (policies, procedures, audit information)
  • For authenticated web search: limited recent conversation text used for intent classification; for ADP-off discovery, a minimized query derived only from the latest user request; transient public search results or exact-URL page text; bounded excerpts, source titles/URLs, and retrieval summary supplied to the answer model already applicable to the conversation or Beyond run; and source links included with the generated answer

Special category data (Article 9 GDPR) and personal data relating to criminal convictions and offences (Article 10 GDPR) are excluded from the default (non-ADP) AI routing path. Users intending to process such data with AI assistance must enable Advanced Data Protection Mode, which routes inputs to the EU-based enhanced-protection model (Mistral, EU). The platform does not automatically detect or filter special-category or criminal-offence content on the default path; users remain responsible for establishing a lawful basis and for enabling Advanced Data Protection Mode before inputting such data. See the Data Processing Agreement §4.2.

Data Processors

Database Storage (always active):

ProcessorRoleLocationMechanism
Supabase PostgreSQLMessage storage, retrieval, conversation managementEU (Frankfurt)GDPR-compliant DPA

AI Processing (routed automatically per selectChatModel(adpEnabled, userPlan) — see "AI Routing — Foundational Concepts" above):

ProcessorWhen invokedLocationRetentionTrainingMechanism
Mistral AIADP enabled (any plan); circuit-breaker failover destination for Anthropic; conversation compaction; conversation summaries; search-intent classification; and provider-attested source-URL discovery for eligible ADP-off authenticated search. Mistral search prose is discarded; bounded exact-fetched evidence goes only to the already applicable answer/Beyond provider; authenticated web search fails closed under ADPExisting inference, moderation, and summarization routes documented in Frankfurt (EU). For ADP-off authenticated search, web-search discovery runs on Mistral's stateful Conversations/Agents endpoint, and Mistral engages Brave (Brave Software, Inc., US) as Mistral's own web-search sub-processor (see Mistral's published sub-processor list and the transparency note below). ISMS Copilot does not separately engage Brave for this routeExisting routes: zero retention. Web-search discovery is outside Mistral's zero-retention posture (stateful endpoint, reached via Brave US): standard, non-zero retention per the applicable Mistral/Brave provider termsNo training under applicable commercial termsExisting routes: EU residency. Via Mistral's web-search chain the query reaches Brave (US) under SCCs; not EU-only
Anthropic ClaudeAny non-ADP plan, as one of the permitted non-ADP providers and the circuit-breaker failover context (a non-ADP request may instead be served by the OpenRouter allowlist for any chat mode). For paid plans (Plus and above) in the Fast and Think modes and the Beyond assistant, Anthropic is the automatic pre-first-token failover (Opus for Think, Sonnet for Fast) behind the xAI "xAI (ZDR)" default, not the default destinationUnited StatesStandard Anthropic commercial API terms: inputs/outputs ordinarily deleted within ~30 days; safety-flagged content up to 2 years; safety-classification scores up to 7 years; never training. Customers needing zero retention can enable ADPNo training (per Anthropic's commercial API terms)SCCs
OpenRouter aggregatorEssential + ADP off (closed subset: Google Vertex, Cerebras); Free / null plan + ADP off (routes to one of the seven allowlisted glm-4.7 underlying providers); and Plus / Standard / Pro / Business + ADP off, where xAI via the "xAI (ZDR)" endpoint is the current default destination for the Fast and Think modes and the Beyond assistant (Anthropic retained as the automatic pre-first-token failover) and, in any chat mode, a non-ADP paid request may be routed across the eight allowlisted underlying providers (including xAI) or Anthropic, with cohorts or modes moved between these destinations over time (control-neutral under DPA §2.4, publication-only)United StatesZero (mandatory at account level)No training (account-level)OpenRouter's role is account-level enforcement; legal transfer mechanism for data leaving the EU is anchored at the underlying-provider rows below
↳ Inceptron (Inceptron AB)OpenRouter underlying provider (allowlisted)Sweden (EU)Zero (enforced via OR account config)No training (enforced via OR account config)SCCs (inference region not pinnable)
↳ DeepInfraOpenRouter underlying provider (allowlisted)United StatesZero (enforced via OR account config)No training (enforced via OR account config)SCCs
↳ CerebrasOpenRouter underlying provider (allowlisted)United StatesZero (enforced via OR account config)No training (enforced via OR account config)SCCs
↳ Google VertexOpenRouter underlying provider (allowlisted)United StatesZero (enforced via OR account config)No training (enforced via OR account config)SCCs + EU-US Data Privacy Framework
↳ Together AIOpenRouter underlying provider (allowlisted, added 2026-05-25)United States (default North America data centers per Together docs; OR aggregator does not pin region per request)Zero (enforced via OR account config)No training (enforced via OR account config)SCCs
↳ Fireworks AIOpenRouter underlying provider (allowlisted, added 2026-05-25)United States: multi-region fleet (US, EU Frankfurt + Iceland, APAC Tokyo only; no PRC or Hong Kong infrastructure identified in Fireworks' published deployment docs; OR aggregator does not pin region per request)Zero (enforced via OR account config)No training (enforced via OR account config)SCCs
↳ NebiusOpenRouter underlying provider (allowlisted, added 2026-05-25)Netherlands HQ; primary inference in Finland (EU) with US secondary per Nebius docs (OR aggregator does not pin region per request)Zero (enforced via OR account config)No training (enforced via OR account config)SCCs
↳ xAI (Grok, via OpenRouter "xAI (ZDR)" endpoint)Default destination for paid plans (Plus and above), ADP off, chat Fast and Think modes and the Beyond assistant, replacing the prior Anthropic default; Anthropic retained as the pre-first-token failover context. Not used for free / null-plan glm-4.7 routing or under ADPUnited States (OpenRouter-published provider footprint; per-request inference region not pinned via OpenRouter)Zero data retention as configured and verified 2026-07-19 (OpenRouter account-level ZDR, "xAI (ZDR)" endpoint)No training (OpenRouter account-level training-disallowed; xAI published API no-training default)SCCs at the underlying-provider layer via xAI's published DPA (Modules 2/3, Irish-law) + OpenRouter Article 28(4) flow-down

Every "Zero" in the OpenRouter rows above is the account-level Zero Data Retention defined in the OpenRouter account-controls section: no persistent retention beyond serving the request; a provider may hold content transiently in memory for the duration of processing, as is inherent to inference.

Backend Infrastructure (always active):

ProcessorRoleLocationMechanism
Fly.ioChat orchestration, streaming responses, message routing, and exact fetching of user-submitted or Mistral-attested public URLsEU deploymentGDPR-compliant hosting agreement

Authenticated web-search retrieval:

  • Launch route, ADP off: the minimized latest-request query goes to Mistral's web-search service for provider-attested source-URL discovery. Mistral's web search runs on Mistral's stateful Conversations/Agents endpoint, which is outside Mistral's zero-retention posture and uses Brave (United States) as its web-search sub-processor, so the query hop reaches Brave (US) under standard (non-zero) retention and is not an EU-only zero-retention route. Mistral's generated prose is discarded. Our SSRF-hardened Fly.io service in the EU exact-fetches the attested pages and supplies bounded labeled extracts to the answer model already applicable to the conversation or Beyond run. No additional semantic grounding model receives the draft. The direct-Brave route (ISMS Copilot calling the Brave API itself) is not constructed or called.
  • ADP: authenticated web search fails closed, because Mistral web search is not EU-only and not zero-retention. Only exact user-selected page/document fetch through EU Fly remains available.
  • Exact user-supplied URL: the same EU Fly.io service fetches the exact public page directly. Analyze-page and import-document remain available under ADP, with subsequent AI processing on the confirmed Mistral EU route. Company research also needs independent discovery and therefore fails closed under ADP.
  • Future Brave-direct route, pending and dark (distinct from Brave's launch role as Mistral's sub-processor above): no earlier than 2026-08-12, and only after actual notice and founder contractual acceptance, a non-ADP route in which ISMS Copilot would call the Brave Search API itself could send a minimized latest-request query to Brave Software, Inc. in the United States. No files, memories, workspace context, account identifiers, or user/device identifiers would be sent. Brave standard query logs may be retained up to 90 days; SCCs apply; Brave's DPA excludes Search Query Data from processor scope. This direct route is not the launch default.

Sub-processor chain transparency (external recipient via Mistral). For the launch web-search route, ISMS Copilot does not separately engage Brave and does not list Brave as one of its own Article 28 sub-processors. Brave (US) is engaged by Mistral as Mistral's own web-search sub-processor; the minimized query reaches Brave only through Mistral's web-search chain, and Mistral identifies Brave on its published sub-processor list. We disclose this onward Mistral (EU) to Brave (US) query hop for transparency as an external recipient reached via Mistral: it is not EU-only and not zero-retention, and standard, non-zero retention applies per the applicable Mistral/Brave provider terms.

User-directed feature, launch disclosure basis. Authenticated web search is a user-directed, customer-controllable feature rather than a change to baseline AI processing: it fires only on the user's own search intent (a conservative intent classifier), is disabled entirely under Advanced Data Protection (it fails closed), is controllable at both the organization and personal level through the Allow web search settings, and is shown to the user through an in-product provenance indicator when a search runs. On that basis the launch (Mistral-mediated) route is disclosed at launch through the Trust Center, the DPA, and the in-app changelog once the feature is live, rather than treated as a change requiring 30 days' advance sub-processor notice. The 30-day advance-notice mechanism continues to apply only to the separate future Brave-direct route.

Reserved AI Processors (code paths exist; not invoked in current production)

OpenAI, X.AI (Grok), and Google Gemini have direct-API integration code paths in the platform, but no current user-facing flow invokes them. They are not active sub-processors. Activation of any Reserved processor for live processing of user data requires a 30-day customer notice under the change-of-sub-processor procedure.

Retention Period

  • User-configurable retention: 1 day to 7 years (this is what "Keep Forever" means)
  • Default retention: As configured by user in account settings
  • Automated deletion: Daily automated process deletes messages older than user-specified retention period
  • Temporary chats: Automatically deleted after 30 days
  • After account deletion: All conversations permanently deleted within 30 days
  • Mistral search prose, raw discovery responses, and fetched page text: request-scoped only and not stored in conversation history, Beyond run records, detector telemetry, or application logs
  • Generated answer and displayed source links: follow the Customer's conversation-retention setting
  • Search counters: user identifier, UTC date, count, and update timestamp only; no query or evidence

Users control their data retention period through Settings. Configure retention to match your organization's data protection policies and legal requirements.

Security Measures

  • TLS encryption for data in transit
  • Row-level security ensures users can only access their own conversations
  • Workspace isolation prevents cross-contamination of client data
  • User authentication required for persistent conversations
  • Automated deletion of expired data
  • Latest-turn-only search-query minimization; provider-specific length/word bounds; no file, memory, workspace-context, account-identifier, or user/device-identifier transfer; credential and signed-URL rejection; personal and organization hard-off controls; Mistral-prose discard; exact-fetch restricted to provider-attested or user-submitted URLs
  • Multi-provider AI failover (Anthropic → Mistral via circuit breaker for any non-ADP traffic served by Anthropic; for the paid Fast/Think/Beyond routes defaulting to xAI via the "xAI (ZDR)" endpoint, the pre-first-token failover is Anthropic, then Mistral (EU) if Anthropic's circuit breaker is open; OpenRouter aggregator-level failover across the allowlisted providers for OpenRouter-served traffic (the Essential subset is Google Vertex and Cerebras)) for service availability without compromising the privacy bar

Processing Activity #3: Content Moderation & Safety

Purpose of Processing

To automatically detect potentially harmful, illegal, or policy-violating content in user chat messages, ensuring platform safety and compliance with legal obligations.

  • Primary: Legitimate Interest (Article 6(1)(f) GDPR) — platform safety, fraud prevention, legal compliance, and protection of users
  • Secondary: Legal Obligation (Article 6(1)(c) GDPR) — compliance with laws requiring prevention of illegal content distribution

Categories of Data Subjects

  • All platform users sending chat messages
  • Individuals mentioned in flagged messages (indirect data subjects)

Categories of Personal Data

  • User chat message content (analyzed for safety violations in real time; not stored by the moderation pipeline)
  • For flagged messages only: a moderation_events row containing the message identifier, the thread identifier, the abuse categories matched, and a timestamp. The full message content is not stored in the moderation record.

Data Processors

Moderation always runs on Mistral, regardless of Advanced Data Protection setting. This is a single-provider design choice for consistency and EU-residency safety review.

ProcessorRoleLocationRetentionTrainingMechanism
Mistral AI Moderation API (mistral-moderation-latest)Two-stage pipeline: fast classifier followed by a judge model that reviews borderline casesEU (Frankfurt)ZeroNo training (contractual)EU residency — no transfer
Supabase PostgreSQLStorage of moderation_events rows for flagged messages (metadata only — no message content)EU (Frankfurt)12 months, then automatically purgedn/aGDPR-compliant DPA

How Moderation Works

  1. Real-time analysis. Every user message is sent synchronously to the Mistral moderation API. The judge model reviews borderline cases.
  2. Event storage (flagged only). When a message is flagged, a moderation_events row is written containing only the message identifier, thread identifier, abuse categories matched, and timestamp. No message content is stored in the moderation record.
  3. Thread deletion lock (Article 17 limitation). When a thread contains a flagged message, the thread is locked from user-initiated deletion via the prevent_flagged_thread_deletion() database trigger. This is a security measure to prevent destruction of abuse evidence. Customer Content within a flagged thread is still subject to deletion on a verified Article 17 erasure request submitted to privacy@ismscopilot.com; we evaluate each such request against the legitimate-interest balancing test (Article 17(3)(e) and recital 47) and respond within 30 days.
  4. No record for non-flagged messages. No moderation row is written for messages that pass moderation; no metadata, no scores, no record.

Retention Period

  • Non-flagged messages: No moderation record stored.
  • Flagged messages: moderation_events metadata (message ID, thread ID, abuse categories, timestamp — no message content) retained for 12 months, then automatically purged.
  • After account deletion: All moderation_events rows associated with the user are deleted within 30 days, except where retention is required by law.

Security Measures

  • Synchronous moderation with two-stage classifier + judge pipeline (Mistral)
  • EU residency, zero retention by Mistral
  • Row-level security ensures moderation_events are isolated per user
  • Encrypted data transmission (TLS 1.3)
  • Database-level thread-deletion lock to prevent abuse-evidence destruction
  • Automated purge of moderation_events after 12 months

Processing Activity #4: File Upload & Document Processing

Purpose of Processing

To enable users to upload compliance documents for AI analysis, gap assessment, and document generation; and to maintain workspace files for reuse across conversations.

Primary: Contract Performance (Article 6(1)(b) GDPR) — service feature

Categories of Data Subjects

  • Platform users uploading documents
  • Individuals mentioned in uploaded documents (employees, customers, third parties)

Categories of Personal Data

  • Uploaded files (PDF, DOCX, XLSX)
  • Extracted document content and metadata
  • File names, sizes, upload timestamps
  • Document processing status
  • Workspace assignment (for files attached to a workspace)
  • File summaries (eager Mistral summarization for workspace files)
  • Potentially sensitive organizational data (policies, audit reports, risk assessments)

Uploaded documents may contain special category data (Article 9 GDPR), personal data relating to criminal convictions and offences (Article 10 GDPR), or confidential business information. Such special-category and criminal-offence data is excluded from the default (non-ADP) AI routing path: users intending to process it with AI assistance must enable Advanced Data Protection Mode, and must ensure they have a lawful basis. Storage alone remains EU-resident regardless. See DPA §4.2.

Data Processors

ProcessorRoleLocationMechanism
Supabase StorageSecure file storage (uploads bucket)EU (Frankfurt)GDPR-compliant DPA
ConvertAPIDocument format conversion (PDF/DOCX/XLSX ↔ HTML)EU endpointISO/IEC 27001:2022 (Cert No. 1512122216, valid to 2028-08-18); signed DPA with Better ISMS
Mistral AIWorkspace file summarization (eager, on upload)EU (Frankfurt)EU residency — no transfer; no training under Mistral's commercial API terms; zero retention
Fly.ioDocument conversion orchestrationEU deploymentGDPR-compliant hosting agreement

Retention Period

  • Active files: Retained according to user's data retention settings (linked to conversation retention)
  • Workspace files: Retained while the workspace exists; deleted when the workspace is deleted
  • Orphaned files: Automatically deleted via background cleanup process (excluding workspace-attached files)
  • After account deletion: All uploaded files permanently deleted within 30 days
  • ConvertAPI processing: Files processed in memory, not stored permanently by the processor

Security Measures

  • User-scoped file access (files linked to user ID via row-level security)
  • Encrypted storage at rest
  • Secure file upload over HTTPS
  • Authentication required for file upload and deletion
  • Automated orphaned-file cleanup (with workspace-aware exclusions)

Processing Activity #5: Payment & Subscription Management

Purpose of Processing

To process subscription payments, manage billing, and provide access to premium features.

  • Primary: Contract Performance (Article 6(1)(b) GDPR) — billing and payment processing
  • Secondary: Legal Obligation (Article 6(1)(c) GDPR) — tax and accounting compliance

Categories of Data Subjects

  • Premium subscribers
  • Trial users converting to paid plans
  • Billing contacts for organizational accounts

Categories of Personal Data

  • Stripe customer IDs (Paddle for UK customers)
  • Subscription IDs and status
  • Payment metadata (no full credit card numbers stored)
  • Billing events and timestamps
  • Invoice information

Data Processors

ProcessorRoleLocationMechanism
StripePayment processing, subscription management, customer portal (non-UK)Global (EU DPA); PCI DSS Level 1GDPR-compliant DPA
PaddleMerchant of Record for UK customers (HMRC VAT compliance)Global (EU DPA)GDPR-compliant DPA
SupabaseStores subscription status and customer IDs (not payment card data)EU (Frankfurt)GDPR-compliant DPA

Retention Period

  • Active subscriptions: Retained while subscription is active
  • After cancellation: Anonymized billing records retained for 7 years (tax and accounting compliance)
  • Payment card data: NEVER stored by ISMS Copilot (handled exclusively by Stripe / Paddle)

Security Measures

  • PCI DSS Level 1 compliant payment processing (via Stripe)
  • No credit card data stored in ISMS Copilot systems
  • Webhook signature verification
  • Encrypted transmission of payment data
  • Duplicate payment prevention

Processing Activity #6: Analytics & Product Improvement

Purpose of Processing

To analyze platform usage, improve user experience, identify bugs, and monitor system performance.

Primary: Legitimate Interest (Article 6(1)(f) GDPR) — product improvement and service reliability

Categories of Data Subjects

  • All platform users
  • Website visitors

Categories of Personal Data

  • User behavior events (page views, button clicks, feature usage)
  • Session data and session duration
  • Browser and device information
  • Error logs and exception data (with user UUID only — no email or content)
  • Performance metrics (page load times, interaction metrics)
  • IP addresses (anonymized)

Analytics systems are configured with sendDefaultPii: false to prevent automatic collection of personally identifiable information. No conversation content or uploaded documents are shared with analytics providers.

Data Processors

ProcessorRoleLocationMechanism
PostHogProduct analytics (cookieless mode, in-memory persistence)EU (Frankfurt)GDPR-compliant; PII protection via sendDefaultPii: false
SentryError tracking and performance monitoringGermanyGDPR-compliant; PII protection via sendDefaultPii: false
Vercel Web AnalyticsWeb vitals, performance metricsGlobal CDNGDPR-compliant

Retention Period

  • PostHog analytics: According to PostHog retention policy (typically up to 7 years, anonymized)
  • Sentry error logs: 90 days
  • Vercel analytics: According to Vercel retention policy

Security Measures

  • Anonymized IP addresses
  • No PII sent by default
  • No conversation content shared
  • EU-based analytics infrastructure
  • Production-only tracking (no development environment data)

Processing Activity #7: Infrastructure & Deployment

Purpose of Processing

To host and deliver the ISMS Copilot application securely to users.

Primary: Contract Performance (Article 6(1)(b) GDPR) — service delivery

Categories of Data Subjects

  • All platform users and visitors

Categories of Personal Data

  • HTTP request logs
  • IP addresses (temporary, for routing)
  • Connection metadata
  • Session cookies

Data Processors

ProcessorRoleLocationMechanism
VercelFrontend hosting and content deliveryGlobal CDNGDPR-compliant
Fly.ioBackend API hostingEU deploymentGDPR-compliant
AWS (via Supabase)Database and storage infrastructureFrankfurt (EU-Central-1)GDPR-compliant

Retention Period

  • Access logs: 30-90 days per infrastructure provider policies
  • Session data: Expires after user session ends

Security Measures

  • TLS 1.3 encryption for all connections
  • Content Security Policy headers
  • DDoS protection
  • Regular security updates and patches

Processing Activity #8: Email Communications & Updates

Purpose of Processing

To send legal updates, product updates, onboarding guidance, and service-related communications.

Service and onboarding email: Legitimate Interest (Article 6(1)(f) GDPR). Onboarding guidance, product education, and service or legal-update communications related to platform usage.

Marketing newsletters: Consent (Article 6(1)(a) GDPR). Product-update marketing sent only to users who have opted in; withdrawable via unsubscribe.

Scope: covers ISMS Copilot and heyGRC signups (same processors, same purpose).

Categories of Data Subjects

  • All platform users (new signups and existing users)
  • Trial users receiving onboarding sequences
  • Premium subscribers receiving product updates

Categories of Personal Data

  • Email addresses
  • Subscription preferences (legal updates, product updates)
  • Email engagement data (opens, clicks)
  • Unsubscribe status
  • Send timestamps

Data Processors

ProcessorRoleLocationMechanism
SendGrid (Twilio)Transactional and legal-update email deliveryUnited StatesSCCs
Kit (ConvertKit)Onboarding email sequences and product update emailsUnited StatesSCCs

Users can unsubscribe from product updates and onboarding emails at any time via the unsubscribe link in each email. Essential service notifications (e.g., security alerts, account changes) may still be sent as required by law or contract.

Retention Period

  • Active subscriptions: Retained while user remains subscribed
  • After unsubscribe: Email removed from mailing lists immediately
  • Engagement data: Retained according to email service provider policies (typically up to 2 years)
  • After account deletion: All email preferences and data removed within 30 days

Security Measures

  • Encrypted email transmission (TLS)
  • Secure API connections to email providers
  • One-click unsubscribe functionality
  • Email authentication (SPF, DKIM, DMARC)
  • Bounce and complaint handling

Processing Activity #9: Token Consumption Tracking & Usage Monitoring

Purpose of Processing

To track AI token consumption for billing, quota management, and service optimization.

  • Primary: Contract Performance (Article 6(1)(b) GDPR) — necessary to enforce usage quotas
  • Secondary: Legitimate Interest (Article 6(1)(f) GDPR) — service optimization and cost management

Categories of Data Subjects

  • All platform users with active subscriptions

Categories of Personal Data

  • User ID
  • Token consumption counts per conversation
  • AI provider used (anthropic, mistral, openrouter)
  • Timestamps of usage
  • Subscription plan tier

Data Processors

ProcessorRoleLocationMechanism
Supabase PostgreSQLStorage of token usage metricsEU (Frankfurt)GDPR-compliant DPA
Fly.ioToken calculation and aggregationEU deploymentGDPR-compliant

Retention Period

  • Active subscriptions: Retained for duration of subscription
  • After subscription cancellation: Retained for 90 days for billing dispute resolution
  • After account deletion: Anonymized within 30 days

Security Measures

  • Aggregated metrics only (no message content stored)
  • Row-level security in database
  • Encrypted data transmission and storage
  • Access limited to billing and support functions

Processing Activity #10: Slack Bot Integration (heygrc)

Purpose of Processing

To allow paid Customers to interact with the ISMS Copilot AI compliance assistant from inside their Slack workspace via the heygrc bot — direct messages to the bot or @heygrc channel mentions.

  • Primary: Contract Performance (Article 6(1)(b) GDPR) — optional integration the Customer's organization owner explicitly installs to extend the contracted service into Slack
  • Secondary: Legitimate Interest (Article 6(1)(f) GDPR) — for the OAuth audit trail (recording which organization owner installed the integration)

Categories of Data Subjects

  • The organization owner who performs the install (their ISMS Copilot user ID is recorded for audit)
  • Members of the Customer's Slack workspace who interact with the bot. These users typically do not hold an ISMS Copilot account; their messages addressed to the bot are processed under the installing Customer's organization. The Customer is responsible for informing its Slack workspace users that messages addressed to the bot are processed by ISMS Copilot.

Categories of Personal Data

  • Slack workspace metadata captured during OAuth: workspace (team) ID, workspace name, bot user ID
  • OAuth bot token issued by Slack
  • ISMS Copilot user ID of the installer (audit trail)
  • Slack message content of messages addressed to the bot — DMs to heygrc or @heygrc channel mentions only. Other workspace messages are not read.
  • Slack user identifiers (slack_user_id) of users who interact with the bot, recorded in the slack_threads mapping table

Data Processors

ProcessorRoleLocationMechanism
Slack Technologies, Inc.Originates OAuth handshake and message events; receives AI response posts back to the workspaceUnited StatesSCCs
Supabase PostgreSQLStores slack_integrations (workspace metadata), slack_integration_secrets (bot token, service-role-only RLS), slack_threads (Slack-thread ↔ ISMS-thread mapping). Conversation content lands in the main messages and threads tables.EU (Frankfurt)GDPR-compliant DPA
Fly.ioHosts the slack-bot service that handles inbound Slack events, signing-secret verification, retry deduplication, and outbound response postsEU deploymentGDPR-compliant
Mistral AIContent moderation of Slack-originated messages (same pipeline as web chat)EU (Frankfurt)EU residency — no transfer; no-training; zero retention
Anthropic ClaudeAI processing for Slack-originated messages from any non-ADP organization (ADP off); Slack routing follows the same unified non-ADP envelope as web chat (for paid organizations, Plus and above, the Fast and Think modes and Beyond default to xAI via OpenRouter's "xAI (ZDR)" endpoint with Anthropic as the automatic pre-first-token failover; otherwise Anthropic or the OpenRouter allowlist; the Essential-plan subset is Google Vertex + Cerebras). See the AI Processing routing matrix.United StatesSCCs; no training under Anthropic's commercial API terms; retention under Anthropic's standard commercial API terms (ordinary ~30-day deletion; safety-flagged content up to 2 years; safety-classification scores up to 7 years; not training); customers needing zero retention can enable ADP at the org level
Mistral AI (also)AI processing for Slack-originated messages when ADP is enabled at the org levelEU (Frankfurt)EU residency — no transfer

How the Integration Works

  1. Install (paid orgs only). An ISMS Copilot organization owner clicks "Add to Slack" on the Connectors page. The OAuth callback verifies the installer is (a) authenticated as an org owner, and (b) on a paid plan; free / null-plan organizations are rejected with a paid_plan_required error. The OAuth scope is bot-only — we do not request the workspace user directory, channel history, or file access.
  2. Inbound message. Slack sends DMs to the bot or @heygrc mentions to a Fly.io endpoint. The signing secret is verified, retries are deduplicated, and the message is routed through the same chat API as web users (with X-Internal-Auth and X-Slack-User-Id headers in place of a JWT).
  3. Routing. selectChatModel(adpEnabled, userPlan) runs against the organization owner's ADP setting and plan — Slack workspace users inherit the org's settings; a Slack user cannot select their own routing.
  4. Moderation. Slack-originated messages run through the same Mistral moderation pipeline as web chat (always Mistral, regardless of ADP).
  5. Response post-back. The AI response is read from the messages table and posted back to the originating Slack channel/DM via the Slack Web API.

Retention Period

  • Slack integration records (slack_integrations, slack_integration_secrets, slack_threads): retained while the integration is active; hard-deleted within seconds of uninstall (the app_uninstalled event handler cascades a DELETE FROM slack_integrations which removes the secret and thread mappings).
  • Conversation content (Slack-originated messages and AI responses, stored in the main messages and threads tables): retained per the Customer's account-level retention setting (1 day to 7 years, or "keep forever"). Uninstall does not delete conversation content because it belongs to the Customer's organization, but the link from a Slack thread back to a specific Slack workspace user is severed (the slack_threads row is deleted).
  • After account deletion: all Slack-related records are deleted within 30 days alongside the rest of the Customer's data.

Security Measures

  • Slack signing-secret verification on every inbound event
  • Retry deduplication via context.retryNum
  • Bot tokens stored in an isolated slack_integration_secrets table with service-role-only Row-Level Security; never exposed to authenticated org members via UI or API. Encryption at rest is provided by the database infrastructure layer; an application-level pgcrypto encryption layer is a tracked follow-up.
  • OAuth scope is bot-only; no workspace user-directory or file scope is requested
  • Install gated to paid org owners only (callback verifies plan + ownership before issuing bot token)
  • Hard-delete on uninstall via app_uninstalled event handler — no soft-delete or archive

Processing Activity #11: Logged-out Risk-Analysis Demo (Public Marketing)

Purpose of Processing

To provide a public, logged-out marketing demonstration at /iso-27001-risk-analysis: a visitor enters a company name or URL, and the service generates an illustrative ISO 27001 risk register from public information, saved behind an unguessable shareable link for 7 days. The goal is product demonstration and lead generation. It is decoupled and isolated from the authenticated product: there is no account and no login, and it does not process authenticated Customer Content. Because the input field accepts free text, visitor-supplied content may incidentally include personal data (for example a sole trader's or eponymous business's name), which is handled under the legal basis and 7-day retention stated here.

  • Legitimate Interest (Article 6(1)(f) GDPR): demonstrating the product to prospective customers. The processing is limited to public business information the visitor chooses to submit, is transient (7-day retention), does not profile the visitor, and offers an easy erasure route.

Categories of Data Subjects

  • Website visitors running the demo. No account is created; a salted hash of the visitor's IP is used transiently for rate limiting and is not linked to a stored run.
  • Individuals named in the public information about the subject company (for a sole trader or eponymous small business, the company name/URL and public-site content may reference a natural person).

Categories of Personal Data

  • Visitor-supplied company name or URL (max 100 characters)
  • Public information about the subject company (a web-search result set and an extract of the company's own public website)
  • A salted hash of the visitor's IP address (rate limiting only; the raw IP is not stored; not linked to a run)
  • The generated illustrative risk analysis

Data Processors

ProcessorRoleLocationMechanism
Mistral AIWeb search and research synthesis (a grounded factual profile of the subject company)EU (Frankfurt)EU residency, no transfer; no training; zero retention
xAI (Grok)Generates the illustrative ISO 27001 risk register from the research. Routed via OpenRouter, pinned in code to the "xAI (ZDR)" zero-data-retention endpoint (zdr: true). Designed to process visitor-supplied company identifiers and public-web research and isolated from authenticated Customer Content; because the input field accepts free text, visitor-supplied content may incidentally contain personal data (for example for a sole trader or an eponymous business), which is covered by the demo's legal basis and 7-day retention aboveUnited States (OpenRouter-published provider footprint; per-request inference region not pinned via OpenRouter)SCCs at the underlying-provider layer via xAI's published DPA with OpenRouter Article 28(4) flow-down; no training; zero data retention ("xAI (ZDR)" endpoint)
Supabase PostgreSQLStores the demo run (input, resolved company, generated analysis) behind an unguessable share token for 7 daysEU (Frankfurt)GDPR-compliant DPA
Fly.ioHosts the demo backend and performs the SSRF-safe fetch of the company's own public websiteEU deploymentGDPR-compliant

Retention Period

  • Demo runs are stored for 7 days behind an unguessable share token, then deleted automatically by the cleanup_demo_data cron. A visitor may request earlier erasure via privacy@ismscopilot.com (see Data Subject Rights).
  • The salted IP-rate-limit hash is transient and not linked to a stored run.
  • No retention at the AI providers: Mistral (zero retention) and xAI (zero-data-retention endpoint).

Security Measures

  • No account, no tracking cookies, and no visitor identifiers beyond a transient salted IP hash
  • Isolated database tables (demo_runs plus separate rate-limit tables) with deny-by-default Row-Level Security; never the authenticated product's tables
  • Unguessable crypto-random share token; per-IP and global rate limits; input denylist
  • SSRF-safe server-side site fetch (https and port 443 only, with TLS validation against the requested host)
  • xAI Grok call pinned to a zero-data-retention endpoint in code
  • noindex on the demo page and on shared runs

Data Subject Rights Implementation

ISMS Copilot supports all GDPR data subject rights through both in-product self-service features (in Settings → Data Protection) and an email-mediated path for cases requiring evaluation.

Right to Access (Article 15)

  • Self-service: View all conversations and files through the platform interface; request a complete data export in JSON format via Settings → Data Protection (available to all plans)
  • Response time: Self-service is immediate; export typically delivered within 72 hours

Right to Rectification (Article 16)

  • Self-service: Update settings through the Settings dialog
  • Email-mediated: privacy@ismscopilot.com for email address changes
  • Response time: Immediate for self-service; within 30 days for email-mediated

Right to Erasure (Article 17)

  • Self-service: Account deletion via Settings → Data Protection (available to all plans)
  • Email-mediated: privacy@ismscopilot.com for deletion of specific Customer Content within a flagged thread (per Activity #3 — moderation thread-deletion lock); we evaluate each such request against the legitimate-interest balancing test (Article 17(3)(e), recital 47) and respond within 30 days
  • Scope: All personal data, conversations, files, and settings (subject to the moderation retention exception in Activity #3 and to anonymized billing records retained for 7 years per Activity #5)
  • Timeline: Permanent deletion within 30 days

Right to Data Portability (Article 20)

  • Format: JSON export including all user data
  • Self-service: Settings → Data Protection
  • Response time: Typically within 72 hours

Right to Restrict Processing (Article 18)

Right to Object (Article 21)

Right to Lodge a Complaint

You have the right to file a complaint with a supervisory authority:

Commission Nationale de l'Informatique et des Libertés (CNIL) — Website: https://www.cnil.fr/en — Address: 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — Phone: +33 1 53 73 22 22


Data Breach Notification Procedures

Detection & Assessment

  • Continuous monitoring via Sentry error tracking
  • Security incident review within 24 hours of detection
  • Risk assessment for potential data breach impact

Notification Timeline

  • To Supervisory Authority (CNIL): Within 72 hours of becoming aware (Article 33)
  • To Data Subjects: Without undue delay if high risk to rights and freedoms (Article 34)

Notification Contents

  • Nature of the breach
  • Categories and approximate number of data subjects affected
  • Likely consequences
  • Measures taken or proposed to address the breach

International Data Transfers

Whether data is transferred outside the EU depends on the Customer's Advanced Data Protection Mode setting and (for AI processing) on subscription plan.

When Advanced Data Protection is ON (any plan)

Core data processing occurs within the European Union.

ComponentLocationTransfer?
Database storageEU (Frankfurt, Germany)None
AI processingEU (Mistral AI, Frankfurt)None
Content moderationEU (Mistral AI)None
File conversionEU endpoint (ConvertAPI)None
Workspace file summarizationEU (Mistral AI)None
AnalyticsEU endpoints (PostHog EU, Sentry Germany)None
Email communicationsUnited States (SendGrid, Kit)SCCs
Authenticated web searchUnavailable under ADP: it fails closed. Only exact user-selected page/document fetch through EU Fly remains available, followed by Mistral EU AI processingNone. Authenticated web search is disabled under ADP because Mistral web search is not EU-only and not zero-retention (it runs on Mistral's stateful endpoint and uses Brave (US) as sub-processor). Exact user-selected fetch: outbound request metadata reaches the user-selected public host from the EU fetcher only.
Exact user-supplied URL fetchEU (Fly.io) plus the user-selected public hostNo search-provider transfer; outbound request metadata reaches the host selected by the user

When Advanced Data Protection is OFF (default)

ComponentLocationMechanism
Database storageEU (Frankfurt, Germany)None — EU residency
AI processing for any non-ADP planUnited States (Anthropic Claude) or United States, Sweden (EU) (Inceptron), or Netherlands / Finland (EU) (Nebius) (OpenRouter allowlist; the non-PRC / EU posture of the underlying providers is a default deployment posture, not contractual EU residency; inference region not pinnable via OpenRouter). For paid plans (Plus and above) in the Fast and Think modes and the Beyond assistant the current default is xAI (Grok) via the "xAI (ZDR)" endpoint (United States), with Anthropic as the automatic pre-first-token failover; in any chat mode ISMS Copilot may serve a non-ADP paid request via any of the eight allowlisted underlying providers or Anthropic and may move any cohort or mode between these destinations over time (control-neutral under DPA §2.4, publication-only)For Anthropic-served traffic: SCCs; no training under Anthropic's commercial API terms; retention under Anthropic's standard commercial API terms (ordinary ~30-day deletion; safety-flagged content up to 2 years; safety-classification scores up to 7 years; not training). For OpenRouter-served traffic: routes to one of the eight allowlisted underlying providers (the seven glm-4.7 hosts plus xAI via the "xAI (ZDR)" endpoint, xAI being the paid Fast/Think/Beyond default); SCCs; EU-US Data Privacy Framework certification for Google Vertex; OpenRouter account-level controls (mandatory ZDR, training-disallowed, publication-disallowed, closed eight-provider allowlist, PRC-jurisdiction blocklist) act as the enforcement layer; zero retention (no persistent retention beyond serving the request; transient in-memory caching only). Contractual EU-only residency is provided by ADP (Mistral), which any customer can enable including organization-wide
AI processing for Essential usersUnited States. OpenRouter aggregator restricted to a closed two-provider subset (Google Vertex, Cerebras)SCCs; EU-US Data Privacy Framework certification for Google Vertex; OpenRouter account-level controls (mandatory ZDR, training-disallowed, publication-disallowed, PRC-jurisdiction blocklist) act as the enforcement layer; enable ADP for EU-only (Mistral) routing
AI processing, free / null-plan usersUnited States, or EU for the EU-based hosts (Inceptron in Sweden, Nebius in Netherlands); OpenRouter aggregator routing to one of seven allowlisted underlying providers (Inceptron, DeepInfra, Cerebras, Google Vertex, Together AI, Fireworks AI, Nebius); inference region not pinnable via OpenRouterSCCs; EU-US Data Privacy Framework certification for Google Vertex; EU residency available via Nebius; OpenRouter account-level controls (mandatory ZDR, training-disallowed, publication-disallowed, closed eight-provider allowlist, PRC-jurisdiction blocklist) act as the enforcement layer
Content moderationEU (Mistral AI — always, regardless of ADP)None
File conversionEU endpoint (ConvertAPI)None
Workspace file summarizationEU (Mistral AI)None
AnalyticsEU endpoints (PostHog EU, Sentry Germany)None
Email communicationsUnited States (SendGrid, Kit)SCCs
Authenticated web search at launchWith ADP off: Mistral AI (EU) plus Brave (US) as Mistral's own web-search sub-processor, EU Fly.io, selected public source hosts, and the already applicable answer provider. With ADP on: web search fails closed; only exact user-selected page/document fetch through EU FlyMistral discovers attested URLs; its prose is discarded; Fly exact-fetches the pages and supplies bounded labeled evidence to the existing answer/Beyond model. No additional semantic grounding model receives the draft. The discovery hop is a US transfer reached via Mistral: Mistral web search runs on Mistral's stateful endpoint (outside its zero-retention posture) and Mistral engages Brave (US, SCCs; standard, non-zero retention per the applicable Mistral/Brave provider terms; Brave DPA excludes Search Query Data from processor scope). ISMS Copilot does not separately engage Brave for this launch route.
Future Brave-direct search route (not before 2026-08-12; pending and dark; distinct from Brave's launch role as Mistral's sub-processor above)United States (Brave Search API)Not active. If later approved, a route in which ISMS Copilot calls the Brave API itself: minimized latest-request query only; SCCs; standard query logs up to 90 days; Brave DPA excludes Search Query Data from processor scope. Personal and organization hard-offs would prevent the transfer.
Exact user-supplied URL fetchEU (Fly.io) plus the user-selected public hostOutbound request metadata reaches the host selected by the user; fetched text is request-scoped and not persisted as raw evidence

Supplementary Measures (Schrems II compliance)

For all transfers outside the EU:

  • TLS 1.3 encryption for data in transit
  • Customer ability to control transfer destination via Advanced Data Protection Mode
  • Authenticated-search minimization: latest user request only, strict query bounds, no files/memories/workspace context/account or device identifiers, credential and signed-URL rejection, personal/organization hard-offs, Mistral-prose discard, and exact-fetch of only attested/submitted URLs

For paid-tier transfers: the current default for paid (Plus and above) Fast/Think/Beyond is xAI (Grok) via the OpenRouter "xAI (ZDR)" endpoint (zero data retention; no training via the OpenRouter account training-disallowed setting layered on xAI's published API no-training default; SCCs at the underlying-provider layer via xAI's published DPA with OpenRouter Article 28(4) flow-down), with Anthropic as the automatic failover; in any chat mode a paid request may be served by any of the eight allowlisted underlying providers or Anthropic (control-neutral moves within the disclosed envelope under DPA §2.4). When Anthropic serves a paid request: no training on Customer Content under Anthropic's commercial API terms; retention under Anthropic's standard commercial API terms (ordinary ~30-day deletion; safety-flagged content up to 2 years; safety-classification scores up to 7 years; not training); customers needing zero retention can enable ADP for Mistral routing.

For free-tier / Essential (OpenRouter, the seven glm-4.7 hosts) transfers:

  • OpenRouter account-level controls applied to every request: mandatory Zero Data Retention (no persistent retention beyond serving the request; a provider may hold content transiently in memory for the duration of processing); Free Training Disallowed + Paid Training Disallowed; Free Publication Disallowed
  • Closed eight-provider allowlist (the seven glm-4.7 hosts, Inceptron, DeepInfra, Cerebras, Google Vertex, Together AI, Fireworks AI, Nebius, plus xAI via the "xAI (ZDR)" endpoint for the Grok models; the seven glm-4.7 hosts were expanded from 4 to 7 on 2026-05-25, and xAI was activated for paid Customer-Content on 2026-07-21)
  • PRC-jurisdiction blocklist (Alibaba Cloud Int., Baidu Qianfan, DeepSeek, Moonshot AI, Xiaomi, Z.AI all blocked) — a Schrems II-style jurisdiction-based supplementary measure aligned with EDPB Recommendations 01/2020
  • Each underlying provider independently confirms zero retention or no-training-on-customer-data in their published policies

A complete Transfer Impact Assessment (TIA) covering US-based sub-processors is available on request via privacy@ismscopilot.com.

Organizations subject to strict EU data residency requirements should enable Advanced Data Protection Mode to eliminate AI processing transfers and simplify Transfer Impact Assessment obligations.


Sub-Processor List

Active Sub-Processors

Sub-processorPurposeLocationRetentionDPA / Transfer mechanism
Supabase (PostgreSQL + Storage)Database and file storageEU (Frankfurt)User-controlledGDPR-compliant DPA
AWS (via Supabase)Underlying infrastructureEU (Frankfurt, EU-Central-1)n/aGDPR-compliant
Anthropic ClaudeAI processing for any non-ADP plan (ADP off), as one of the permitted non-ADP providers and the circuit-breaker failover context (a non-ADP request may instead be served by the OpenRouter allowlist for any chat mode). For paid plans (Plus and above) in the Fast and Think modes and the Beyond assistant, Anthropic is the automatic pre-first-token failover (Opus for Think, Sonnet for Fast) behind the xAI "xAI (ZDR)" default, not the default destinationUnited StatesStandard Anthropic commercial API terms (ordinary ~30-day deletion; safety-flagged content up to 2 years; safety-classification scores up to 7 years; not training); customers needing zero retention can enable ADPSCCs; no training under Anthropic's commercial API terms
OpenRouter (routing aggregator)AI processing for the Essential plan with ADP off (closed subset: Google Vertex, Cerebras); for free / null-plan users with ADP off (one of the seven allowlisted glm-4.7 underlying providers below); and for paid plans (Plus, Standard, Pro, Business) with ADP off, where xAI via the "xAI (ZDR)" endpoint is the current default destination for the Fast and Think modes and the Beyond assistant (Anthropic retained as the automatic pre-first-token failover) and, in any chat mode, a non-ADP paid request may be routed across the eight allowlisted underlying providers below (including xAI) or Anthropic, with cohorts or modes moved between these destinations over time (control-neutral under DPA §2.4, publication-only)United StatesZero (mandatory at account level)OpenRouter's role is account-level enforcement (mandatory ZDR, training-disallowed, allowlist, PRC-blocklist); legal transfer mechanism for data leaving the EU is anchored at the underlying-provider rows below
Inceptron (Inceptron AB)OpenRouter underlying provider (allowlisted)Sweden (EU)Zero (enforced via OR account config)SCCs (inference region not pinnable)
DeepInfraOpenRouter underlying provider (allowlisted)United StatesZero (enforced via OR account config)SCCs
CerebrasOpenRouter underlying provider (allowlisted)United StatesZero (enforced via OR account config)SCCs
Google VertexOpenRouter underlying provider (allowlisted)United StatesZero (enforced via OR account config)SCCs + EU-US Data Privacy Framework
Together AIOpenRouter underlying provider (allowlisted, added 2026-05-25)United States — default routing to North America data centers per Together docs (per-request region pinning not exposed by OpenRouter aggregator)Zero (enforced via OR account config)SCCs; SOC 2 Type II; published DPA
Fireworks AIOpenRouter underlying provider (allowlisted, added 2026-05-25)United States: multi-region fleet (US, EU Frankfurt + Iceland, APAC Tokyo only); no PRC or Hong Kong infrastructure identified in Fireworks' published deployment docs (per-request region pinning not exposed by OpenRouter aggregator)Zero (enforced via OR account config)SCCs; SOC 2 Type II; published DPA
NebiusOpenRouter underlying provider (allowlisted, added 2026-05-25)Netherlands HQ; primary inference in Finland (EU) with US secondary per Nebius docs (per-request region pinning not exposed by OpenRouter aggregator; EU residency is the published default but not contractually guaranteed via OR)Zero (enforced via OR account config)SCCs; published DPA + sub-processor list
xAI (X.AI LLC), "xAI (ZDR)" endpoint, Grok modelsOpenRouter underlying provider (allowlisted); default destination for paid plans (Plus and above), ADP off, for the chat Fast and Think modes and the Beyond assistant, replacing the prior Anthropic default (Anthropic retained as the pre-first-token failover)United States (OpenRouter-published provider footprint; per-request inference region not pinned via OpenRouter)Zero data retention as configured and verified 2026-07-19 (OpenRouter account-level ZDR, "xAI (ZDR)" endpoint)SCCs at the underlying-provider layer via xAI's published DPA (EU SCCs, Modules 2/3, Irish-law) with OpenRouter Article 28(4) flow-down; no-training per OpenRouter account-level training-disallowed + xAI's published API no-training default
Mistral AIAI processing for ADP users (any plan); circuit-breaker failover destination for paid Anthropic; content moderation for all users (always); conversation compaction; workspace file summarization; search-intent classification; and web-search source-URL discovery for eligible non-ADP authenticated search (now live in production)EU (Frankfurt) for inference, moderation, and summarization. For ADP-off web-search discovery, Mistral runs on its stateful endpoint (outside zero-retention) and engages Brave (US) as Mistral's own web-search sub-processor; ISMS Copilot does not separately engage BraveZero for inference/moderation/summarization; web-search discovery is non-zero-retention (reached via Brave, US) per the applicable Mistral/Brave provider termsEU residency for inference/moderation; no training under Mistral's commercial API terms. Via Mistral's web-search chain the query reaches Brave (US) under SCCs; see the sub-processor chain transparency note under Activity #2
StripePayment processing (non-UK)Global (EU DPA)7 years (anonymized)GDPR-compliant DPA; PCI DSS Level 1
PaddleMerchant of Record for UK customersGlobal (EU DPA)7 years (anonymized)GDPR-compliant DPA
ConvertAPIDocument format conversionEU endpointTemporary (in-memory)ISO 27001:2022; signed DPA
PostHogProduct analyticsEU (Frankfurt)Up to 7 years (anonymized)GDPR-compliant
SentryError monitoringGermany90 daysGDPR-compliant
VercelFrontend hostingGlobal CDN30-90 daysGDPR-compliant
Fly.ioBackend API hostingEU deployment30-90 daysGDPR-compliant
SendGrid (Twilio)Transactional + legal-update emailsUnited StatesUp to 2 yearsSCCs
Kit (ConvertKit)Onboarding + product update emailsUnited StatesUp to 2 yearsSCCs

Every "Zero" in the OpenRouter provider rows above is the account-level Zero Data Retention defined in the OpenRouter account-controls section: no persistent retention beyond serving the request; a provider may hold content transiently in memory for the duration of processing, as is inherent to inference.

Notified External Search Recipient: future Brave-direct route (Pending Activation)

This is a distinct route from Brave's launch role as Mistral's web-search sub-processor (listed in the Active Sub-Processors table above). Here ISMS Copilot would call the Brave Search API itself rather than reaching Brave via Mistral.

RecipientPurposeEarliest activationLocationRetentionContract / transfer posture
Brave Software, Inc.Future direct non-ADP authenticated web-search candidate (ISMS Copilot calling the Brave API itself) using a bounded latest-request query; no files, memories, workspace context, account identifiers, or user/device identifiers. This direct route is not constructed or called by the Mistral launch route.2026-08-12 at the earliest, subject to at least 30 days' actual notice and founder contractual acceptanceUnited States (AWS infrastructure)Standard query logs up to 90 daysSCCs; Brave's DPA excludes Search Query Data from processor scope, so Brave is disclosed as a limited recipient and not represented as an Article 28 processor for this processing

Customer-Activated Integrations

The following sub-processors only become active for a Customer's data when that Customer's authorized administrator (e.g., an organization owner) explicitly enables an optional integration in-product. No Customer Personal Data flows to the sub-processor unless and until that step occurs. The 30-day advance-notification rule for Active Sub-Processors does not apply to Customer-Activated Integrations because activation requires explicit Customer-side action; see DPA §2.4.

Sub-processorPurposeActivated byLocationRetentionDPA / Transfer mechanism
Slack Technologies, Inc.Optional heygrc Slack bot integration: OAuth handshake, inbound message events to the bot, outbound AI response postsPaid-organization owner installs from the Connectors page; OAuth callback rejects free / null-plan installs with a paid_plan_required error. Hard-deleted on uninstall.United StatesActive while integration is installedSCCs

Reserved Sub-Processors (code paths exist; not invoked in current production)

Sub-processorCode path purposeStatus
OpenAIDirect OpenAI API pathReserved — not invoked from any current user-facing flow
X.AI (Grok)Direct X.AI API pathReserved — not invoked from any current user-facing flow
Google GeminiDirect Gemini API pathReserved — not invoked from any current user-facing flow

Activation of any Reserved sub-processor for live processing of user data requires customer notice (30 days advance) under the change-of-sub-processor procedure before any user data is processed.

Sub-Processor Change Procedure

Materially adverse changes. ISMS Copilot will notify users at least 30 days in advance, by email and in-app announcement, before a materially adverse change to its sub-processor framework, including adding a new Active sub-processor, replacing an existing one, or activating a Reserved sub-processor for live processing, where that change is materially adverse as defined in DPA §2.4. A change is materially adverse where it materially weakens the applicable retention, training, publication, security, transfer, or residency controls, introduces a new category of Customer Personal Data processed, or introduces a materially different jurisdiction or transfer-risk posture.

Control-neutral changes. For control-neutral sub-processor changes, ISMS Copilot may provide notice by publishing the change in the Trust Center and the customer-facing change log, without an advance notice period, consistent with DPA §2.4. A control-neutral change is one that does not materially weaken the applicable retention, training, publication, security, transfer, or jurisdiction controls and does not expand the categories of Customer Personal Data processed, including adding or substituting a vetted destination within the closed OpenRouter allowlist, or moving a cohort or mode between already-disclosed destinations, where every permitted destination is equal to or stronger than the path it supplements or replaces on retention, training, and jurisdiction, and the Advanced Data Protection (Mistral, EU, zero-retention) guarantee remains available to suppress the OpenRouter path entirely.

Notifications of materially adverse changes are sent via email and in-app announcement. For any change, users may exercise the in-product alternative (enabling Advanced Data Protection Mode, which routes all AI processing to Mistral AI in Frankfurt regardless of plan) and may object on reasonable data-protection grounds, during the stated notice period or, for a control-neutral change published without an advance notice period, at any time, via privacy@ismscopilot.com. Where a contract grants formal sub-processor objection rights and the objection cannot be resolved, the user may terminate the affected service without penalty.

The 30-day advance-notification rule does not apply to Customer-Activated Integrations (see above) because no Customer Personal Data flows to those sub-processors unless and until the Customer's organization owner takes an explicit installation step. New Customer-Activated Integrations are documented in the table above and announced through normal product-update channels.


Technical & Organizational Measures (TOMs)

Access Control

  • Row-level security in database
  • User authentication required for all protected resources
  • Workspace isolation preventing cross-user data access
  • MFA available for enhanced account security
  • Session timeout controls

Encryption

  • TLS 1.3 for data in transit
  • Database encryption at rest
  • Password hashing (irreversible)
  • Encrypted file storage

Data Minimization

  • Only essential data collected (email, messages, files)
  • No unnecessary demographic or contact information
  • Analytics configured to exclude PII
  • User-controlled retention periods

Availability & Resilience

  • Automated database backups
  • Disaster recovery procedures
  • 24/7 monitoring and alerting via Sentry
  • Real-time uptime monitoring via BetterStack with progressive incident escalation (Slack, email, SMS)
  • Public status page for transparency (status.ismscopilot.com)
  • Multi-provider AI failover (Anthropic → Mistral via circuit breaker for any non-ADP traffic served by Anthropic; for the paid Fast/Think/Beyond routes defaulting to xAI via the "xAI (ZDR)" endpoint, the pre-first-token failover is Anthropic, then Mistral (EU) if Anthropic's circuit breaker is open; OpenRouter aggregator-level failover across the allowlisted providers for OpenRouter-served traffic (the Essential subset is Google Vertex and Cerebras))

Testing & Evaluation

  • Regular security assessments
  • Continuous error monitoring and logging
  • Automated data deletion testing
  • Access control verification
  • OpenRouter account-config evidence: documented in this RoPA and demonstrable via live dashboard walkthrough on customer request; ad-hoc capture on material change (configuration-integrity caveat — see "AI Routing — Foundational Concepts")

User Responsibilities

While ISMS Copilot provides GDPR-compliant infrastructure, users (as data controllers) are responsible for ensuring their use of the platform complies with GDPR and other applicable regulations.

As a data controller, users must:

  • Ensure legal basis exists before uploading personal data
  • Configure appropriate data retention periods for their organization
  • Maintain separate workspaces for different clients or data categories
  • Inform individuals when their data is processed through ISMS Copilot
  • Include ISMS Copilot in their own data processing records
  • Conduct Data Protection Impact Assessments (DPIA) when processing high-risk data
  • Enable Advanced Data Protection Mode before processing special category data (Article 9 GDPR) or criminal-offence data (Article 10 GDPR) with AI features, as such data is excluded from the default (non-ADP) AI routing path

Compliance Documentation

Available Compliance Resources

Record Maintenance

  • Quarterly review — verify accuracy of processing activities; confirm OpenRouter account-config still matches the configuration described in this RoPA (live dashboard check; ad-hoc screenshot only on material change)
  • Change-driven updates - the RoPA is updated within 30 days of a new sub-processor activation or a new processing activity. Customer notice follows the sub-processor change procedure above: at least 30 days' advance notice by email and in-app announcement for a materially adverse change, and notice by publication in the Trust Center and the customer-facing change log, without an advance notice period, for a control-neutral change, each as defined in DPA §2.4.
  • Annual audit — comprehensive review of all RoPA entries
  • Version control — dated revisions maintained for audit trail

Contact Information

  • Privacy & GDPR requests: privacy@ismscopilot.com (include "GDPR Request" in the subject line for priority handling)
  • Data Protection Officer: ISMS Copilot has not designated a DPO as we do not meet the mandatory designation criteria under GDPR Article 37. For data protection inquiries, contact privacy@ismscopilot.com.
  • Supervisory Authority: Commission Nationale de l'Informatique et des Libertés (CNIL) — https://www.cnil.fr/en