Your data, hosted in Ireland
Your firm’s AML records are among the most sensitive data you hold. This page sets out plainly where that data lives, how it is protected, who processes it, and what happens when the retention clock runs out. No vague assurances — just the specifics EU buyers are right to ask for.
Hosted in the EU, from the database up
CompliDesk Ireland runs on its own EU infrastructure, fully separate from our Australian deployment. Your customer and KYC data resides in the EU.
Supabase · AWS eu-west-1 (Dublin)
Database & storage
Your client files, CDD records and screening evidence live in Supabase, hosted on AWS eu-west-1 in Dublin. Database and file storage sit in the same EU region.
Vercel
Website delivery
The website and application are delivered through Vercel. Hosting is configured for the Ireland deployment as its own isolated project and environment.
Ireland deployment · EU region
EU-resident by design
CompliDesk Ireland customer data stays in the EU. That is an architectural decision — a separate EU deployment — not a checkbox on a shared system.
Concrete measures, honestly stated
These are the controls actually in place — not aspirations.
Encryption in transit
All traffic between your browser and CompliDesk is encrypted with TLS. There is no unencrypted access to the platform.
Encryption at rest
The database and file storage holding your client records are encrypted at rest.
Row-level security
Access control is enforced inside the database itself. Row-level security policies mean one firm’s records are never queryable by another firm.
Role-based access
Access within your firm is governed by roles, so staff see what their role requires — and your audit trail records who did what.
Least-privilege service keys
Backend services run on scoped, least-privilege keys. No component holds broader access to your data than its job requires.
No scripts without consent
No analytics or marketing scripts load until you consent. Non-essential cookies are blocked by default, with granular preferences.
What we don’t claim
We do not currently hold SOC 2 or ISO 27001 certification, and we won’t pretend otherwise. What you get instead is this page: a specific, truthful account of our controls. If your firm runs vendor security questionnaires, we’ll answer them directly — admin@complidesk.com.au.
Clear roles, written down
GDPR compliance starts with knowing who is responsible for what. Here is how the roles fall.
You are the controller. We are the processor.
For personal data your firm holds on the platform — client identities, CDD records, screening results — your firm is the controller and CompliDesk is the processor. An Article 28 Data Processing Agreement is available and forms part of our terms. Read the DPA.
Breach notification
If a personal data breach occurs, we notify affected customers without undue delay so you can meet your own obligations under Articles 33 and 34 GDPR — notification to the supervisory authority and, where required, to data subjects.
Data subject rights
Access, rectification, erasure and the other GDPR data subject rights are honoured. As processor, we support your firm in responding to requests from your clients. Details are in our Privacy Policy.
Who processes data on our behalf
We keep the list short and public. Each provider is engaged under processor terms, and services marked for launch are engaged as the platform goes live.
| Sub-processor | Role | Status / region |
|---|---|---|
| Supabase | Database and file storage | EU region — AWS eu-west-1 (Dublin) |
| Vercel | Website and application hosting | Active |
| Stripe | Payment processing | From paid launch |
| Resend | Transactional email | From platform launch |
| Didit | KYC / KYB identity verification | Active at platform launch |
| Anthropic | AI analysis of screening results | Active at platform launch |
| Zoho | CRM and email campaigns | Active |
Keep for five years. Then delete.
Regulation (EU) 2024/1624 (AMLR) requires obliged entities to retain records for five years — and then delete them. Most software treats deletion as an afterthought. CompliDesk treats it as a feature: record retention with 5-years-then-delete is built into the product, so your firm can meet both halves of the duty without a manual clean-up exercise.
The same discipline serves GDPR storage limitation: data your firm no longer has a legal basis to hold shouldn’t sit in a database indefinitely.
How it works in the product
Retention periods tracked against each record
Deletion when the retention period ends
Audit trail of retention and deletion actions
Found something? Tell us.
If you believe you’ve found a security vulnerability in CompliDesk, we want to hear about it. Email admin@complidesk.com.au with the details and we’ll investigate promptly, keep you informed, and credit good-faith reports if you’d like us to. Please give us reasonable time to fix an issue before disclosing it publicly.
Sensitive data deserves a straight answer
See how CompliDesk Ireland handles your firm’s AML data in practice — or join the waitlist for free early access ahead of the 10 July 2027 deadline.