The **Settings → Compliance** page surfaces the data-processing transparency information specific to your organization's region. It is the place to confirm where your data lives and which third parties may touch it.

## Data residency

Every organization is pinned to a region at creation. The active organization's region is shown at the top of the compliance page. Tenant data (applicants, verifications, workflow templates, audit history) stays inside that region for the life of the organization and is never replicated across regions.

If you need a different region for a different population of applicants, create a separate organization in that region. See [Create an organization](/guides/organizations/create-organization) and [Data residency](/guides/faq/data-residency).

## Sub-processors

The page lists every third-party service that may process personal data on behalf of the platform for your region. Each entry shows:

- **Name** — the legal entity acting as a sub-processor.
- **Category** — the function it provides (infrastructure, identity verification, email delivery, and so on).
- **Description** — what the sub-processor does in the platform.

The list is the union of platform-wide sub-processors and the ones specific to your region, rendered together. The page also shows the effective date so you can see when the list was last refreshed.

### Biometric verification sub-processor

When a workflow template's identity-document check uses an active-liveness biometric mode, a biometric liveness sub-processor (**Amazon Web Services**) handles the liveness check for your region. Biometric data is special-category personal data (GDPR Article 9), so it is handled under a separate residency commitment: an EU organization's liveness check is pinned to the EU region (Ireland) and the resulting data is written to EU storage and never transits another region. The raw video is not retained; only the reference image needed to match the face against the document is stored, and it follows the same encryption and erasure rules as the other identity-document images. See [Biometric data](/guides/faq/data-residency#biometric-data) for the full residency and retention detail.

## Retention windows

Retention controls are not configurable per-organization. Platform defaults apply and are described in the [Data residency](/guides/faq/data-residency) FAQ.

## Legal agreements

The active legal agreements for the platform — Terms, DPA, and any region-specific addenda — are linked from the marketing site and are not customized per organization in this surface.

## Audit access

Every privileged action on the organization — role changes, branding updates, invites, billing changes — emits an audit event. Review the trail in the [Audit log](/guides/activity/activity-log).

## Where to learn more

- [Data residency](/guides/faq/data-residency)
- [Audit log](/guides/activity/activity-log)
- [Glossary](/glossary)