LEGAL ยท SUB-PROCESSORS

OnGravy sub-processors

Last updated: May 3, 2026 ยท Updated quarterly
๐Ÿ‡ฎ๐Ÿ‡ณ OnGravy uses these third-party services to deliver the platform. Most data stays in India (Mumbai region). Cross-border transfers are minimised + flagged below. Notified 30 days in advance of any addition.

Per Section 8(7) of the Digital Personal Data Protection Act 2023 + Section 9 of OnGravy's Data Processing Agreement, customers (Data Fiduciaries) are notified of all sub-processors. New additions trigger a 30-day notice + the right to object. Object via privacy@ongravy.in.

VendorPurposeData accessedRegionCertificationsSince
SupabasePrimary database + authentication + file storageAll customer data โ€” invoices, journals, employees, KYC documentsIndia (ap-south-1, Mumbai)SOC 2 Type 2, HIPAA-eligible, ISO 270012025-04-01
VercelApplication hosting + edge function execution + asset CDNRequest payloads + response payloads in transit (not stored)Mumbai (primary), Singapore (overflow)SOC 2 Type 2, ISO 27001, GDPR-compliant2025-04-01
RazorpaySubscription billing + payment processingCard details, UPI IDs, billing addresses (PCI-DSS scoped โ€” OnGravy never touches raw card data)IndiaPCI-DSS Level 1, ISO 270012025-04-01
AWS S3 (via Supabase)Encrypted object storage for user-uploaded documents (bills, bank statements, contracts)Document files only โ€” server-side encrypted with AES-256India (ap-south-1, Mumbai)SOC 2, ISO 27001, HIPAA-eligible2025-04-01
ResendTransactional email delivery (OTPs, receipts, compliance reminders)Email addresses + email body contentUnited States + EU (depending on customer route)SOC 2 Type 2, GDPR-compliant2025-04-01
Meta WhatsApp Business APIWhatsApp message delivery + receipt of customer-sent bills/photosPhone numbers + message bodies + media uploaded by usersIndia + global (Meta's infrastructure)ISO 27001, SOC 22025-04-01
Anthropic (Claude)AI processing โ€” bill OCR, journal-entry suggestions, AI advisor responsesAnonymised invoice text + bill images for the duration of the inference (no training)United States โ€” Anthropic does NOT train on inference data per their commercial termsSOC 2 Type 22025-08-01
OpenAIAI fallback โ€” bill OCR + transcription when Claude unavailableSame as Anthropic; opt-out of training data sharing enabledUnited StatesSOC 2 Type 22025-08-01
AWS Textract (via integration layer)Image-to-text extraction for low-confidence billsBill images for the duration of OCR processing onlyIndia (ap-south-1, Mumbai)SOC 2, PCI-DSS, HIPAA-eligible2025-08-01
SentryError tracking + crash reportingStack traces, request URLs, sanitised request bodies (PII auto-scrubbed)United StatesSOC 2 Type 2, ISO 27001, GDPR-compliant2025-04-01

How OnGravy minimises sub-processor risk

  • Encryption in transit (TLS 1.2+) and at rest (AES-256) on every sub-processor
  • Indian data primarily stored in Mumbai region (ap-south-1) โ€” cross-border transfers limited to AI inference and email delivery
  • Anthropic + OpenAI: opt-out of training data sharing exercised; data not retained beyond inference
  • Sub-processor changes follow the 30-day notice in our DPA โ€” customers can object
  • Annual security review of every sub-processor
  • Incident notification within 72 hours per DPDP Act Section 8(6)
Questions about sub-processors or data residency: privacy@ongravy.in