Who else touches the data
Client data is processed by us and by a small number of specialised providers. This page lists the categories, what each one does, and how you are told before anything changes.
Categories, purposes and the data involved
Names of the specific providers, with their processing locations and contractual safeguards, are supplied with your order form — we do not publish suppliers we have not yet contracted with.
| Category | Purpose | Data involved | Where |
|---|---|---|---|
| Managed infrastructure | Hosting the firm’s deployment: compute, database and object storage | All data in the firm’s instance | The region chosen at deployment |
| Backup storage | Encrypted copies of the firm’s database exports | All data in the firm’s instance | Same region as the deployment |
| Transactional email | Delivery of system messages: invitations, password resets, notifications, portal links | Recipient name and email address; message content | Provider’s standard regions |
| Error monitoring | Detecting and diagnosing faults; keeping the service reliable | Technical diagnostics; personal data is excluded from error reports by configuration | Provider’s standard regions |
| Payment processing only if enabled | Collecting fees through the gateway the firm chooses | Payer name, amount, reference; card or wallet details handled by the provider, not by us | Per the provider |
| E-signature only if enabled | Sending documents for signature and returning executed copies | Signatory name, email address and the document being signed | Per the firm’s chosen provider |
| Messaging channels only if enabled | SMS and chat delivery where the firm uses those channels with clients | Recipient number or handle; message content | Per the provider |
| AI model access only if enabled | Drafting, summarising and date extraction requested by the firm’s staff | Only the content the user submits for that task; enabled per firm and visible in usage records | Per the firm’s configuration |
| Support tooling | Handling support requests and tracking their resolution | Contact details and the technical detail of the request | Provider’s standard regions |
Note on self-hosting: where a firm runs its own deployment, none of the infrastructure, backup or monitoring categories apply — those are the firm’s own suppliers and its own decisions. Only the services the firm chooses to connect remain.
Thirty days, in writing, before anything new
- Advance notice. At least 30 days before a new sub-processor begins processing client personal data.
- Sent to administrators. Notice goes to the firm’s named administrators by email, and appears in the compliance briefing list.
- What the notice contains. Who, what purpose, which data, where it is processed, and the safeguard relied on for any transfer.
- Emergency changes. Where a provider must be replaced immediately for security or continuity, we tell the firm as soon as practicable afterwards rather than pretending the 30 days applied.
Your right to object
A firm may object to a new sub-processor on reasonable data protection grounds, within 30 days of notice. We will try to make an alternative available — a different provider, a feature left disabled, or processing restricted to a region the firm accepts.
If no alternative is workable, the firm may terminate the affected part of the service without penalty, and we will assist with an export as usual.
Objections and questions: privacy@openlpm.com. Security reports: security@openlpm.com.
Last reviewed 14 September 2026. This page is updated whenever the register changes.