SUBPROCESSOR LIST
Last Updated
August 5, 2026
1. About This List
Legalica OÜ ("Legalica") engages the third parties listed below to provide the Platform. This page is the authoritative subprocessor register referred to in Section 15 of our Privacy & Data Governance Policy and in the Data Processing Addendum incorporated there. It is maintained under GDPR Article 28 and is updated before any new subprocessor is engaged.
Change notifications: Workspace Owners (Controllers) receive at least 14 days' advance notice of any new subprocessor (30 days for changes to our key Infrastructure Provider) via email to the registered account address. Objections may be raised to privacy@legalica.app. If an objection cannot be resolved, the Controller may terminate with a pro-rata refund, as set out in the Data Processing Addendum.
2. Infrastructure & AI Subprocessors
These providers process Customer Data on documented instructions as subprocessors. All AI inference subprocessors are contractually bound to zero-retention, no-training processing.
| Subprocessor | Service | Data Location | Role | Safeguards |
|---|---|---|---|---|
| Google LLC (Google Cloud Platform / Firebase) | Application hosting, Cloud Firestore database, Firebase Authentication, Cloud Storage, Cloud Functions, Cloud CDN, Vertex AI (primary AI inference) | EU (europe-west3, Frankfurt); limited processing via US endpoints under SCC | Infrastructure processor | GCP Data Processing Addendum; SCC 2021/914; EU-US Data Privacy Framework |
| Google LLC (Vertex AI — Gemini models) | Primary AI language model inference (AI Cascade priority #1) | EU (europe-west3) | AI subprocessor | Enterprise API terms: zero data retention, no training on Customer Data; SCC 2021/914 |
| Moonshot AI — Beijing Moonshot AI Technology Co., Ltd. (Kimi) | Fallback AI language model inference (AI Cascade priority #2) | China (api.moonshot.ai) | AI subprocessor (fallback only) | Contractual zero-retention and no-training obligations; SCC 2021/914 execution and TIA finalization in progress; see Section 4 — China transfer notice |
| Groq, Inc. (Meta Llama models via Groq API) | Fallback AI language model inference (AI Cascade priority #3) | US (api.groq.com) | AI subprocessor (fallback only) | Contractual zero-retention and no-training obligations; SCC 2021/914; EU-US DPF |
3. Local Processing (No External Transfer)
| Component | Service | Data Location | Transfer | Safeguards |
|---|---|---|---|---|
| Ollama (self-hosted runtime) | Local AI model inference (AI Cascade priority #4) | Within Legalica's application environment — no external transfer | No third-country transfer | No data leaves the application layer; no third party involved |
4. International Transfer Notice (China & US)
The AI Cascade routes queries to providers in priority order. The primary inference route is EU-based (Google Vertex AI, europe-west3). Fallback providers are queried sequentially only if the higher-priority provider is unavailable:
- United States (Groq): transfers rely on SCC 2021/914 and the EU-US Data Privacy Framework, with TLS 1.3 encryption in transit and contractual zero-retention.
- China (Moonshot AI / Kimi): China has no EU adequacy decision. Transfers rely on contractual zero-retention and no-training obligations (SCC 2021/914 execution and Transfer Impact Assessment finalization in progress); a residual risk that Chinese authorities could compel access cannot be fully excluded. Do not submit highly sensitive, privileged, or special-category data if you require EU-only processing. Enterprise customers may request an EU-only routing configuration via support@legalica.app.
A summary of the Transfer Impact Assessment is available on request at privacy@legalica.app.
5. Payment Processing — Merchant of Record (Independent Controller)
Payments are processed by Creem as Merchant of Record. Creem is the contractual seller for billing purposes and processes buyer payment data as an independent data controller, not as Legalica's subprocessor. Legalica never receives or stores full payment card numbers.
| Provider | Service | Location | Role | Notes |
|---|---|---|---|---|
| Creem (Armitage Labs OÜ, Estonia) | Merchant of Record: payment processing, tax calculation and remittance, buyer invoicing, refunds/chargeback handling | Estonia / EU | Independent data controller (Merchant of Record) — NOT a subprocessor | Creem processes buyer payment data as controller under its own privacy notice (creem.io); Legalica does not receive or store full card numbers |
6. Public Data Sources (No Customer Data Shared)
| Source | Service | Location | Role | Notes |
|---|---|---|---|---|
| GLEIF (Global Legal Entity Identifier Foundation) | LEI reference data for entity validation | International (public reference data) | Public data source — no Customer Data shared | Publicly available registry data; queries do not identify the requesting user |
7. What We Do Not Use
- No advertising or behavioural-tracking networks (no Meta Pixel, no Google Ads cookies).
- No sale or sharing of Customer Data for third-party marketing.
- No subprocessor is permitted to retain Customer Data beyond response generation or to use it for model training.
8. Subscribe to Updates
Get an email when this subprocessor list changes. We will only use your address for subprocessor notifications.
9. Contact
Data protection inquiries: privacy@legalica.app
Legal notices: legal@legalica.app
Postal: Legalica OÜ, Ahtri tn 12, 10151 Tallinn, Estonia (registered address — temporary, pending completion of company formation)