SUBPROCESSOR LIST

Last Updated

August 5, 2026

1. About This List

Legalica OÜ ("Legalica") engages the third parties listed below to provide the Platform. This page is the authoritative subprocessor register referred to in Section 15 of our Privacy & Data Governance Policy and in the Data Processing Addendum incorporated there. It is maintained under GDPR Article 28 and is updated before any new subprocessor is engaged.

Change notifications: Workspace Owners (Controllers) receive at least 14 days' advance notice of any new subprocessor (30 days for changes to our key Infrastructure Provider) via email to the registered account address. Objections may be raised to privacy@legalica.app. If an objection cannot be resolved, the Controller may terminate with a pro-rata refund, as set out in the Data Processing Addendum.

2. Infrastructure & AI Subprocessors

These providers process Customer Data on documented instructions as subprocessors. All AI inference subprocessors are contractually bound to zero-retention, no-training processing.

SubprocessorServiceData LocationRoleSafeguards
Google LLC (Google Cloud Platform / Firebase)Application hosting, Cloud Firestore database, Firebase Authentication, Cloud Storage, Cloud Functions, Cloud CDN, Vertex AI (primary AI inference)EU (europe-west3, Frankfurt); limited processing via US endpoints under SCCInfrastructure processorGCP Data Processing Addendum; SCC 2021/914; EU-US Data Privacy Framework
Google LLC (Vertex AI — Gemini models)Primary AI language model inference (AI Cascade priority #1)EU (europe-west3)AI subprocessorEnterprise API terms: zero data retention, no training on Customer Data; SCC 2021/914
Moonshot AI — Beijing Moonshot AI Technology Co., Ltd. (Kimi)Fallback AI language model inference (AI Cascade priority #2)China (api.moonshot.ai)AI subprocessor (fallback only)Contractual zero-retention and no-training obligations; SCC 2021/914 execution and TIA finalization in progress; see Section 4 — China transfer notice
Groq, Inc. (Meta Llama models via Groq API)Fallback AI language model inference (AI Cascade priority #3)US (api.groq.com)AI subprocessor (fallback only)Contractual zero-retention and no-training obligations; SCC 2021/914; EU-US DPF

3. Local Processing (No External Transfer)

ComponentServiceData LocationTransferSafeguards
Ollama (self-hosted runtime)Local AI model inference (AI Cascade priority #4)Within Legalica's application environment — no external transferNo third-country transferNo data leaves the application layer; no third party involved

4. International Transfer Notice (China & US)

The AI Cascade routes queries to providers in priority order. The primary inference route is EU-based (Google Vertex AI, europe-west3). Fallback providers are queried sequentially only if the higher-priority provider is unavailable:

  • United States (Groq): transfers rely on SCC 2021/914 and the EU-US Data Privacy Framework, with TLS 1.3 encryption in transit and contractual zero-retention.
  • China (Moonshot AI / Kimi): China has no EU adequacy decision. Transfers rely on contractual zero-retention and no-training obligations (SCC 2021/914 execution and Transfer Impact Assessment finalization in progress); a residual risk that Chinese authorities could compel access cannot be fully excluded. Do not submit highly sensitive, privileged, or special-category data if you require EU-only processing. Enterprise customers may request an EU-only routing configuration via support@legalica.app.

A summary of the Transfer Impact Assessment is available on request at privacy@legalica.app.

5. Payment Processing — Merchant of Record (Independent Controller)

Payments are processed by Creem as Merchant of Record. Creem is the contractual seller for billing purposes and processes buyer payment data as an independent data controller, not as Legalica's subprocessor. Legalica never receives or stores full payment card numbers.

ProviderServiceLocationRoleNotes
Creem (Armitage Labs OÜ, Estonia)Merchant of Record: payment processing, tax calculation and remittance, buyer invoicing, refunds/chargeback handlingEstonia / EUIndependent data controller (Merchant of Record) — NOT a subprocessorCreem processes buyer payment data as controller under its own privacy notice (creem.io); Legalica does not receive or store full card numbers

6. Public Data Sources (No Customer Data Shared)

SourceServiceLocationRoleNotes
GLEIF (Global Legal Entity Identifier Foundation)LEI reference data for entity validationInternational (public reference data)Public data source — no Customer Data sharedPublicly available registry data; queries do not identify the requesting user

7. What We Do Not Use

  • No advertising or behavioural-tracking networks (no Meta Pixel, no Google Ads cookies).
  • No sale or sharing of Customer Data for third-party marketing.
  • No subprocessor is permitted to retain Customer Data beyond response generation or to use it for model training.

8. Subscribe to Updates

Get an email when this subprocessor list changes. We will only use your address for subprocessor notifications.

9. Contact

Data protection inquiries: privacy@legalica.app
Legal notices: legal@legalica.app
Postal: Legalica OÜ, Ahtri tn 12, 10151 Tallinn, Estonia (registered address — temporary, pending completion of company formation)