Skip to content
Legiscope
Menu
Provider transparency

Subprocessors and service providers

The cloud, AI and operational providers Legiscope uses—or may select—to deliver the service, with the data boundary for each.

01

How to read this register

Core providers support the customer platform or a feature represented in the reviewed service configuration. Legiscope uses commercial AI services from OpenAI, Anthropic and Google Gemini and may select any one of them for a bounded task; only the provider selected for that operation receives its input. Operational providers support billing, correspondence, scheduling or the public website and do not receive Customer Content unless a person deliberately supplies it through that channel.

A service provider may perform different legal roles for different data. This register describes the operational boundary; the customer DPA and the provider-specific terms determine the contractual role for the processing in scope.

The cards name provider organisations and services. The exact contracting legal entity can depend on the provider account, service and customer location; the controlled entity-level record is confirmed from the applicable Legiscope provider agreement and is available during procurement.

02

Customer platform providers

These providers support the hosted Legiscope application and AI-assisted workflows.

AWS · cloud infrastructure and transactional email

Amazon Web Services

Core provider
Purpose
Host and secure the application; provide identity, API, compute, database, object storage, backup, monitoring, secrets and transactional-email services.
Data in scope
Customer Content, account and authentication data, service records, uploaded files, job data, security and diagnostic metadata, and transactional email content. The public demonstration-booking service also handles the submitted booking fields.
Processing context
The primary customer application is in AWS eu-west-1 (Ireland), with a protected customer-object recovery copy in eu-west-3 (France). The public demo-booking API is addressed in us-east-1 (United States). The applicable AWS DPA includes transfer safeguards for restricted transfers.
Commercial API · AI-assisted processing

OpenAI

AI provider
Purpose
Generate structured analysis, drafting and decision-support output when an OpenAI model is selected for an authorised AI-assisted workflow.
Data in scope
When selected: the source material or Customer Content, task instructions, minimum workflow context and generated output required for that operation.
Processing context
Legiscope uses OpenAI through commercial API routes. Model selection may vary by task and configuration. Commercial/API inputs and outputs are not used for model training by default. Processing and retention follow the contracted API service, DPA and enabled controls; processing may involve the United States.
Commercial API · AI-assisted processing

Anthropic

AI provider
Purpose
Generate structured analysis, drafting and decision-support output when an Anthropic model is selected for an authorised AI-assisted workflow.
Data in scope
When selected: the source material or Customer Content, task instructions, minimum workflow context and generated output required for that operation.
Processing context
Legiscope uses Anthropic as a commercial AI provider and may route a bounded operation to an Anthropic model. Anthropic states that commercial API customer content is not used to train models by default; the applicable DPA governs commercial processing and transfers.
Gemini API paid services · AI-assisted processing

Google Gemini

AI provider
Purpose
Generate structured analysis, drafting and decision-support output when a Gemini model is selected for an authorised AI-assisted workflow.
Data in scope
When selected: the source material or Customer Content, task instructions, minimum workflow context and generated output required for that operation.
Processing context
Legiscope uses Google Gemini as a commercial AI provider and may route a bounded operation to a Gemini model. Legiscope uses the paid-service contractual position for EEA processing; Google states that paid-service prompts and responses are not used to improve its products. Global processing and limited abuse-monitoring logs are governed by the applicable terms and DPA.
03

Operations, scheduling and billing

These providers support Legiscope business operations or the public website. They are listed for transparency but do not receive platform Customer Content through those functions.

Gmail and Google Calendar · correspondence and appointments

Google Workspace

Operational provider
Purpose
Receive and manage business email; create and administer requested sales and product-demonstration appointments, invitations and joining details.
Data in scope
Names, business email addresses, correspondence and attachments; for appointments, the selected time, optional organisation and message, invitee details and meeting records supplied through the booking or email channel.
Processing context
Google Workspace supports professional correspondence and Calendar appointments. It is not an application content store. Google publishes its Workspace subprocessors and applicable data-processing terms; processing locations depend on the Workspace service and configuration.
reCAPTCHA · public form abuse prevention

Google reCAPTCHA

Operational provider
Purpose
Assess whether a public contact or demonstration-booking submission is legitimate and protect both forms from automated abuse.
Data in scope
The reCAPTCHA token and the device, browser, network and interaction information Google requires for risk analysis. It does not receive Legiscope platform Customer Content through this flow.
Processing context
reCAPTCHA loads only when a visitor proceeds with the contact or demonstration-booking form. From 2 April 2026, Google acts as processor for reCAPTCHA Customer Data under the Google Cloud Terms and Cloud Data Processing Addendum; Legiscope remains controller for this use.
Stripe Billing and Payments · subscriptions and invoicing

Stripe

Operational provider
Purpose
Maintain billing profiles, subscriptions, invoices, tax information and payment status, and process payment methods where enabled.
Data in scope
Customer contact and billing details, postal address, tax or VAT identifiers, subscription and invoice records, payment tokens and transaction metadata. Stripe receives payment details directly through its payment services; it does not receive platform Customer Content.
Processing context
Stripe’s legal role can vary by payment activity and jurisdiction. Processing and international transfers follow the applicable Stripe services agreement, DPA and service-provider list.
04

AI selection and safeguards

  • Legiscope uses OpenAI, Anthropic and Google Gemini through centrally controlled model routes. One enabled provider is selected for an operation; the three providers do not all receive the same prompt or source material.
  • The browser does not send Customer Content directly to an AI provider. A bounded backend job sends only the content and context selected for the authorised workflow.
  • Model names and versions can change under controlled routing. The provider identity and contractual terms, not the model label, determine the applicable processing position.
  • The linked commercial provider terms describe whether inputs and outputs are used for model training or product improvement. The applicable service tier, enabled controls and provider abuse-monitoring or security retention must be checked for the selected route.
  • AI output remains draft decision-support material and requires authoritative human review.
05

Locations, transfers and assurance

An EU application region does not mean every optional or operational service is processed only in the EU. Legiscope assesses the actual provider, service, destination, access pattern and contractual transfer safeguard for the customer scope.

Provider certifications and independent reports describe that provider’s controls; they are not Legiscope certifications. Evidence may be shared during procurement subject to the provider’s distribution terms.

06

Changes and questions

Legiscope reviews this public register when a provider, purpose or material processing boundary changes. For contracted customer processing, the applicable DPA governs advance notice, the notification channel and any right to object to a new or replacement subprocessor.

A customer or procurement reviewer may ask contact@legiscope.com which providers apply to a proposed workflow and request the current contractual record. Customer-directed exports and integrations are not Legiscope-appointed subprocessors merely because a customer chooses to connect them.

Provider review

Ask about your exact service scope.

Tell us which workflows and organisations are in scope. We can pair this register with the applicable DPA, AI usage, hosting and transfer context.

Contact Privacy