Sub-processor register
The providers that process firm data on OrdoMetric's behalf, with purpose and region, and the processors a firm may select itself.
Version 0.1 · Effective September 7, 2026Draft for counsel review
Draft for counsel review
A Nepali practitioner has not yet reviewed this document. The highlighted markers show the statements awaiting confirmation; until they are cleared, this text is not a binding version.
This register lists every third party that processes a firm's data on OrdoMetric's behalf. It is incorporated by reference into the Privacy notice and the Data processing agreement. Firm Owners are notified by email at least 30 days before a new provider processes firm data [verify DPA notice period]; the version and date above change with every amendment.
Regions and retention are stated as configured for the pilot [verify each provider's current terms]. Where a provider's role depends on the deployment profile a firm is placed on, both are stated.
Processors engaged by OrdoMetric
Engaged for every firm, only once a firm enables AI (the AI rows), or only for firms placed on the Google Cloud profile (the gcp hosting row).
| Provider | Purpose | Region | Data |
|---|---|---|---|
| RailwayInfrastructure | Compute, PostgreSQL, object storage (Railway Buckets), service logs and scheduled volume backups for the pilot (railway profile) | Singapore (asia-southeast1); documents are single-region on the pilot[verify Railway's own infrastructure sub-processors and the Railway region list] | Database, documents encrypted under the per-firm key, encrypted backups |
| CloudflareEdge | Edge proxy for the pilot: DNS, TLS termination, web application firewall, rate limits, static-asset caching; R2 object storage holds the off-site copy of the encrypted nightly database backup (35 days) | Global edge; TLS terminates at Cloudflare, so request content is visible to it in transit; no request bodies or dynamic responses are stored. R2 location assigned automatically by Cloudflare[verify R2 region auto placement] | Connection metadata and request content in transit; age-encrypted database dumps (off-site backup copy) |
| Google Cloud (Vertex AI embeddings)AI, opt-in | Document embeddings for search (platform default), called over the API from every profile; only when the firm enables AI | Mumbai (asia-south1) | Text chunks of documents of firms that enabled AI |
| Google Cloud (gcp profile hosting)Infrastructure | Cloud SQL, Cloud Storage, Cloud KMS and Cloud Logging for firms placed on the gcp profile once it is activated (India residency, per-firm hardware-backed keys, approver-gated staff access) | Mumbai (asia-south1); backups and the documents dual-region pair in Delhi (asia-south2) | Database, documents under per-firm Cloud KMS keys and backups, only for firms on that profile |
| AnthropicAI, opt-in | Platform default AI provider: assistant, summaries, drafts, key-date extraction and OCR; only when the firm enables AI | United States, in transit; zero data retention requested, the standard API retention disclosed until it is granted[verify zero-data-retention availability for the selected models and Files API retention] | For the assistant, the text the asking user may read (document passages, notes, case facts); for OCR of scanned documents, the document file itself, uploaded to the Files API and deleted on exclusion or purge; no automated redaction before sending |
| ResendEmail | Transactional email: verification codes, invitations, digests, client updates | EU[verify Resend retention period] | Recipient address, subject and delivery status; the message body is kept for the shortest available period |
| SentryMonitoring | Error monitoring on every profile, including the public website; traces (10% sampling) on the pilot and self-hosted profiles | EU[verify Sentry EU data residency] | Error messages and identifiers only; request bodies and document, note and comment fields are stripped before sending |
Processors a firm selects
Engaged by the firm's own decision in Settings and listed here for transparency. The firm names them in its own notice to its clients; with a firm-held key or account, the firm's own vendor agreement governs.
| Provider | Purpose | Region | Data |
|---|---|---|---|
| OpenAISelected by the firm | AI provider selected by a firm instead of the platform default, for the assistant, OCR and, where offered, embeddings; with a bring-your-own key the firm holds the vendor contract | As configured by the firm | Text of that firm’s cases and documents that the asking user may read; rendered page images for OCR of scanned documents; no automated redaction before sending |
| Azure OpenAI (Microsoft)Selected by the firm | AI provider selected by a firm instead of the platform default, for the assistant, OCR and, where offered, embeddings; with a bring-your-own key the firm holds the vendor contract | As configured by the firm | Text of that firm’s cases and documents that the asking user may read; rendered page images for OCR of scanned documents; no automated redaction before sending |
| AWS Bedrock (Amazon Web Services)Selected by the firm | AI provider selected by a firm instead of the platform default, for the assistant, OCR and, where offered, embeddings; with a bring-your-own key the firm holds the vendor contract | As configured by the firm | Text of that firm’s cases and documents that the asking user may read; rendered page images for OCR of scanned documents; no automated redaction before sending |
| Google Vertex AI (firm-selected AI provider)Selected by the firm | AI provider selected by a firm instead of the platform default, for the assistant, OCR and, where offered, embeddings; with a bring-your-own key the firm holds the vendor contract | As configured by the firm | Text of that firm’s cases and documents that the asking user may read; rendered page images for OCR of scanned documents; no automated redaction before sending |
| DropboxSelected by the firm | Bring-your-own storage: the firm's own account holds the original documents uploaded after the firm connects it | The firm's own account | Original documents; OrdoMetric holds an OAuth token encrypted under the firm key and keeps derived text and vectors on the platform |
| Google DriveSelected by the firm | Bring-your-own storage: the firm's own account holds the original documents uploaded after the firm connects it | The firm's own account | Original documents; OrdoMetric holds an OAuth token encrypted under the firm key and keeps derived text and vectors on the platform |
Notes
- Processors engaged by OrdoMetric run for every firm (Railway, Cloudflare, Resend, Sentry),
only once a firm enables AI (Anthropic, Google Cloud Vertex AI embeddings), or only for firms
placed on the
gcpprofile once it is activated (Google Cloud hosting). Cloudflare also holds the off-site copy of the encrypted nightly database backup in R2 object storage. - Processors a firm selects are engaged by the firm's own decision in Settings: an alternative AI provider, optionally with the firm's own key, or the firm's own Dropbox or Google Drive account. They appear here for transparency; the firm names them in its own notice to its clients, and with a firm-held key or account the firm's own vendor agreement governs.
- Not engaged today: SMS is off during the pilot, so no SMS provider processes firm data. Sparrow SMS (Nepal) and, as a fallback, Twilio (United States) would be added under the 30-day notice before a firm's first message. No analytics provider is wired; the website sets no analytics cookies.
Changes
| Version | Date | Change |
|---|---|---|
| 0.1 | 2026-09-07 | First published register (draft for counsel review) |