Scope
How to read this register
This register supports the Oporo Data Processing Agreement. An authorised Subprocessor processes Customer Personal Data on Oporo's behalf to provide the subscribed service. Optional providers process that data only when the relevant feature or deployment configuration is enabled.
Other third parties are disclosed for transparency because a browser or Oporo business process communicates with them, but they are not necessarily processors of Customer Personal Data under Oporo's Article 28 appointment. The classification depends on the data flow, provider terms, and the purpose for which Oporo uses the service.
Customer Content means data submitted to or generated within the service on Customer's behalf. Customer Personal Data is the part of Customer Content that is personal data under applicable Data Protection Laws.
Customer Personal Data
Authorised Subprocessors
These services form part of the current Oporo delivery architecture. Actual use and location remain subject to the applicable Order Form and deployment configuration.
| Provider and service | Purpose and data | Data subjects | Location | Status |
|---|---|---|---|---|
| Microsoft Corporation and affiliatesAzure App Service, Azure SQL Database, Azure Blob Storage, App Service persistent storage, and related Azure infrastructure | Application hosting, relational data storage, and storage of documents, attachments, images, and BIM/IFC content.Customer Content; account, project, asset, workflow, and audit records; files; identifiers; and service metadata. | Customer authorised users and individuals identified in Customer Content. | The currently documented API, database, file storage, and monitoring deployment is in Australia East. Customer-specific locations apply only where agreed in writing. | Core |
| Microsoft Corporation and affiliatesAzure Static Web Apps | Delivery and operation of the Oporo customer portal.IP address, browser and request metadata, and limited service telemetry. The browser retrieves Customer Content from the separately hosted Oporo API. | Customer authorised users. | The currently documented portal resource is in East Asia; Microsoft may process operational data globally under its applicable terms. | Core |
| Microsoft Corporation and affiliatesApplication Insights, Log Analytics, and Azure Monitor | Application telemetry, diagnostic logging, health monitoring, alerting, and incident investigation.User and request identifiers, IP and device/request metadata, timestamps, route and dependency telemetry, errors, and diagnostic records. Logs should not intentionally contain credentials or unnecessary Customer Content. | Customer authorised users and individuals incidentally represented in diagnostic records. | The currently documented monitoring resources are in Australia East; support and service operations may involve other locations under Microsoft terms. | Core |
| Microsoft Corporation and affiliatesMicrosoft Entra ID | Federated authentication and identity validation where Microsoft sign-in is enabled.Name, work email address, tenant and account identifiers, authentication claims, sign-in metadata, IP address, and device/request information. | Customer authorised users using Microsoft sign-in. | Global Microsoft identity service. The exact controller/processor relationship can also depend on the Customer's Microsoft tenant arrangements. | Enabled deployment feature |
| Microsoft Corporation and affiliatesAzure Communication Services Email | Delivery of invitations, account verification, password reset, workflow notifications, and other service messages.Recipient and sender email addresses, display names where included, message subject and content, delivery status, and technical metadata. | Customer authorised users, invited users, and notification recipients. | Global Azure service; processing locations and safeguards are governed by the applicable Microsoft terms. | Core where ACS email is configured |
Feature-dependent
Optional and customer-specific Subprocessors
| Provider and service | Purpose and data | Data subjects | Location | Status |
|---|---|---|---|---|
| Microsoft Corporation and affiliatesAzure OpenAI Service | Generate AI-assisted responses from a user request and selected Oporo project context.The user's prompt and generated project context, which can include project name, number, address, status, asset names and tags, document filenames and types, and aggregate record counts. | Customer authorised users and individuals identified in the submitted project context. | The configured Azure OpenAI region and any other locations permitted by the applicable Microsoft terms. The deployment region must be confirmed before activation. | Optional; only when configured and customer-authorised |
| Provider to be identified for the relevant deploymentSMTP or replacement email-delivery provider | Delivery of account, workflow, support, or service messages when Azure Communication Services Email is not used.Recipient and sender email addresses, display names where included, message subject and content, delivery status, and technical metadata. | Customer authorised users, invited users, and notification recipients. | To be identified in the Order Form, service documentation, or advance subprocessor notice before use. | Optional; customer/deployment-specific |
Transparency
Other service providers and integrations
These services are present in the reviewed repositories but are separated from the authorised Subprocessor list because their current role is controller-purpose, direct browser integration, content delivery, or internal software operations.
| Provider and service | Relationship | Data disclosed | Location and status |
|---|---|---|---|
| OpenStreetMap FoundationOpenStreetMap map embed and public Nominatim geocoding | External browser integration. OSMF receives requests directly and describes its own processing under its privacy policy; it is not presented here as an Article 28 Subprocessor contracted by Oporo. | Project address or location search text, map coordinates, IP address, browser/device type, operating system, referrer, request time, and pages or services accessed. | OSMF states that relevant personal data is stored in the United Kingdom and the Netherlands, with EU backups; map tiles can be served through a global cache network.Active product integration. Public Nominatim use must be replaced, self-hosted, or contractually approved before production publication because its policy prohibits client-side autocomplete and asks users not to submit personal or confidential material. |
| OpenMeteo GmbHOpen-Meteo geocoding and weather APIs | External browser integration used to resolve project locations and display local weather. Its contractual data-protection role must be confirmed for commercial production use. | Project address or place search text, latitude and longitude, IP address, requested URL, and ordinary request metadata. | Open-Meteo states that servers operate in Europe and North America and that API logs can contain IP addresses and geographic coordinates for up to 90 days.Active product integration; commercial plan and data-protection terms to be confirmed |
| UNPKG CDN (contracting entity to be confirmed)Delivery of the web-ifc WebAssembly runtime | External content-delivery integration. Customer IFC files are parsed in the browser and are not intentionally sent to UNPKG by this integration. | IP address, browser and request metadata, referrer, requested runtime asset, and timestamp. | Global CDN delivery; contracting entity, processing locations, retention, and transfer terms require verification.Active product dependency; self-hosting the pinned runtime should be assessed |
| Plus Five Five, Inc. (Resend)Public website enquiry email delivery | Processor for Oporo in Oporo's capacity as Controller of website enquiry data. It is not currently used as a Subprocessor for Customer Personal Data unless separately configured and notified. | Name, company, work email, role, project stage, enquiry message, email content, delivery metadata, IP address, and ordinary service usage data. | Resend states that personal data may be transferred to and processed in the United States. Applicable contractual transfer safeguards must be verified before publication.Active public website provider |
| Microsoft Corporation and affiliatesAzure DevOps | Software development, source control, build, test, and deployment service. It is an operational supplier and is not intended to receive production Customer Content. | Source code, developer identity and activity, build and deployment logs, artifact metadata, and protected deployment configuration. Customer Content should not be copied into CI/CD. | According to the Oporo Azure DevOps organisation configuration and applicable Microsoft terms; not verified in this register.Internal operational service |
Exclusions
Locally executed software
A software dependency is not a Subprocessor merely because Oporo uses its code. The reviewed applications include libraries such as xBIM, ClosedXML, That Open, Three.js, ag-Grid, pdf.js, pdf-lib, Axios, and QR-generation packages. These components execute within Oporo's application environment or the user's browser and were not found to send Customer Personal Data to their publishers as part of their ordinary operation.
The UNPKG-hosted web-ifc runtime is separately disclosed above because retrieving it creates a network request to an external CDN. Oporo should self-host that pinned runtime if external CDN disclosure is not required for the product.
International processing
Locations and transfer safeguards
The current production architecture is not UK-only: the customer portal is documented in East Asia, while the API, Azure SQL Database, Blob Storage, Application Insights, and Log Analytics are documented in Australia East. Microsoft identity, communication, support, and service operations may involve global processing. Customer-specific UK or EEA residency applies only where expressly agreed.
Where restricted transfers of Customer Personal Data occur, Oporo will use a lawful transfer mechanism required by the applicable Data Protection Laws, such as adequacy regulations, the UK International Data Transfer Agreement or UK Addendum to approved Standard Contractual Clauses, together with supplementary measures where required. The exact mechanism and provider contractual terms must be verified for the relevant service and deployment before this draft is approved.
Governance
Changes, notice, and objections
Oporo may update this register as suppliers and service features change. Under the DPA, Oporo will provide at least 30 days' prior notice of a new or replacement Subprocessor where reasonably practicable. A Customer may object during that period on reasonable, documented data-protection grounds using the notice route specified in its agreement.
Oporo and Customer will work in good faith on a commercially reasonable solution. If no solution is available, the rights relating to the affected service are those set out in the DPA. Changes to providers that do not process Customer Personal Data are managed under the Privacy Policy, service documentation, and applicable agreement rather than the Article 28 objection process.
Contact
Questions and notices
Questions about this register can be sent to contact@oporo.net. Contractual notices and objections must also follow any notice requirements in the applicable customer agreement.
