oporoInformation that builds

Trust

Sub-Processor Register

Third-party services used to deliver Oporo, with a clear distinction between Customer Personal Data subprocessors and other external integrations.

Draft inventory dated 13 September 2026

Draft for legal, procurement, and security approval: provider contracting entities, Microsoft terms, deployment locations, transfer mechanisms, the configured SMTP provider, and the notification contact must be verified before publication. The Nominatim autocomplete integration requires remediation or an approved replacement. This page is excluded from search indexing while those matters remain open.

Scope

How to read this register

This register supports the Oporo Data Processing Agreement. An authorised Subprocessor processes Customer Personal Data on Oporo's behalf to provide the subscribed service. Optional providers process that data only when the relevant feature or deployment configuration is enabled.

Other third parties are disclosed for transparency because a browser or Oporo business process communicates with them, but they are not necessarily processors of Customer Personal Data under Oporo's Article 28 appointment. The classification depends on the data flow, provider terms, and the purpose for which Oporo uses the service.

Customer Content means data submitted to or generated within the service on Customer's behalf. Customer Personal Data is the part of Customer Content that is personal data under applicable Data Protection Laws.

Customer Personal Data

Authorised Subprocessors

These services form part of the current Oporo delivery architecture. Actual use and location remain subject to the applicable Order Form and deployment configuration.

Provider and servicePurpose and dataData subjectsLocationStatus
Microsoft Corporation and affiliatesAzure App Service, Azure SQL Database, Azure Blob Storage, App Service persistent storage, and related Azure infrastructureApplication hosting, relational data storage, and storage of documents, attachments, images, and BIM/IFC content.Customer Content; account, project, asset, workflow, and audit records; files; identifiers; and service metadata.Customer authorised users and individuals identified in Customer Content.The currently documented API, database, file storage, and monitoring deployment is in Australia East. Customer-specific locations apply only where agreed in writing.Core
Microsoft Corporation and affiliatesAzure Static Web AppsDelivery and operation of the Oporo customer portal.IP address, browser and request metadata, and limited service telemetry. The browser retrieves Customer Content from the separately hosted Oporo API.Customer authorised users.The currently documented portal resource is in East Asia; Microsoft may process operational data globally under its applicable terms.Core
Microsoft Corporation and affiliatesApplication Insights, Log Analytics, and Azure MonitorApplication telemetry, diagnostic logging, health monitoring, alerting, and incident investigation.User and request identifiers, IP and device/request metadata, timestamps, route and dependency telemetry, errors, and diagnostic records. Logs should not intentionally contain credentials or unnecessary Customer Content.Customer authorised users and individuals incidentally represented in diagnostic records.The currently documented monitoring resources are in Australia East; support and service operations may involve other locations under Microsoft terms.Core
Microsoft Corporation and affiliatesMicrosoft Entra IDFederated authentication and identity validation where Microsoft sign-in is enabled.Name, work email address, tenant and account identifiers, authentication claims, sign-in metadata, IP address, and device/request information.Customer authorised users using Microsoft sign-in.Global Microsoft identity service. The exact controller/processor relationship can also depend on the Customer's Microsoft tenant arrangements.Enabled deployment feature
Microsoft Corporation and affiliatesAzure Communication Services EmailDelivery of invitations, account verification, password reset, workflow notifications, and other service messages.Recipient and sender email addresses, display names where included, message subject and content, delivery status, and technical metadata.Customer authorised users, invited users, and notification recipients.Global Azure service; processing locations and safeguards are governed by the applicable Microsoft terms.Core where ACS email is configured

Feature-dependent

Optional and customer-specific Subprocessors

Provider and servicePurpose and dataData subjectsLocationStatus
Microsoft Corporation and affiliatesAzure OpenAI ServiceGenerate AI-assisted responses from a user request and selected Oporo project context.The user's prompt and generated project context, which can include project name, number, address, status, asset names and tags, document filenames and types, and aggregate record counts.Customer authorised users and individuals identified in the submitted project context.The configured Azure OpenAI region and any other locations permitted by the applicable Microsoft terms. The deployment region must be confirmed before activation.Optional; only when configured and customer-authorised
Provider to be identified for the relevant deploymentSMTP or replacement email-delivery providerDelivery of account, workflow, support, or service messages when Azure Communication Services Email is not used.Recipient and sender email addresses, display names where included, message subject and content, delivery status, and technical metadata.Customer authorised users, invited users, and notification recipients.To be identified in the Order Form, service documentation, or advance subprocessor notice before use.Optional; customer/deployment-specific

Transparency

Other service providers and integrations

These services are present in the reviewed repositories but are separated from the authorised Subprocessor list because their current role is controller-purpose, direct browser integration, content delivery, or internal software operations.

Provider and serviceRelationshipData disclosedLocation and status
OpenStreetMap FoundationOpenStreetMap map embed and public Nominatim geocodingExternal browser integration. OSMF receives requests directly and describes its own processing under its privacy policy; it is not presented here as an Article 28 Subprocessor contracted by Oporo.Project address or location search text, map coordinates, IP address, browser/device type, operating system, referrer, request time, and pages or services accessed.OSMF states that relevant personal data is stored in the United Kingdom and the Netherlands, with EU backups; map tiles can be served through a global cache network.Active product integration. Public Nominatim use must be replaced, self-hosted, or contractually approved before production publication because its policy prohibits client-side autocomplete and asks users not to submit personal or confidential material.
OpenMeteo GmbHOpen-Meteo geocoding and weather APIsExternal browser integration used to resolve project locations and display local weather. Its contractual data-protection role must be confirmed for commercial production use.Project address or place search text, latitude and longitude, IP address, requested URL, and ordinary request metadata.Open-Meteo states that servers operate in Europe and North America and that API logs can contain IP addresses and geographic coordinates for up to 90 days.Active product integration; commercial plan and data-protection terms to be confirmed
UNPKG CDN (contracting entity to be confirmed)Delivery of the web-ifc WebAssembly runtimeExternal content-delivery integration. Customer IFC files are parsed in the browser and are not intentionally sent to UNPKG by this integration.IP address, browser and request metadata, referrer, requested runtime asset, and timestamp.Global CDN delivery; contracting entity, processing locations, retention, and transfer terms require verification.Active product dependency; self-hosting the pinned runtime should be assessed
Plus Five Five, Inc. (Resend)Public website enquiry email deliveryProcessor for Oporo in Oporo's capacity as Controller of website enquiry data. It is not currently used as a Subprocessor for Customer Personal Data unless separately configured and notified.Name, company, work email, role, project stage, enquiry message, email content, delivery metadata, IP address, and ordinary service usage data.Resend states that personal data may be transferred to and processed in the United States. Applicable contractual transfer safeguards must be verified before publication.Active public website provider
Microsoft Corporation and affiliatesAzure DevOpsSoftware development, source control, build, test, and deployment service. It is an operational supplier and is not intended to receive production Customer Content.Source code, developer identity and activity, build and deployment logs, artifact metadata, and protected deployment configuration. Customer Content should not be copied into CI/CD.According to the Oporo Azure DevOps organisation configuration and applicable Microsoft terms; not verified in this register.Internal operational service

Exclusions

Locally executed software

A software dependency is not a Subprocessor merely because Oporo uses its code. The reviewed applications include libraries such as xBIM, ClosedXML, That Open, Three.js, ag-Grid, pdf.js, pdf-lib, Axios, and QR-generation packages. These components execute within Oporo's application environment or the user's browser and were not found to send Customer Personal Data to their publishers as part of their ordinary operation.

The UNPKG-hosted web-ifc runtime is separately disclosed above because retrieving it creates a network request to an external CDN. Oporo should self-host that pinned runtime if external CDN disclosure is not required for the product.

International processing

Locations and transfer safeguards

The current production architecture is not UK-only: the customer portal is documented in East Asia, while the API, Azure SQL Database, Blob Storage, Application Insights, and Log Analytics are documented in Australia East. Microsoft identity, communication, support, and service operations may involve global processing. Customer-specific UK or EEA residency applies only where expressly agreed.

Where restricted transfers of Customer Personal Data occur, Oporo will use a lawful transfer mechanism required by the applicable Data Protection Laws, such as adequacy regulations, the UK International Data Transfer Agreement or UK Addendum to approved Standard Contractual Clauses, together with supplementary measures where required. The exact mechanism and provider contractual terms must be verified for the relevant service and deployment before this draft is approved.

Governance

Changes, notice, and objections

Oporo may update this register as suppliers and service features change. Under the DPA, Oporo will provide at least 30 days' prior notice of a new or replacement Subprocessor where reasonably practicable. A Customer may object during that period on reasonable, documented data-protection grounds using the notice route specified in its agreement.

Oporo and Customer will work in good faith on a commercially reasonable solution. If no solution is available, the rights relating to the affected service are those set out in the DPA. Changes to providers that do not process Customer Personal Data are managed under the Privacy Policy, service documentation, and applicable agreement rather than the Article 28 objection process.

Contact

Questions and notices

Questions about this register can be sent to contact@oporo.net. Contractual notices and objections must also follow any notice requirements in the applicable customer agreement.