Third party processors

In order to provide the services that we offer as efficiently as possible, Open GI (and associated companies) may use third parties to perform certain functions and in doing so, they may process customer data or personal data as part of the service. In some circumstances, the third party may have been appointed by Open GI’s client to act as their processor or the third party may be a data controller itself, but in other circumstances the third party may be acting directly as a sub-processor of Open GI under Open GI’s general written agreement to appoint sub-processors to process client data on the data controller’s behalf.

This list separates the following entities which we have defined in this notice:

‍Sub-Processori: This is a data protection term under GDPR Art 28(4) and will apply to entities (including some applicable sub-contractors) where Open GI engaged them under the client’s general authorisation to carry out part of the processing Open GI performs on the client’s behalf. They will process client data only within the purposes the client has determined and on the client’s instructions, passed down through Open GI, and never for any purpose of its own. Open GI’s selection determines the technical means of implementation only. The client determines the purposes and essential means of the data. Open GI do not determine its own purposes for the data processing. We notify the client of this appointment and provide them with an opportunity to object to the appointment of the sub-processor.
‍
‍Authorised ‘Recipient’ii: The client engaged it directly or have a business relationship with them to perform part of a processing function; for example, an Insurer. It processes on the client’s behalf, but we are a peer in the chain, not its principal. We merely route data to it on instruction through our platforms in order to facilitate processing functions such as enrichments, lookups, fraud checks, etc. A recipient is defined in the UK and EU GDPR (see footnote 2).

‍Sub-Contractoriii: Any third party we partner with to help deliver a service or provide supporting services to Open GI. In some cases, these may be mutual to Open GI and its clients who are data controllers. Data may be processed as part of an agreed contract or arrangement. This may not be personal data. An example may be a support ticketing platform which allows Open GI to perform a support function to its clients and to internally manage support tickets.

In all cases, Open GI maintains full control of the data it is processing, and where Open GI appoints a sub-processor, it will enter into a contract with each of the sub-processors to regulate their use of the data and to ensure compliance with all relevant legislation. Data is restricted to the minimum that is required to perform the service.

Sub-Processors engaged by Open GI processing client data on behalf of the client

Third partyPurposeApplicable servicesLocation
Associated Open GI group companies
(Machine Learning Programs [MLP Newco 1], Transactor Global Solutions Limited, Powerplace Insurance Services Limited, Open GI London Limited, Open GI Ireland Limited)
Processing of client data for the delivery of the contracted services.Various, including Core, IHP, Ratings, Powerplace, Propensity machine learning models, Mobius, V6, V7UK / EU (Ireland / Poland)
Associated Group Company
Open GI Group LLC Skopje
Software development customer support which can entail processing of client data for support tickets. This processing is performed under the responsibility of Open GI UK.MobiusSkopje, North Macedonia
Associated Group Company
Transactor Poland sp.z.o.o
Software development customer support which can entail processing of client data for support tickets. This processing is performed under the responsibility of Open GI UK.MobiusKrakow, Poland
Microsoft (UK)Provision of cloud hosting services (containers) in Microsoft Azure. Microsoft do not have access to data or process it beyond the provision of storage, network, and compute resources. This includes customers data, policy documents, etc.MobiusUK
Microsoft (Ireland)Provision of cloud hosting services (containers) in Microsoft Azure. Microsoft do not have access to data or process it beyond the provision of storage, network, and compute resources. This includes customers data, policy documents, etc.Ratings, IHPDublin, Ireland
TelehouseProvision of ‘rack’ hosting only (co-location). All compute, storage, and networking is owned and maintained by Open GI. Telehouse have no general access to our systems, data, or our hardware (see below).

Telehouse would otherwise not be deemed a sub-processor, but as we have an agreement for “remote hands” when needed, they are. Remote hands would be cases such as where a system requires a hard reset or a failed hard drive in an array need pulling and replacing where our own employees are unable to attend in time.
Core Cloud, eBroker / Digital Elements, Powerplace, GiHub, Corporate Websites, Support Site, V6/V7UK
OVH CloudHosting of MLP Machine Learning servicesMLP Propensity to Claim, MLP ScoreOVH UK
Mongo DB / Mongo AtlasCloud database storageIHP, Ratings, MobiusDublin, Ireland
COEODatabase managed supportSQL supportUK
Next VentureBridge between eAggregator and Transactor TES agg / MobiusV6/V7, MobiusUK
ThoughtSpotData and Analytics visualisation (charting metrics, etc.)Data and Analytics PlatformUK

Authorised Recipients – Other partners we work with, but who are not processing client data solely via an engagement from Open GI on behalf of the data controller.

These may be data controllers in their own right or processors under instruction from a data controller (please refer to each entities privacy notice). Open GI may provide the platform or conduit to connect the entity such as a broker or insurer to the other party. For example, facilitating the connection of a broker to a credit reference agency.

Third partyPurposeApplicable services
Motor Insurers’ Bureau (My Licence)Enrichment & checking services (UK)Core, Mobius, Ratings, IHP, V6/V7
Royal Mail Group LimitedAddress Lookup Services (UK)Core, V6/V7, Mobius
Close Brothers LimitedPremium Finance (UK)Core, V6/V7, Mobius
WTW RadarEnrichment & checking servicesIHP, Ratings
Premium Credit LimitedPremium FinanceCore, V6/V7, Mobius
Autoaddress (Gamma/Bizmaps)Enrichment & checking servicesCore, IHP, Ratings
Auto Records Limited (Cartell)LookupsCore (ROI)
Carweb LimitedVehicle LookupsCore, V6/V7, Mobius
AccadianEnrichment & screening servicesCore, IHP, Ratings
Creation Consumer Finance Limited (BNP Paribas)Premium FinanceCore, V6/V7
Eagle EyeOutgoing SMS ServiceCore, V6/V7, Mobius (UK)
Equifax LimitedEnrichment & screening servicesCore, IHP, Ratings, V6/V7
Experian LimitedEnrichment & screening servicesCore, V6/7, IHP, Ratings
Flood ReEnrichment & checking services (UK)IHP, Ratings, V6/V7
Global PaymentsProvision of vendor hosted payment iFrames or hosted redirects that OGI embed into its applicable solutionsCore, Mobius, V6 (UK)
LexisNexis Risk Solutions UK LimitedEnrichment & screening servicesCore, V6/7, Mobius, IHP, Ratings (AWS, Ireland)
Loqate (a data controller)Address verification and lookupCore, Digital Services
North DoorSanctionsV6
Opayo / ElevonProvision of vendor hosted payment iFrames or hosted redirects that OGI embed into its applicable solutionsV6/V7
Open DialogVirtual AssistantDigital web platforms (AWS EU)
Percayso Inform LimitedEnrichmentCore, IHP, Ratings, V6/V7 (AWS, UK)
PremFina LimitedPremium Finance (UK)Core, V6/V7
Premium Credit LimitedPremium FinanceCore, V6/V7, Mobius
RadarEnrichment & checking servicesIHP, Ratings
SynecticsClient screening fraud checkingCore, Mobius, V7/V7
Vast VisibilityAggregatorCore, Mobius
VeriskEnrichment, screening, and address lookup servicesCore, V6/7, Mobius, IHP, Ratings

This page was last updated Thursday 10 September 2026. Please check back regularly for updates.

Last update made: Removal of Open GI internal business sub-processors list. These have been moved to our own employee facing Intranet privacy notice. No changes have been made to customer facing sub-processors as part of this update.

i A processor that engages another processor for carrying out specific processing activities on behalf of the controller. The same data protection obligations as set out in the contract or other legal act between the controller and the processor shall be imposed on that other processor by way of a contract or other legal act under local or member state law, in particular providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing will meet the requirements of the GDPR. Where that other processor fails to fulfil its data protection obligations, the initial processor shall remain fully liable to the controller for the performance of that other processor’s obligations.


‍
ii ‘Recipient’ means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not.


‍iii This is a commercial term with no direct GDPR definition or basis. Every sub-processor is a sub-contractor. Not every sub-contractor is a sub-processor. E.g. office cleaners may be sub-contractors but not sub-processors. Or, where a processor engages Microsoft Azure to process the data, Microsoft would be sub-processing with the processor. The key here is, is there any personal data being processed.