In order to provide the services that we offer as efficiently as possible, Open GI (and associated companies) may use third parties to perform certain functions and in doing so, they may process customer data or personal data as part of the service. In some circumstances, the third party may have been appointed by Open GI’s client to act as their processor or the third party may be a data controller itself, but in other circumstances the third party may be acting directly as a sub-processor of Open GI under Open GI’s general written agreement to appoint sub-processors to process client data on the data controller’s behalf.
This list separates the following entities which we have defined in this notice:
Sub-Processori: This is a data protection term under GDPR Art 28(4) and will apply to entities (including some applicable sub-contractors) where Open GI engaged them under the client’s general authorisation to carry out part of the processing Open GI performs on the client’s behalf. They will process client data only within the purposes the client has determined and on the client’s instructions, passed down through Open GI, and never for any purpose of its own. Open GI’s selection determines the technical means of implementation only. The client determines the purposes and essential means of the data. Open GI do not determine its own purposes for the data processing. We notify the client of this appointment and provide them with an opportunity to object to the appointment of the sub-processor.
Authorised ‘Recipient’ii: The client engaged it directly or have a business relationship with them to perform part of a processing function; for example, an Insurer. It processes on the client’s behalf, but we are a peer in the chain, not its principal. We merely route data to it on instruction through our platforms in order to facilitate processing functions such as enrichments, lookups, fraud checks, etc. A recipient is defined in the UK and EU GDPR (see footnote 2).
Sub-Contractoriii: Any third party we partner with to help deliver a service or provide supporting services to Open GI. In some cases, these may be mutual to Open GI and its clients who are data controllers. Data may be processed as part of an agreed contract or arrangement. This may not be personal data. An example may be a support ticketing platform which allows Open GI to perform a support function to its clients and to internally manage support tickets.
In all cases, Open GI maintains full control of the data it is processing, and where Open GI appoints a sub-processor, it will enter into a contract with each of the sub-processors to regulate their use of the data and to ensure compliance with all relevant legislation. Data is restricted to the minimum that is required to perform the service.
Sub-Processors engaged by Open GI processing client data on behalf of the client
| Third party | Purpose | Applicable services | Location |
|---|---|---|---|
| Associated Open GI group companies (Machine Learning Programs [MLP Newco 1], Transactor Global Solutions Limited, Powerplace Insurance Services Limited, Open GI London Limited, Open GI Ireland Limited) | Processing of client data for the delivery of the contracted services. | Various, including Core, IHP, Ratings, Powerplace, Propensity machine learning models, Mobius, V6, V7 | UK / EU (Ireland / Poland) |
| Associated Group Company Open GI Group LLC Skopje | Software development customer support which can entail processing of client data for support tickets. This processing is performed under the responsibility of Open GI UK. | Mobius | Skopje, North Macedonia |
| Associated Group Company Transactor Poland sp.z.o.o | Software development customer support which can entail processing of client data for support tickets. This processing is performed under the responsibility of Open GI UK. | Mobius | Krakow, Poland |
| Microsoft (UK) | Provision of cloud hosting services (containers) in Microsoft Azure. Microsoft do not have access to data or process it beyond the provision of storage, network, and compute resources. This includes customers data, policy documents, etc. | Mobius | UK |
| Microsoft (Ireland) | Provision of cloud hosting services (containers) in Microsoft Azure. Microsoft do not have access to data or process it beyond the provision of storage, network, and compute resources. This includes customers data, policy documents, etc. | Ratings, IHP | Dublin, Ireland |
| Telehouse | Provision of ‘rack’ hosting only (co-location). All compute, storage, and networking is owned and maintained by Open GI. Telehouse have no general access to our systems, data, or our hardware (see below). Telehouse would otherwise not be deemed a sub-processor, but as we have an agreement for “remote hands” when needed, they are. Remote hands would be cases such as where a system requires a hard reset or a failed hard drive in an array need pulling and replacing where our own employees are unable to attend in time. | Core Cloud, eBroker / Digital Elements, Powerplace, GiHub, Corporate Websites, Support Site, V6/V7 | UK |
| OVH Cloud | Hosting of MLP Machine Learning services | MLP Propensity to Claim, MLP Score | OVH UK |
| Mongo DB / Mongo Atlas | Cloud database storage | IHP, Ratings, Mobius | Dublin, Ireland |
| COEO | Database managed support | SQL support | UK |
| Next Venture | Bridge between eAggregator and Transactor TES agg / Mobius | V6/V7, Mobius | UK |
| ThoughtSpot | Data and Analytics visualisation (charting metrics, etc.) | Data and Analytics Platform | UK |
Authorised Recipients – Other partners we work with, but who are not processing client data solely via an engagement from Open GI on behalf of the data controller.
These may be data controllers in their own right or processors under instruction from a data controller (please refer to each entities privacy notice). Open GI may provide the platform or conduit to connect the entity such as a broker or insurer to the other party. For example, facilitating the connection of a broker to a credit reference agency.
| Third party | Purpose | Applicable services |
|---|---|---|
| Motor Insurers’ Bureau (My Licence) | Enrichment & checking services (UK) | Core, Mobius, Ratings, IHP, V6/V7 |
| Royal Mail Group Limited | Address Lookup Services (UK) | Core, V6/V7, Mobius |
| Close Brothers Limited | Premium Finance (UK) | Core, V6/V7, Mobius |
| WTW Radar | Enrichment & checking services | IHP, Ratings |
| Premium Credit Limited | Premium Finance | Core, V6/V7, Mobius |
| Autoaddress (Gamma/Bizmaps) | Enrichment & checking services | Core, IHP, Ratings |
| Auto Records Limited (Cartell) | Lookups | Core (ROI) |
| Carweb Limited | Vehicle Lookups | Core, V6/V7, Mobius |
| Accadian | Enrichment & screening services | Core, IHP, Ratings |
| Creation Consumer Finance Limited (BNP Paribas) | Premium Finance | Core, V6/V7 |
| Eagle Eye | Outgoing SMS Service | Core, V6/V7, Mobius (UK) |
| Equifax Limited | Enrichment & screening services | Core, IHP, Ratings, V6/V7 |
| Experian Limited | Enrichment & screening services | Core, V6/7, IHP, Ratings |
| Flood Re | Enrichment & checking services (UK) | IHP, Ratings, V6/V7 |
| Global Payments | Provision of vendor hosted payment iFrames or hosted redirects that OGI embed into its applicable solutions | Core, Mobius, V6 (UK) |
| LexisNexis Risk Solutions UK Limited | Enrichment & screening services | Core, V6/7, Mobius, IHP, Ratings (AWS, Ireland) |
| Loqate (a data controller) | Address verification and lookup | Core, Digital Services |
| North Door | Sanctions | V6 |
| Opayo / Elevon | Provision of vendor hosted payment iFrames or hosted redirects that OGI embed into its applicable solutions | V6/V7 |
| Open Dialog | Virtual Assistant | Digital web platforms (AWS EU) |
| Percayso Inform Limited | Enrichment | Core, IHP, Ratings, V6/V7 (AWS, UK) |
| PremFina Limited | Premium Finance (UK) | Core, V6/V7 |
| Premium Credit Limited | Premium Finance | Core, V6/V7, Mobius |
| Radar | Enrichment & checking services | IHP, Ratings |
| Synectics | Client screening fraud checking | Core, Mobius, V7/V7 |
| Vast Visibility | Aggregator | Core, Mobius |
| Verisk | Enrichment, screening, and address lookup services | Core, V6/7, Mobius, IHP, Ratings |
This page was last updated Thursday 10 September 2026. Please check back regularly for updates.
Last update made: Removal of Open GI internal business sub-processors list. These have been moved to our own employee facing Intranet privacy notice. No changes have been made to customer facing sub-processors as part of this update.
i A processor that engages another processor for carrying out specific processing activities on behalf of the controller. The same data protection obligations as set out in the contract or other legal act between the controller and the processor shall be imposed on that other processor by way of a contract or other legal act under local or member state law, in particular providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing will meet the requirements of the GDPR. Where that other processor fails to fulfil its data protection obligations, the initial processor shall remain fully liable to the controller for the performance of that other processor’s obligations.
ii ‘Recipient’ means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not.
iii This is a commercial term with no direct GDPR definition or basis. Every sub-processor is a sub-contractor. Not every sub-contractor is a sub-processor. E.g. office cleaners may be sub-contractors but not sub-processors. Or, where a processor engages Microsoft Azure to process the data, Microsoft would be sub-processing with the processor. The key here is, is there any personal data being processed.