Lemric Subprocessor List
As of: 9 August 2026 | Version: 2.0
Questions and objections: privacy@lemric.com
This list is the source of truth for Lemric subprocessors referred to in the DPA (Article 28 GDPR) and the Privacy Policy.
1. Active providers
| Provider | Processing purpose | Region / location | Notes |
|---|---|---|---|
| Amazon Web Services (Simple Email Service) | Sending Service, account, and notification messages | eu-central-1 | Transactional mail and notifications |
| Cloudflare (R2) | Storage of attachments and exports encrypted by the application | Per provider agreement | Encryption on the Lemric application side |
| OVH | Production hosting of the application and supporting services (Lemric infrastructure) | Poland (EEA) | Production environment under the Lemric brand |
2. Conditional providers
Data are transferred only after the stated condition is met:
| Provider | Processing purpose |
|---|---|
| Revolut Merchant | Payments |
| Google Analytics | Optional site analytics |
| iFirma | Invoices and bookkeeping data |
3. Recipients chosen by the Customer
Jira and webhooks are configured by the Customer. They are not permanent Lemric subprocessors. They are recipients acting on the Customer’s instruction.
4. Changes to the list
- Before adding or replacing a subprocessor of Entrusted Data, Lemric will give electronic notice.
- Exception: an urgent change needed for security or continuity may take effect earlier, with notice given as soon as reasonably possible.
- An objection on data protection grounds may be sent to privacy@lemric.com within the period stated in the notice.
- The detailed objection procedure and effects follow from the DPA.
Related documents:
- DPA: https://lemric.com/en/legal/dpa
- Privacy Policy: https://lemric.com/en/legal/privacy
- Terms: https://lemric.com/en/legal/terms
As of: 9 August 2026
Document version: 2.0