NODE · LON-01|LONDON --:--:--
DC-Services — Digital Claims Services Limited
Legal Documentation

DC-Services UK Subprocessor Register

Published register of categories of approved providers used in service delivery.

This register lists the categories of third-party providers that may, under contract, support Digital Claims Services Limited (trading as DC-SERVICES UK) in delivering documentation services. It is informational and does not constitute financial, investment, legal or tax advice.

Last reviewed: February 2026 · 20 sections

subprocessor-register.pdf · A4 · brandedAll documents
01

Purpose of subprocessors

  1. 1.1Subprocessors are used only where necessary to deliver documentation services securely, reliably and to a defined standard.
  2. 1.2A subprocessor is a third party engaged by DC-SERVICES UK to process personal data on its behalf as part of an engagement.
  3. 1.3Each category is justified, contracted and reviewed before any client data is shared.
  4. 1.4This page is published so clients can see the categories relied upon and raise objections where needed.
02

Difference between processor and subprocessor

  1. 2.1Where DC-SERVICES UK is acting as a processor for a client, any further providers it engages are subprocessors of that client.
  2. 2.2A processor handles data on instructions from a controller; a subprocessor handles data on instructions from the processor.
  3. 2.3The legal chain of obligations flows from controller, to processor, to subprocessor without weakening data-protection standards.
  4. 2.4Clients are told in writing whether a given provider is a subprocessor or a controller in its own right.
03

Categories of approved providers

  1. 3.1Approved providers fall into defined categories: hosting, security, communications, payment processing and document storage.
  2. 3.2Categories are reviewed by the Compliance Office before new providers may be added.
  3. 3.3Only providers passing due diligence are placed on the approved list.
  4. 3.4The current categories are listed below; specific provider names can be disclosed to clients on request under NDA.
04

Hosting providers

  1. 4.1Hosting providers supply the infrastructure on which client portals, documents and operational systems run.
  2. 4.2Hosting is selected to keep client data within the UK or EEA wherever technically possible.
  3. 4.3Hosting contracts include UK GDPR-aligned data-processing terms, security obligations and breach-notification timelines.
  4. 4.4Clients are told when a hosting change materially affects data location or access controls.
05

Security providers

  1. 5.1Security providers supply controls such as identity, endpoint protection, monitoring and vulnerability scanning.
  2. 5.2Security providers do not receive client documentation content; they receive technical telemetry to defend the estate.
  3. 5.3Their access is limited to security functions and is audited internally.
  4. 5.4Where a security incident involves a security provider, the client is told within the timeframe required by law.
06

Communication providers

  1. 6.1Communication providers handle email, secure messaging and case-update notifications.
  2. 6.2Communication providers process metadata (sender, recipient, timestamps) and the content of messages sent through them.
  3. 6.3Sensitive client documents are not sent through standard email; they are exchanged via the secure portal.
  4. 6.4Clients are advised of the communication channels used and any related limitations.
07

Payment providers where applicable

  1. 7.1Where fees are collected by card or bank transfer, a regulated payment provider processes the transaction.
  2. 7.2Payment providers act as independent controllers for the payment instrument data they collect.
  3. 7.3DC-SERVICES UK does not store full card numbers or banking credentials.
  4. 7.4Receipts and invoices are issued by DC-SERVICES UK; payment confirmations come from the payment provider.
08

Document storage providers

  1. 8.1Document storage providers supply encrypted storage for client materials and deliverables for the duration of retention.
  2. 8.2Storage providers cannot read document content where end-to-end encryption is in place.
  3. 8.3Access by storage provider staff is restricted, logged and reviewed.
  4. 8.4Storage location is preferred within the UK or EEA and is disclosed in the engagement letter.
09

Access control expectations

  1. 9.1Every approved provider must support role-based access control and multi-factor authentication for staff with access to systems holding client data.
  2. 9.2Access control means only people who need data to do their job can reach it.
  3. 9.3Provider access is reviewed at least annually and on staff changes.
  4. 9.4Clients can request the high-level access model applied to their data.
10

Confidentiality obligations

  1. 10.1Every approved provider is bound by confidentiality obligations equivalent to those owed by DC-SERVICES UK to its clients.
  2. 10.2Confidentiality obligations survive termination of the provider contract.
  3. 10.3Provider staff are bound by employment-level confidentiality undertakings.
  4. 10.4Confidentiality terms are not negotiable below DC-SERVICES UK's published baseline.
11

Data processing agreements

  1. 11.1Every approved provider executes a UK GDPR Article 28-aligned Data Processing Agreement before any client data is shared.
  2. 11.2The DPA sets out purposes, categories of data, security measures, sub-processing rules and breach-notification timelines.
  3. 11.3DPAs are maintained centrally by the Compliance Office and made available to clients on request under NDA.
  4. 11.4DPAs are renewed when a provider's services materially change.
12

Geographic processing locations

  1. 12.1Processing locations are recorded per provider and per category of data.
  2. 12.2Locations cover both primary storage and any backup or disaster-recovery sites.
  3. 12.3Locations are reviewed when a provider opens new regions or retires old ones.
  4. 12.4Clients can request the locations applicable to their data.
13

UK and EEA processing preference

  1. 13.1Where multiple locations are technically possible, DC-SERVICES UK selects providers whose default processing is within the UK or EEA.
  2. 13.2This preference reduces the need for restricted transfer safeguards and simplifies oversight.
  3. 13.3Where a non-UK/EEA option is the only viable provider, the additional safeguard is documented before adoption.
  4. 13.4Clients are told if a provider operates outside the UK or EEA in respect of their engagement.
14

International transfer safeguards

  1. 14.1Restricted international transfers, where they occur, are protected by the UK International Data Transfer Agreement, the UK Addendum to the EU SCCs, or an adequacy decision.
  2. 14.2A Transfer Risk Assessment is recorded for each restricted transfer before it begins.
  3. 14.3Additional technical measures (such as in-transit and at-rest encryption) are layered on top of the legal safeguard.
  4. 14.4Clients are told which safeguard applies to any restricted transfer affecting their data.
15

Client notification of changes

  1. 15.1Material changes to the subprocessor categories used for active engagements are notified in writing.
  2. 15.2Notification gives clients a reasonable window to raise objections before the change takes effect.
  3. 15.3Notification is sent through the secure portal and the engagement email address.
  4. 15.4Notification is also published as a change to this page with a new 'Last reviewed' date.
16

Objection process

  1. 16.1Clients may object to a proposed subprocessor change on reasonable grounds within the notification window.
  2. 16.2Objections are reviewed by the Compliance Office; reasonable alternatives are offered where possible.
  3. 16.3If no acceptable alternative exists, the client may terminate the affected engagement without penalty.
  4. 16.4Objection outcomes are recorded with reasoning and provided to the client in writing.
17

Subprocessor due diligence

  1. 17.1Due diligence is performed before any provider is added to the approved list.
  2. 17.2Due diligence covers corporate identity, data-protection posture, security certifications, financial stability and incident history.
  3. 17.3Findings are scored against an internal threshold; failures block onboarding.
  4. 17.4Due diligence packs are retained and refreshed at defined intervals.
18

Security review process

  1. 18.1Approved providers are subject to periodic security reviews including evidence requests, control testing and incident debriefs.
  2. 18.2Reviews focus on access control, encryption, monitoring, vulnerability management and breach response.
  3. 18.3Findings drive remediation requests or, where remediation fails, removal from the approved list.
  4. 18.4Clients are told if a security review produces findings affecting the safety of their data.
19

Removal or replacement of providers

  1. 19.1Providers may be removed for breach, performance failure or change in risk posture, or replaced where a better option becomes available.
  2. 19.2Removal is planned to avoid service interruption and data loss.
  3. 19.3Migration to a replacement provider is logged and tested before cutover.
  4. 19.4Clients are told before, during and after a removal or replacement affecting their data.
20

Register update schedule

  1. 20.1This register is reviewed at least annually and updated whenever a category or significant provider changes.
  2. 20.2The Compliance Office owns the review; the Data Protection Officer signs off changes affecting personal data.
  3. 20.3Updates are version-controlled and published with a new 'Last reviewed' date.
  4. 20.4Historical versions are retained internally for audit purposes.
Frequently Asked Questions

Questions about this page

Can I see the names of specific subprocessors?
Provider names can be disclosed to active clients on request under a non-disclosure agreement. Categories and locations are published here.
Where is my data stored?
By default within the UK or EEA. If a restricted transfer applies to your engagement we tell you which safeguard is in place.
How will I be told if a subprocessor changes?
We notify active clients in writing before a material change and give a reasonable window to object.
Can I object to a subprocessor?
Yes, on reasonable grounds. We will offer an alternative where possible or allow you to terminate the affected engagement without penalty.