Security Measures
and Sub-Processors


As incorporated into LightWork’s Data Processing Agreement

Annex 1: Security measures

Technical and organisational
measures to ensure the
security of Personal Data

Technical measures

  • All workloads run on Google Cloud Platform (GCP), deployed strictly in EU regions (London or other EU zones only).

  • MongoDB (EU region) is our primary database. Data is encrypted at rest with AES-256 and encrypted in transit (TLS).

  • We maintain periodic automated backups of all production databases with secure storage and controlled access.

  • Qdrant (EU region) is used as our vector database, and Redis Cloud (EU region) is used for caching.

  • Access to infrastructure is restricted via IAM, MFA-enforced accounts and least-privilege roles.

  • Services run in private networks with firewalls and VPC-level isolation.

  • Monitoring, alerting and log management are handled by Datadog, configured within EU regions.

  • We use Vanta to continuously monitor our security position and maintain compliance with ISO27001:2022 and SOC2 frameworks.

  • All software is kept up-to-date and security updates are installed as soon as reasonably possible.

Organisational measures

  • Operational practices include regular patching, vulnerability scanning, penetration testing and maintaining incident management and response processes.

  • Making all employees and third-party agents fully aware of their individual responsibilities under the UK GDPR.

Annex 2: Sub-processors


Current sub-processors


Name of Sub- processor

Location of Processing

Transfer mechanism

OpenAI (ChatGPT): foundational model provider

EEA

N/A

Google (Gemini) foundational model provider

EEA

N/A

Google Cloud Platform (GCP): cloud infrastructure

EEA

N/A

MongoDB Atlas: primary database

EEA

N/A

Qdrant Cloud: vector database

EEA

N/A

Redis Cloud: caching

EEA

N/A

Nylas: email service provider

EEA

N/A


Version

Date

Description

Author

Approved By

1.0

25 March 2026

Security Measures and Sub-Processors

James Wilson

Rameen Sorkhabi

Ready to let Felicity handle the admin?

Book a 20-minute walkthrough to see exactly what Felicity would handle for your team.

© 2026 LightWork Holding Ltd. Company No. 15027977 · VAT: GB488579216

83 Victoria Street, London, SW1H 0HW

Ready to let Felicity handle
the admin?

Book a 20-minute walkthrough to see exactly what Felicity would handle for your team.

© 2026 LightWork Holding Ltd. Company No. 15027977 · VAT: GB488579216

83 Victoria Street, London, SW1H 0HW

Ready to let Felicity handle the admin?

Book a 20-minute walkthrough to see exactly what Felicity would handle for your team.

© 2026 LightWork Holding Ltd. Company No. 15027977 · VAT: GB488579216

83 Victoria Street, London, SW1H 0HW