TRUST CENTRE · ASSURANCE STANDARD
Subprocessor & Third-Party Service Register
PUBLIC ASSURANCELast updated: September 2026PCL OneVersion 1.0
Scope: PCL One cloud services; service-specific applicability confirmed before production
Baseline Commitment
PCL One maintains a named, service-specific subprocessor list, applies written security and confidentiality obligations, limits provider access to what is necessary, and gives advance notice of material changes before a new provider begins processing customer data where practicable.
Service provider register
| Provider | Purpose | Customer-data treatment | Status |
|---|---|---|---|
| Microsoft Azure | Cloud infrastructure, networking, storage, backup and recovery services for the municipal cloud baseline | Customer data may be hosted or processed where Azure is selected for the service. For Canada-only municipal deployments, approved Canadian regions are used and final regions are documented in the service schedule. | Applicable where selected for hosting |
| MongoDB | Database technology or managed database service used by selected PCL One architectures. | Applies only where included in the subscribed service design. Processing scope and location are documented in the service-specific schedule. | Conditional - architecture dependent |
| OpenAI | AI service provider for specifically approved AI-assisted capabilities where enabled. | Used only for approved use cases. Customer data is not used to train generalized or shared models. AI capabilities may be restricted or disabled according to the service design. | Conditional - feature dependent |
Service-specific disclosure
The providers listed in this register represent services that may support PCL One’s cloud environment. A customer-specific subprocessor schedule includes only providers that actually process customer data for the subscribed service. Applicability, processing purpose and location are confirmed before production use.
Onboarding and change controls
- Security, privacy, confidentiality and service-dependency risks are assessed before a provider is used for customer processing.
- Written contractual obligations are flowed down to the provider appropriate to its role and the sensitivity of the data involved.
- Access to customer data is limited to the minimum necessary, role-controlled and logged where access is required.
- PCL One remains responsible for its contractual obligations to the customer when subprocessors are used.
- PCL One provides advance written notice of a material subprocessor change before processing begins where practicable and provides sufficient information for the customer to assess the change.
- A customer may raise a reasonable data-protection objection. PCL One will work in good faith to mitigate the concern or identify a practical alternative, subject to the contracted service.
What a customer-specific register records
| Field | Recorded information |
|---|---|
| Provider | Legal / service provider name |
| Purpose | Service function performed |
| Data categories | Types of customer data processed, if any |
| Location | Approved processing/storage region or jurisdiction |
| Access model | Whether provider personnel may access customer data and under what controls |
| Change date | Date added, changed or removed from the customer schedule |
Assurance records
- Customer-specific subprocessor schedule
- Provider due-diligence / risk assessment record
- Applicable contractual security/privacy clauses
- Material-change notification record
- Relevant provider assurance reports or certifications, subject to confidentiality
Applicability
A customer agreement, service schedule or stricter applicable law may set additional or different requirements for a specific service.