---
title: "Trust & subprocessors — Omra"
description: "The public subprocessor register and the register of where omra uses AI, both readable as JSON without an account."
canonical: https://clubomra.com/trust
last-updated: 2026-08-23
---
# Trust and subprocessors

> Two public registers — the companies that process data for omra, and where omra
> uses AI and what it may decide. Neither needs an account to read, and neither is
> specific to a club.

## When to use this page

- Listing who processes club data on Omra's behalf, and where Omra uses AI.
- Answering a due-diligence or DPA question with a machine-readable source.

A club is the controller for its own member data. Omra processes it on the club's
instructions.

## The registers, as data

Both registers are code-defined, identical for every caller, and served as JSON
without authentication:

- Subprocessors: `GET https://api.clubomra.com/trust/subprocessors`
  — returns a controller statement and, per subprocessor, its name, purpose, data
  categories, location, DPA URL, effective date and whether it is active or merely
  announced.
- AI systems: `GET https://api.clubomra.com/trust/ai-systems`
  — returns a statement and, per system, its purpose, the human oversight applied
  to it, and whether it is live.

Read the JSON rather than this page when you need the current list: the registers
change without this summary changing.

## Where omra uses AI

- **Monthly written summary** — decides nothing.
- **Ranking overdue accounts, new applications and renewal risk** — a person
  approves every action.
- **Follow-up calls** — a person approves each run.

## Asking about your data

Write to hello@clubomra.com for a data protection question, a subprocessor query, or
to ask what omra holds about a member.
