Skip to main content
← Back

Sub-processors

Last updated 16 July 2026

The platform is operated as a data processor for each academy (the data controller of its students' and staff's personal data). To deliver the service, the operator engages the sub-processors below under written data-protection terms consistent with Article 28 GDPR. Where a sub-processor is outside the EU/EEA, transfers rely on the European Commission's Standard Contractual Clauses (SCCs) and/or the vendor's EU–US Data Privacy Framework (DPF) certification, as listed per vendor. Each DPA link points to the vendor's own official document.

Academies receive advance notice of material changes to this list so they may object. See also the Privacy Policy.

Active sub-processors

These vendors currently process personal data on the academies' behalf as part of delivering the service.

Active sub-processors
VendorPurposePersonal dataLocation / regionTransfer mechanismDPA
ElevenLabsSpeech-to-text and the synthesised voice of the speaking interlocutor / AI tutor (text-to-speech + conversational AI)Candidate raw spoken audio (realtime speech-to-text during Speaking) and exam text to be voicedUnited States (EU residency available on the Enterprise tier only)SCCs (Modules 2 + 3) + EU–US Data Privacy Framework (certified)ElevenLabs DPA
SimliPhoto-real avatar rendering (lip-sync) for the speaking interlocutor / AI tutorCandidate live audio/video used to render the lip-synced avatar sessionNorway (EEA) — Simli AS, OsloIntra-EEA to Simli (Norwegian entity); SCCs (Module 4) in its DPA; Simli's own US sub-processors carry the third-country exposureSimli DPA (v002, Aug 2024)
LiveKitRealtime WebRTC media transport for the live speaking session (engaged via Simli's avatar service)Candidate live voice and video, transported in real time (transient — routed, not stored), plus connection/session metadataUnited States (LiveKit Cloud; EU region-pinning available per project)SCCs (Modules 1, 2 + 3); DPF self-certification under verificationLiveKit DPA (2025-11-18)
AnthropicAI-assisted grading, tutoring and coaching of exam responses (Claude)Candidate written responses, speaking transcripts and tutor/coach contextUnited States / global (no EU residency for the API)SCCs (Modules 2 + 3) + UK and Swiss addenda (no DPF reliance)Anthropic DPA (2025-02-24)
AWS (Amazon Web Services)Production infrastructure — compute (Fargate), database (Aurora PostgreSQL), object storage (S3) and secrets managementAll authoritative platform data: candidate account data, exam attempts, answers and scores, rosters, credentials (hashed) and the audit logEU — Frankfurt (eu-central-1); data at rest stays in the selected regionProcessing pinned in-region (EU); 2021 SCCs auto-apply to any ancillary transfer; EU–US Data Privacy Framework (certified)AWS GDPR DPA (Service Terms §1.14)
AWS SESTransactional email — invitations and notifications (per-academy sending domains)Recipient name and email address, and message contentEU sending region (per tenant) — an AWS serviceCovered by the AWS GDPR DPA (row above); in-region EU sendingCovered by the AWS DPA
CloudflareContent delivery, object storage for exam media (R2), WAF and edge routingExam content (audio/images — not per-candidate records) and edge traffic metadata (IP address, host headers) of users transiting the networkGlobal edge network (EU localisation via a separate Data Localization Suite product)SCCs (Modules 2 + 3) + EU–US Data Privacy Framework (certified)Cloudflare Customer DPA (v6.4, 2026-04-03)
VercelStaging and preview hosting (production runs on AWS)Staging/demo and QA-pilot data; residual pilot-era file storage (Blob)United States / global (no EU residency option)SCCs (Modules 1, 2 + 3) + EU–US Data Privacy Framework (certified)Vercel DPA (2026-03-31)
StripePayment processing and payouts (Stripe Connect). Dual role: processor for merchant payment processing, and independent controller for fraud detection, loss mitigation and AML/KYCBilling identifiers, payer name and email, connected-account onboarding data (card data goes to Stripe directly — the platform never stores card numbers)United States / global (no customer-selectable EU residency)SCCs (Modules 1 + 2) + UK IDTA + EU–US Data Privacy Framework (certified)Stripe DPA (2025-11-18)
SlackQA reviewer feedback channels (exam-review workflow)Reviewer identity and report message content (may include exam screenshots); candidate personal data is kept out by policyUnited States (EU residency on Business+/Enterprise tiers only)SCCs (2021, deemed-executed) + DPF via parent Salesforce, Inc.Salesforce DPA (Apr 2026, via Slack)
GitHubSource control, CI/CD and the QA feedback dispatch pipelineSource code and CI logs (no production candidate data by design); QA dispatch payloads carry reviewer report textUnited States / globalSCCs (Modules 2 + 3) + EU–US Data Privacy Framework (certified)GitHub Data Protection Agreement (Oct 2025)

Approved, not currently active

These vendors are integrated or approved but do not currently process personal data (the integration is dormant or not yet enabled). They are listed for transparency; they will not be activated for production data before the applicable data-processing agreement is in place.

Approved vendors not currently processing personal data
VendorPurposePersonal dataLocation / regionTransfer mechanismDPA
WorkOSStaff identity — SSO / AuthKit / directory sync (SCIM) for enterprise academiesStaff and admin identity (name, email, organisation, authentication events) — no data flows until the integration is activatedUnited States (no EU hosting commitment)SCCs (Modules 2 + 3) — SCC-only (no DPF listing found)WorkOS DPA (2023-06-27)
SentryApplication error reporting (observability)Error events and stack traces (may embed user identifiers) — no data flows until the integration is enabledEU region available (Frankfurt), chosen at organisation creationSCCs (Modules 2 + 3) + UK AddendumSentry DPA (v5.1.0, 2024-05-29)
ResendTransactional email (dormant — superseded by AWS SES)Recipient email and message content — no data flows while dormantUnited States (no EU residency)SCCs (Modules 1, 2 + 3) + UK/Swiss addenda; DPF claimed (under verification)Resend DPA
OpenAIAlternate AI model path (not active — no key configured)Would receive the same class of data as Anthropic IF ever enabled — no data flows todayUnited States (EU residency at project level, gated)SCCs (Modules 2 + 3) + UK Addendum (not DPF-listed)OpenAI DPA (v.010126)

Where the operator is the controller

For the vendors below, the platform operator acts as the data controller in its own right (for example, marketing enquiries from prospective academies). This is a separate legal seat from the candidate-data chain above — no candidate or exam data is involved.

Processors engaged where the operator is the controller
VendorPurposePersonal dataLocation / regionTransfer mechanismDPA
HubSpotMarketing lead management (CRM) for the public website — ProficientHub is the data controller for this processingProspective-customer contact data (name, email, academy, locale) — never candidate or exam dataUnited States (EU data centre in Frankfurt on paid tiers)SCCs (Modules 2 + 3) + EU–US Data Privacy Framework (certified)HubSpot DPA (2026-04-14)

Stripe additionally acts as an independent controller for its own fraud-detection, loss-mitigation and AML/KYC processing (see its DPA). Sign in with Google is not a sub-processor: when you choose to sign in with a Google Account, Google acts as an independent controller of that account under its own terms — see the Privacy Policy for details.