The platform is operated as a data processor for each academy (the data controller of its students' and staff's personal data). To deliver the service, the operator engages the sub-processors below under written data-protection terms consistent with Article 28 GDPR. Where a sub-processor is outside the EU/EEA, transfers rely on the European Commission's Standard Contractual Clauses (SCCs) and/or the vendor's EU–US Data Privacy Framework (DPF) certification, as listed per vendor. Each DPA link points to the vendor's own official document.
Academies receive advance notice of material changes to this list so they may object. See also the Privacy Policy.
Active sub-processors
These vendors currently process personal data on the academies' behalf as part of delivering the service.
| Vendor | Purpose | Personal data | Location / region | Transfer mechanism | DPA |
|---|---|---|---|---|---|
| ElevenLabs | Speech-to-text and the synthesised voice of the speaking interlocutor / AI tutor (text-to-speech + conversational AI) | Candidate raw spoken audio (realtime speech-to-text during Speaking) and exam text to be voiced | United States (EU residency available on the Enterprise tier only) | SCCs (Modules 2 + 3) + EU–US Data Privacy Framework (certified) | ElevenLabs DPA |
| Simli | Photo-real avatar rendering (lip-sync) for the speaking interlocutor / AI tutor | Candidate live audio/video used to render the lip-synced avatar session | Norway (EEA) — Simli AS, Oslo | Intra-EEA to Simli (Norwegian entity); SCCs (Module 4) in its DPA; Simli's own US sub-processors carry the third-country exposure | Simli DPA (v002, Aug 2024) |
| LiveKit | Realtime WebRTC media transport for the live speaking session (engaged via Simli's avatar service) | Candidate live voice and video, transported in real time (transient — routed, not stored), plus connection/session metadata | United States (LiveKit Cloud; EU region-pinning available per project) | SCCs (Modules 1, 2 + 3); DPF self-certification under verification | LiveKit DPA (2025-11-18) |
| Anthropic | AI-assisted grading, tutoring and coaching of exam responses (Claude) | Candidate written responses, speaking transcripts and tutor/coach context | United States / global (no EU residency for the API) | SCCs (Modules 2 + 3) + UK and Swiss addenda (no DPF reliance) | Anthropic DPA (2025-02-24) |
| AWS (Amazon Web Services) | Production infrastructure — compute (Fargate), database (Aurora PostgreSQL), object storage (S3) and secrets management | All authoritative platform data: candidate account data, exam attempts, answers and scores, rosters, credentials (hashed) and the audit log | EU — Frankfurt (eu-central-1); data at rest stays in the selected region | Processing pinned in-region (EU); 2021 SCCs auto-apply to any ancillary transfer; EU–US Data Privacy Framework (certified) | AWS GDPR DPA (Service Terms §1.14) |
| AWS SES | Transactional email — invitations and notifications (per-academy sending domains) | Recipient name and email address, and message content | EU sending region (per tenant) — an AWS service | Covered by the AWS GDPR DPA (row above); in-region EU sending | Covered by the AWS DPA |
| Cloudflare | Content delivery, object storage for exam media (R2), WAF and edge routing | Exam content (audio/images — not per-candidate records) and edge traffic metadata (IP address, host headers) of users transiting the network | Global edge network (EU localisation via a separate Data Localization Suite product) | SCCs (Modules 2 + 3) + EU–US Data Privacy Framework (certified) | Cloudflare Customer DPA (v6.4, 2026-04-03) |
| Vercel | Staging and preview hosting (production runs on AWS) | Staging/demo and QA-pilot data; residual pilot-era file storage (Blob) | United States / global (no EU residency option) | SCCs (Modules 1, 2 + 3) + EU–US Data Privacy Framework (certified) | Vercel DPA (2026-03-31) |
| Stripe | Payment processing and payouts (Stripe Connect). Dual role: processor for merchant payment processing, and independent controller for fraud detection, loss mitigation and AML/KYC | Billing identifiers, payer name and email, connected-account onboarding data (card data goes to Stripe directly — the platform never stores card numbers) | United States / global (no customer-selectable EU residency) | SCCs (Modules 1 + 2) + UK IDTA + EU–US Data Privacy Framework (certified) | Stripe DPA (2025-11-18) |
| Slack | QA reviewer feedback channels (exam-review workflow) | Reviewer identity and report message content (may include exam screenshots); candidate personal data is kept out by policy | United States (EU residency on Business+/Enterprise tiers only) | SCCs (2021, deemed-executed) + DPF via parent Salesforce, Inc. | Salesforce DPA (Apr 2026, via Slack) |
| GitHub | Source control, CI/CD and the QA feedback dispatch pipeline | Source code and CI logs (no production candidate data by design); QA dispatch payloads carry reviewer report text | United States / global | SCCs (Modules 2 + 3) + EU–US Data Privacy Framework (certified) | GitHub Data Protection Agreement (Oct 2025) |
Approved, not currently active
These vendors are integrated or approved but do not currently process personal data (the integration is dormant or not yet enabled). They are listed for transparency; they will not be activated for production data before the applicable data-processing agreement is in place.
| Vendor | Purpose | Personal data | Location / region | Transfer mechanism | DPA |
|---|---|---|---|---|---|
| WorkOS | Staff identity — SSO / AuthKit / directory sync (SCIM) for enterprise academies | Staff and admin identity (name, email, organisation, authentication events) — no data flows until the integration is activated | United States (no EU hosting commitment) | SCCs (Modules 2 + 3) — SCC-only (no DPF listing found) | WorkOS DPA (2023-06-27) |
| Sentry | Application error reporting (observability) | Error events and stack traces (may embed user identifiers) — no data flows until the integration is enabled | EU region available (Frankfurt), chosen at organisation creation | SCCs (Modules 2 + 3) + UK Addendum | Sentry DPA (v5.1.0, 2024-05-29) |
| Resend | Transactional email (dormant — superseded by AWS SES) | Recipient email and message content — no data flows while dormant | United States (no EU residency) | SCCs (Modules 1, 2 + 3) + UK/Swiss addenda; DPF claimed (under verification) | Resend DPA |
| OpenAI | Alternate AI model path (not active — no key configured) | Would receive the same class of data as Anthropic IF ever enabled — no data flows today | United States (EU residency at project level, gated) | SCCs (Modules 2 + 3) + UK Addendum (not DPF-listed) | OpenAI DPA (v.010126) |
Where the operator is the controller
For the vendors below, the platform operator acts as the data controller in its own right (for example, marketing enquiries from prospective academies). This is a separate legal seat from the candidate-data chain above — no candidate or exam data is involved.
| Vendor | Purpose | Personal data | Location / region | Transfer mechanism | DPA |
|---|---|---|---|---|---|
| HubSpot | Marketing lead management (CRM) for the public website — ProficientHub is the data controller for this processing | Prospective-customer contact data (name, email, academy, locale) — never candidate or exam data | United States (EU data centre in Frankfurt on paid tiers) | SCCs (Modules 2 + 3) + EU–US Data Privacy Framework (certified) | HubSpot DPA (2026-04-14) |
Stripe additionally acts as an independent controller for its own fraud-detection, loss-mitigation and AML/KYC processing (see its DPA). Sign in with Google is not a sub-processor: when you choose to sign in with a Google Account, Google acts as an independent controller of that account under its own terms — see the Privacy Policy for details.