Sub-processors
Every organisation we can name that personal data passes through to run Aspire & Thrive, what each one does, and whether it applies to your organisation by default or only once a feature is switched on. None of them may use your data for their own purposes, and each is bound by a data processing agreement.
The list
| Service | Used for | Applies to your organisation |
|---|---|---|
| SupabaseEvery organisation | Database, file storage and sign-in — this is where the records themselves live. Where: Ireland (eu-west-1). A move to Supabase's London region is planned but has not happened yet. | Every organisation, always. |
| VercelEvery organisation | Hosts the website and its API endpoints. Where: London. | Every organisation, always. |
| ResendEvery organisation | Sends transactional email: attendance notices, questionnaire invitations, staff and password-reset emails. Where: Sent from a domain we control; not otherwise verified by us. | Every organisation, always. |
| Google (Firebase Cloud Messaging) and Apple (APNs)Every organisation | Deliver push notifications to the mobile app, and to a browser that has turned on notifications, via each platform's own push service. Safeguarding alerts are content-free — the push says an alert exists, never its details. Where: Google's and Apple's own infrastructure. | Any organisation whose staff use the app or the website and allow notifications. |
| TwilioOpt-in | Sends and receives SMS — session reminders and two-way message threads with a parent or contact. Where: Not otherwise verified by us. | Only organisations that connect Twilio from Admin → Integrations. |
| Anthropic (Claude)Opt-in | Reads the text you submit to an AI feature (session-note drafting, summarising, concern-triage suggestions) to generate a suggestion. Every call is logged to an audit trail your admin can read. Where: Not otherwise verified by us. | Only organisations with AI features switched on. Off by default. |
| StripeOpt-in | Processes subscription payment and invoicing. Where: Not otherwise verified by us. | Only organisations on a paid plan, at checkout and billing. |
| Google WorkspaceOpt-in | Syncs calendar entries (and, where connected, Drive) with the platform. Where: Not otherwise verified by us. | Only organisations that connect it from Admin → Integrations. |
| Microsoft (Teams)Opt-in | Syncs calendar and meeting entries with the platform. This is separate from Microsoft Entra sign-in (SSO), which is not live — see Security. Where: Not otherwise verified by us. | Only organisations that connect it from Admin → Integrations. |
| WondeOpt-in | School MIS sync — students, staff and attendance. Where: Not otherwise verified by us. | Only organisations that connect it from Admin → Integrations. |
| SentryDeployment-wide | Error monitoring for the website, so a crash can be diagnosed. Error reports can include technical detail about the request that failed. Where: Not otherwise verified by us. | Not a per-organisation choice — a service-level setting. Active for the whole platform when error monitoring is configured for the deployment; otherwise off for everyone. |
Changes
Adding or replacing a sub-processor is notified to customer organisations at least 30 days in advance, with a window to object. See also our privacy notice and security pages.