Skip to content
Legal

Sub-processors

Every organisation we can name that personal data passes through to run Aspire & Thrive, what each one does, and whether it applies to your organisation by default or only once a feature is switched on. None of them may use your data for their own purposes, and each is bound by a data processing agreement.

The list

Sub-processors: what each is used for, where, and whether it applies by default.
ServiceUsed forApplies to your organisation
SupabaseEvery organisation

Database, file storage and sign-in — this is where the records themselves live.

Where: Ireland (eu-west-1). A move to Supabase's London region is planned but has not happened yet.

Every organisation, always.
VercelEvery organisation

Hosts the website and its API endpoints.

Where: London.

Every organisation, always.
ResendEvery organisation

Sends transactional email: attendance notices, questionnaire invitations, staff and password-reset emails.

Where: Sent from a domain we control; not otherwise verified by us.

Every organisation, always.
Google (Firebase Cloud Messaging) and Apple (APNs)Every organisation

Deliver push notifications to the mobile app, and to a browser that has turned on notifications, via each platform's own push service. Safeguarding alerts are content-free — the push says an alert exists, never its details.

Where: Google's and Apple's own infrastructure.

Any organisation whose staff use the app or the website and allow notifications.
TwilioOpt-in

Sends and receives SMS — session reminders and two-way message threads with a parent or contact.

Where: Not otherwise verified by us.

Only organisations that connect Twilio from Admin → Integrations.
Anthropic (Claude)Opt-in

Reads the text you submit to an AI feature (session-note drafting, summarising, concern-triage suggestions) to generate a suggestion. Every call is logged to an audit trail your admin can read.

Where: Not otherwise verified by us.

Only organisations with AI features switched on. Off by default.
StripeOpt-in

Processes subscription payment and invoicing.

Where: Not otherwise verified by us.

Only organisations on a paid plan, at checkout and billing.
Google WorkspaceOpt-in

Syncs calendar entries (and, where connected, Drive) with the platform.

Where: Not otherwise verified by us.

Only organisations that connect it from Admin → Integrations.
Microsoft (Teams)Opt-in

Syncs calendar and meeting entries with the platform. This is separate from Microsoft Entra sign-in (SSO), which is not live — see Security.

Where: Not otherwise verified by us.

Only organisations that connect it from Admin → Integrations.
WondeOpt-in

School MIS sync — students, staff and attendance.

Where: Not otherwise verified by us.

Only organisations that connect it from Admin → Integrations.
SentryDeployment-wide

Error monitoring for the website, so a crash can be diagnosed. Error reports can include technical detail about the request that failed.

Where: Not otherwise verified by us.

Not a per-organisation choice — a service-level setting. Active for the whole platform when error monitoring is configured for the deployment; otherwise off for everyone.

Changes

Adding or replacing a sub-processor is notified to customer organisations at least 30 days in advance, with a window to object. See also our privacy notice and security pages.