Who else touches a school's data
Sub-processors
The external services that touch a school's data, what each of them receives, and where. A change to this list is something we tell every school about.
What none of them receive
No student personal data reaches any sub-processor. Names, e-mail addresses and progress never leave this system: the narration and enrichment functions take sentences and lemmas as arguments and have no access to a user record. Logs carry a school and document identifier and never the text or a name.
Cloudflare
Hosting, database, object storage and queues. The platform runs on it.
- Everything the platform stores: school and user records, uploaded texts, generated audio and progress
- Request metadata, including the IP address a person connects from
Where: Databases and buckets are created in the EU — D1 in Western Europe, R2 with the EU jurisdiction. Worker code runs at the Cloudflare location nearest the visitor, which for a request from Iceland has been observed as Reykjavík and Dublin.
Processed inside the EEA.
Voicemaker
Text-to-speech. It turns one sentence of the uploaded text into narration.
- One sentence of Icelandic text at a time, and the voice and speed to read it with
- Nothing else: no user, class, school or document identifier is part of the request
Where: Requested at developer.voicemaker.in. The processing location has not been established in writing, so it is treated as outside the EEA.
Outside the EEA. Not yet in place. Standard contractual clauses are required before a school with real students uses narration; until then this is an open item, recorded in docs/subprocessors.md.