⚠️ DRAFT. Must be reviewed by a lawyer before publication. This is prepared text, not legal advice.
Version: 2026-08-22 · Effective: to be confirmed
Annex to the Privacy Policy. Required by GDPR Art. 28.
A sub-processor is a company that processes user data on our instructions. We have a Data Processing Agreement with each of them, obliging them to process data only as we instruct.
The list is assembled from what the service actually runs, not from a generic template. If a company is not on the list, data does not go to it.
Always involved, because without them there is no service.
| What it does | The physical server everything runs on: Matrix server, database, backend, call server |
| What data | Everything except course video and payment credentials: accounts, messages (ciphertext only in encrypted rooms), membership, access, progress, logs |
| Where | to be confirmed, Germany — EU |
| Transfer outside the EU | None |
| DPA | to be confirmed |
| What it does | Storage of course video (R2), its delivery (Worker), authoritative DNS records for the domain, aggregate DMARC reports on our email |
| What data | Video lesson files; requests for them (time, IP address, which lesson); queries to our DNS records |
| Where | Storage — EU region; the delivery network is global and may be operated from the United States |
| Transfer outside the EU | Possible. Basis: EU Standard Contractual Clauses; Cloudflare participates in the EU–US Data Privacy Framework |
| DPA | cloudflare.com/cloudflare-customer-dpa |
🔴 Only video passes through Cloudflare. Traffic proxying is switched off ("grey mode"): the app, chat, calls and the web cabinet connect to our server directly, and Cloudflare does not see those requests. The only stream of user requests that goes through it is protected video.
Course video is not stored in Matrix and is not mixed with chat media — it is a separate protected path with signed access tokens.
| What it does | Distribution of the app; delivery of push notifications; for in-app purchases, taking payment; today also the relay for outgoing email (see §1.4) |
| What data | Device token, event and room identifiers, unread counter. For purchases — payment data (processed by Apple, not by us). For email — address, name and message body |
| Where | United States and globally |
| Transfer outside the EU | Yes. Basis: Standard Contractual Clauses; Apple participates in the EU–US Data Privacy Framework |
| DPA | Part of the Apple Developer Program License Agreement |
🔴 What does NOT go into a push: message text, sender name, content. Apple receives only identifiers and a counter — your device does the decryption.
| What it does | Delivers email: address confirmation, password recovery, decisions on reports, receipts |
| What data | Email address, name, message content |
| Where | to be confirmed — a provider processing in the EU is required |
| Transfer outside the EU | Depends on the provider; having none is a selection criterion |
| DPA | to be confirmed |
🔴 No permanent provider has been chosen, yet email already flows — today through Apple. The node sends mail through an iCloud+ relay on our own domain (smtp.mail.me.com). In practice this means the recipient's address, name and the body of the message pass through Apple, and until the provider changes, a line saying "no transfer outside the EU" would be untrue.
One of two things must therefore be settled before publication: either the Apple relay is described here as permanent (in which case the transfer basis is the one in §1.3), or the provider is changed to a European one. Leaving this row as an empty commitment is not an option — the processing is already happening.
Engaged only if a school enabled the corresponding feature. Off by default.
| When | A school enabled card payments |
| What it does | Takes payments, stores payment data, pays out to the school |
| What data | Name, email address, amount, card details (seen only by Stripe — we hold no card data), the school's tax details |
| Where | EU and United States |
| Transfer outside the EU | Yes. Basis: Standard Contractual Clauses; Stripe participates in the EU–US Data Privacy Framework |
| DPA | stripe.com/legal/dpa |
The arrangement is Stripe Connect: money goes to the school's account and the platform withholds its commission. In this channel the seller to the student under the contract is the school (who accounts for VAT is a separate question — see document 5, §10).
| When | A school connected Zoom for meetings |
| What it does | Hosts a video meeting outside our infrastructure |
| What data | Participant name and email address, the fact and time of participation; if recorded in Zoom, audio and video |
| Return flow | A meeting recorded in Zoom is downloaded back to our server so that it can become a lesson; from then on the copy lives with us under the retention rules in recording-retention.md |
| Where | United States and globally |
| Transfer outside the EU | Yes. Basis: Standard Contractual Clauses |
| DPA | zoom.com/trust/privacy |
A class run with our tools (LiveKit + Element Call on our server) does not reach Zoom at all.
| When | A school linked a room to a Telegram chat |
| What it does | Relays messages between the room and Telegram in both directions |
| What data | Messages and attachments in the linked room, display names |
| Where | Telegram infrastructure, outside the EU |
| Transfer outside the EU | Yes |
| DPA | Not available in the usual form — 🔴 see the warning below |
🔴 A linked room cannot be encrypted, otherwise the bridge cannot work. Telegram sees the messages in it. The room is marked and participants are warned by a separate message when the room is linked.
Separately: the node uses a Telegram channel for operational alerts to the operator ("a report in organisation N has been waiting M hours"). By design, no personal data goes into such alerts.
Not yet engaged. A row appears here before it is switched on, not after.
| Who | What for | Status |
|---|---|---|
| Speech recognition provider | Transcribing published video for moderation and subtitles | 🔴 Not selected. Criterion: processing in the EU, or running the model on our own server |
The following runs on our own server, not at a provider:
And the following does not exist at all:
We announce a new sub-processor 30 days before processing starts — in the app and on this page. Objections go to to be confirmed; if an objection is well-founded and there is no alternative, you may terminate and receive a refund for the unused period.
Previous versions of the list stay published.
to be confirmed · to be confirmed, to be confirmed, Austria
The source version is Russian: 06-subprocessors.ru.md.
“To be confirmed” in place of a detail means exactly that: the value has not been filled in yet. We do not put invented data here.