Sub-processors list
These third parties process personal data on Amosia's behalf so that we can deliver the service to your school. Each is bound by a data-processing agreement that limits what it may do with the data, in line with the GDPR and applicable privacy rules. Your school remains the controller of its pupils' and staff's data and Amosia is its processor; where a provider below acts in a different role, its row says so.
Last reviewed on August 13, 2026
Vercel Inc., USA
Hosting of the application, edge network and CDN, serverless compute, the web application firewall, the durable workflows that dispatch transactional e-mail, and the AI Gateway that routes requests to the language model.
All application data in transit, request and function logs, visitors' IP addresses, and the redacted prompts passed on to the language model.
Global edge network; compute and logs in the deployment's configured region.
PlanetScale, Inc., USA
Managed PostgreSQL — the single database the whole application runs on.
All application data at rest: staff accounts (name, e-mail, password hash), sign-ins (IP address, browser), pupils (name, date of birth, notes), class rosters, teachers' observations, reflections, and the audit log.
The database cluster's configured cloud region.
Anthropic PBC, USA
Language-model inference for AI-drafted pupil reflections, reached through the Vercel AI Gateway. A draft is only ever a suggestion — a teacher reads, edits and approves it before it becomes a record. The model used is the one configured for your school; pointing that setting at another provider changes who processes the data, and this list with it.
The reflection prompt: the school's prompt text, teachers' observations, lesson progress, the current reflection, and — when a teacher asks for a rewrite — the draft on screen together with their instruction. The pupil's name and its variants are struck out of every free text before it leaves the application, and no account identifiers are sent.
USA.
Plus Five Five, Inc. (Resend), USA
Transactional e-mail — the password-reset and welcome messages sent to staff. Amosia sends no marketing e-mail.
The recipient's e-mail address and name, the school's name, and the message body including its single-use link.
USA.
Functional Software, Inc. (Sentry), USA
Error monitoring, performance tracing and sampled session replay of the staff interface, plus the in-app feedback form, so that faults are found and can be reported.
Error events and stack traces, browser and device metadata, and sampled recordings of staff sessions. Automatic reporting carries no user identity, no AI inputs or outputs, no request bodies and no IP-bearing headers, cookies or query parameters. The in-app feedback form is the exception: it sends what the member writes, their e-mail address (prefilled from their account, editable and removable before sending) and a recording of the session.
EU (Germany) — the project uses Sentry's European data region.
Google Ireland Limited, Ireland
The optional “Sign in with Google” button for staff accounts. Only staff who choose that button reach Google; signing in with e-mail and password does not. For the Google account itself, Google acts as an independent controller rather than as our sub-processor.
Google account identifier, e-mail address and display name, exchanged at sign-in.
EU and USA.