Version 1.0 - effective 25 August 2026
UK GDPR Article 28 requires controllers - schools in the school flow, AgentChamp Ltd in the family flow - to know who their processor onward-engages. This inventory is the answer. It lists every third party that processes personal data in delivering AgentChamp, what each receives, and whether any child data is involved.
Authoritative version: this document. A new sub-processor is added here *before* its integration goes live, with notice to school administrators per the DPA.
AgentChamp Ltd - company number 17176256, ICO registration ZC230270.
| Provider | Purpose | Location | Child data? | Transfer safeguard |
|---|---|---|---|---|
| Google Cloud | Hosting: database, cache, file storage, application servers, task queue, logs. Speech synthesis and AI story generation | UK (London, europe-west2) | Yes - as hosting infrastructure | UK Extension to the EU-US Data Privacy Framework (UK-US Data Bridge) |
| Microsoft Azure Speech | Story narration audio with word-level timings | UK (UK South) | No - story text only | Data stays in the UK; Microsoft Products and Services DPA applies |
| ElevenLabs | Narration, quiz and dictionary audio | US | No - published text only | EU SCCs + UK Addendum, incorporated into the ElevenLabs DPA |
| Stripe | Payments (adults only) | EU / US | No | UK Extension to the Data Privacy Framework, with the UK Addendum as a fallback |
| Resend | Service emails (adults only) | US | No | EU SCCs + UK Addendum, incorporated into the Resend DPA |
No child's personal data leaves the United Kingdom. The three US-processing providers receive, respectively: nothing routinely (Google - data at rest is pinned to London), an adult's email address (Stripe, Resend), and published text with no identifier attached (ElevenLabs).
Location: europe-west2 (London) for every service that touches personal data. Transfer safeguard: Google LLC holds an active certification under the UK Extension to the EU-US Data Privacy Framework, adopted by Google Cloud as its transfer solution for UK customer data. Data at rest is region-pinned to London.
Google processes this data as infrastructure only. No Google service receives a request that identifies a pupil by name, and no children's data is used to train any model.
Location: UK South. Data does not leave the United Kingdom.
No child data. Azure Blob Storage was previously used to cache narration audio; that moved to Google Cloud Storage on 5 August 2026 and no Azure storage service is now in use.
Location: United States. Transfer safeguard: the ElevenLabs Data Processing Addendum incorporates the EU Standard Contractual Clauses and the UK International Data Transfer Addendum (version B1.0, 21 March 2022). It forms part of the terms of service rather than requiring separate signature.
No child data.
Location: EU, with processing in the US under Stripe's own safeguards. Transfer safeguard: belt and braces - Stripe is certified under the UK Extension to the EU-US Data Privacy Framework, and its Data Transfers Addendum incorporates the UK International Data Transfer Addendum as a fallback should the Framework ever be invalidated.
m.stripe.network) loads inside Stripe's payment form and examines the device to distinguish a genuine payment from a stolen card. It loads only on adult checkout pages and never on any page reachable by a child. We leave it enabled because it is the protection against card fraudNo child data.
Location: United States. Transfer safeguard: Resend's Data Processing Addendum incorporates the EU Standard Contractual Clauses as amended by the UK Addendum.
No child data.
One, and only on adult checkout pages.
js.stripe.com, hooks.stripe.com, m.stripe.network) - the payment form and its fraud-detection component, loaded when an adult is entering card detailsEverything else comes from us. Fonts, scripts and interface graphics are served from our own application origin.
One nuance stated precisely, because it is the kind of thing an inventory should not gloss: story cover images and story, quiz and dictionary audio are fetched by the reader's browser from `storage.googleapis.com` - our own Cloud Storage buckets. Google therefore sees the request, including the device's IP address. That is not a fifth-party exposure: Google Cloud is our hosting provider and is section 1 of this inventory. The distinction that matters is that no company outside this document sees a child's device - no advertiser, no analytics provider, no font host, no CDN.
Cover images are served through 15-minute signed URLs from a private bucket. The audio buckets are public-read and contain only synthesised speech of published text, with no identifier in any file name, metadata or content.
This was not always true. Until 25 August 2026 the display typefaces loaded from Google Fonts and the accessibility typefaces (OpenDyslexic, Atkinson Hyperlegible, Lexend) from the jsDelivr CDN, on every page including children's, and a placeholder image service served one fallback graphic. All four were removed and the files brought in-house.
Retired - code and configuration removed; no data flows:
Dormant - configuration exists, no live code path calls them. Each would be added to the table above before any activation:
Never used: advertising networks, behavioural analytics (Google Analytics, Mixpanel, Segment, PostHog, Hotjar and the like), social-media pixels, and third-party error-tracking or session-replay services. There is no third-party analytics or tracking code anywhere in the product, and none has ever been removed - there was never any to remove.
When AgentChamp engages a new sub-processor:
A structural test in our test suite asserts that every third-party origin the application is permitted to contact appears in this document, so the inventory cannot silently drift out of date as the product changes.
archive/AgentChamp keeps you signed in and remembers your reading settings using cookies and browser storage. What we store, in full.