Subprocessors

Last updated: 2026-06-05

Under Article 28 of the EU/UK GDPR and equivalent laws, we maintain a current list of the third parties that process personal data on our behalf. We require every subprocessor to sign data-protection terms at least as protective as our own, to process data only for the purpose we engaged them for, and to maintain appropriate technical and organisational measures.

1. Current subprocessors

ProviderPurposeDataLocation
RenderApplication hosting (backend, web).All platform data passes through during normal operation.United States, European Union
Managed Postgres providerPrimary relational database.Account, profile, content, transactional metadata.Same region as Render deployment
Managed Redis providerCaching, session, rate-limit data, presence.Session tokens, ephemeral cache values.Same region as Render deployment
Amazon Web Services (S3 + CloudFront)File and media storage; CDN delivery.Profile photos, post media, reels, books, marketplace listing images, tutor materials.United States (primary region: us-east-1 unless otherwise specified)
ResendTransactional email (welcome, verification, receipts, alerts, weekly summary).Recipient email, name, message body.United States, European Union
Expo (push notifications)Sending push notifications to mobile devices.Device push token, notification payload.United States
SentryError tracking and performance monitoring.Crash logs, sanitised request metadata, user ID for impacted-user grouping.European Union, United States
PaystackPayment processing — cards, bank transfers, mobile money.Transaction amount, currency, payer email, transaction reference. Card data is collected directly by Paystack and never reaches Larnnit servers.Africa (a Stripe company), with global PSPs
Safaricom M-Pesa DarajaM-Pesa STK Push and B2C payouts.Mobile-money phone number, transaction amount, M-Pesa receipt number.Kenya
Stripe (where enabled)Card payment processing for international payers.Same as Paystack; card data handled by Stripe.United States, European Union
CloudflareDNS, edge protection, DDoS mitigation.IP address, request metadata.Global edge
Anthropic / model provider for AI RevisionGenerating practice questions, explanations, and study summaries.Text prompts you submit. We do not include account identifiers in prompts and do not train provider models on your content.United States

2. Changes & notifications

  • We add new subprocessors to this list before they begin processing customer data, and announce material additions in-app and (for DPA customers) by email at least 14 days in advance.
  • DPA customers may object to a new subprocessor in writing during the notice window. We will work with you in good faith; if we can't resolve the objection you may terminate the affected service.

3. International transfers

Where personal data of EEA, UK, or Swiss data subjects is transferred to a country without an adequacy decision, we rely on the EU Standard Contractual Clauses (2021) together with supplementary measures, or the UK International Data Transfer Addendum. Where required, we conduct a transfer impact assessment.

4. Audit rights

DPA customers may request information about subprocessor controls — including SOC 2, ISO 27001, or equivalent reports where the subprocessor provides them — by contacting privacy@larnnit.com.