Skip to main content
Privacy & Information

Subprocessors

Effective 9 October 2026 · Last updated 9 October 2026 · Version 2.0 · ACADEMYSHIP PTY LTD · ACN 698 283 448 · ABN 89 698 283 448

#01What this list is

This page is Academyship's canonical, public register of Subprocessors — the third parties that ACADEMYSHIP PTY LTD (ACN 698 283 448, ABN 89 698 283 448) engages to process Customer Data on its behalf when providing the Services. It is informational, but it is directly connected to the contractual rights in our Data Processing Addendum (DPA).

A Subprocessor is a provider Academyship appoints that processes Customer Data under Academyship's instructions. This is different from:

  • Customer-selected Integrations — providers an Institution chooses to connect to its own tenant (see Section 5). Academyship does not control these data flows;
  • Independent controllers / service providers — a party that determines its own purposes for certain data rather than acting on Academyship's instructions, such as Stripe for some payment functions (see Section 4);
  • Telecommunications carriers — networks that carry SMS or other messages to their destination;
  • Browser, operating-system and device providers — which supply the speech recognition used by Razi voice typing (see Section 4); and
  • Calendar providers — which receive event or booking details only when a User chooses a calendar link (see Section 4).

Under section 18 of the DPA, Academyship gives Customers written notice at least 30 days before a new or replacement Subprocessor begins processing Customer Data, except in a limited emergency, and Customers may object. Customers receive these notices without needing to request them. See Sections 7 and 8 for notice and objection.

This register is versioned. The change log in Section 9 and the version history in Section 11 record what changed and when, so the list of Subprocessors that applied on any date can be identified.

#02How to read the register

The register in Section 3 lists each active Subprocessor with the following information:

  • Provider legal entity — the contracting company, not just a brand name;
  • Service name — the trading or service name used;
  • Website — the provider's public site;
  • Role / classification — Subprocessor, and the nature of the processing;
  • Service and purpose — what Academyship uses the provider for;
  • Data categories — the types of Customer Data involved;
  • Data subjects — the people the data is about;
  • Processing / storage location — where the data is processed or stored;
  • Transfer safeguards — where relevant to any cross-border processing;
  • Public assurance information — where publicly available;
  • Effective date, status and last reviewed; and
  • Change history — recorded in the change log in Section 9.

We list specific legal entities rather than generic descriptions.

Status. "Active" means the provider is approved and processes Customer Data in production. A provider that Academyship is evaluating, or whose support exists in Academyship's software but which Academyship has not approved, is not listed as Active and must not receive Customer Data.

Support access. Academyship's own support and engineering access to Customer Data, including any remote access from outside Australia, is governed by section 14 of the DPA. Access by a Subprocessor's personnel is governed by Academyship's agreement with that Subprocessor.

#03Active production subprocessors

The following are Academyship-appointed Subprocessors that currently process Customer Data in production. This table is Academyship's canonical current register.

Active Academyship-appointed subprocessors that process Customer Data.
Provider legal entity Service name Website Role / classification Service and purpose Data categories Data subjects Processing / storage location Transfer safeguards Provider privacy and security information Effective date Status Last reviewed
Amazon Web Services Australia Pty Ltd (ABN 63 605 345 891)AWS core infrastructureAWS Customer AgreementSubprocessor (processor)Application hosting, tenant RDS databases, S3 files, logs, snapshots and backups.Customer Data hosted by the platform, including workspace records, files, logs and backup copies.Students, parents/guardians, staff, administrators and other individuals whose data an Institution places in the platform.Sydney, Australia (ap-southeast-2).Core platform Customer Data remains in Sydney; see the processing position below.AWS security information12 September 2026Active12 September 2026
Amazon Web Services Australia Pty Ltd (ABN 63 605 345 891)Amazon SESAmazon SESSubprocessor (processor)Transactional and Institution-sent email.Email recipient names and addresses, message content, delivery metadata and related service records.Email recipients, including students, parents/guardians, staff and administrators.Sydney, Australia (ap-southeast-2).Core platform Customer Data remains in Sydney; see the processing position below.Amazon SES service information12 September 2026Active12 September 2026
Amazon Web Services Australia Pty Ltd (ABN 63 605 345 891)AWS End User MessagingAWS End User MessagingSubprocessor (processor)SMS processing through AWS.Mobile numbers, message content, delivery metadata and related service records.SMS recipients, including students, parents/guardians, staff and administrators.Sydney, Australia (ap-southeast-2) for SMS processing.Telecommunications carriers may route messages through the recipient’s carrier network.AWS End User Messaging service information12 September 2026Active12 September 2026
Amazon Web Services Australia Pty Ltd (ABN 63 605 345 891)Amazon BedrockAmazon BedrockSubprocessor (processor)Foundation-model processing for Academyship’s institutional AI assistant, permitted Tenant search, summarisation, drafting, report and document assistance, administrative recommendations and action previews.Permitted AI inputs, authorised workspace context, outputs and related usage or audit events.Authorised Institution staff and individuals whose permitted Customer Data is included in an AI task.Sydney, Australia (ap-southeast-2); cross-region inference is disabled.Customer Data is not used to train general-purpose models. Core platform Customer Data remains in Sydney.Each Institution may enable, disable or restrict AI Features. AI usage, security and audit events follow the 30-day infrastructure and security-log retention position.12 September 2026Active12 September 2026

Academyship hosts its core production platform and Customer Data in Sydney, Australia (ap-southeast-2). Limited processing outside Australia may occur through disclosed telecommunications delivery, Stripe-hosted payment services, Customer-selected Integrations or authorised access, subject to applicable privacy, contractual and security safeguards.

For Academyship's Australian AWS account, the AWS Customer Agreement identifies Amazon Web Services Australia Pty Ltd (ABN 63 605 345 891) as the AWS contracting party. The public AI feature inventory, role controls and human-review requirements are in the Responsible AI Statement. SMS messages are handed to telecommunications carriers for delivery and may be routed through carrier networks in the recipient's country.

Amazon Bedrock is Academyship's approved AI provider for Customer Data, and Academyship configures it in the AWS Asia Pacific (Sydney) Region. Academyship's software also contains support for other model providers, including a fallback path that can operate where configured. No other AI provider is approved to process Customer Data unless it is listed in this register and any notice required by the DPA has been given (see Section 4).

Academyship uses AWS End User Messaging SMS for SMS delivery. AWS may process recipient mobile numbers, message content and delivery metadata, while telecommunications carriers participate in delivery and may route messages through recipient-country networks. Institutions control message content, recipients, timing and any authorised sender identity, and are responsible for consent, other lawful authority, notices, opt-outs and communications-law compliance. Academyship does not guarantee carrier delivery or exact sender-ID display. An Institution’s sender identity does not change the parties’ privacy or data-processing roles, and is not an Academyship Subprocessor.

#04Other third-party service providers that are not subprocessors

Some third parties are not Academyship-appointed Subprocessors because they provide services under their own contractual and regulatory arrangements. Customer-selected Integrations are not listed here — they are addressed in Section 5.

Stripe payment services

Stripe’s published data-processing terms describe different roles for different functions, so Academyship classifies each Stripe function separately rather than applying one label to all of them. None of the functions below is an Academyship Subprocessor function.

Stripe’s role for each payment function.
FunctionWho Stripe provides the service toStripe entity and termsClassificationInformation processedProcessing locations
Academyship subscription checkout and billingAcademyship, as the merchant for its own fees.Stripe Payments Australia Pty Ltd (A.C.N. 160 180 343), under the Stripe Services Agreement.Independent payment-service provider; not an Academyship-appointed Subprocessor. This is Academyship’s own billing information, not Customer Data processed for an Institution. Stripe’s own role for payment data is determined under its terms and applicable law.Payer and billing contact details, payment-method details, transaction amount, date and status, subscription status, applicable tax, refund or chargeback information, and support interactions, as applicable.Australia for Stripe Payments Australia Pty Ltd; Stripe’s international processing operations may also involve other countries, including the United States and India, as described in Stripe’s Privacy Policy.
Institution Charges collected through Academyship’s payment features, where an Institution uses themThe Institution. The features are designed so that the Institution’s Stripe account, connected to Academyship’s platform, is the seller of record for the underlying charge.The Stripe entity and terms that apply to the Institution’s own Stripe account.Payment service provided to the Institution under the terms of its Stripe account; not an Academyship-appointed Subprocessor. On the Institution’s instructions, Academyship’s platform exchanges with Stripe the information needed to initiate and record each payment, and keeps the resulting records in the Institution’s tenant.Payer name and contact details; the Institution Charge and amount; payment method, for example card or PayTo, depending on the Institution’s configuration; PayTo mandate details; transaction, refund and dispute status; and identifiers that link these records.Stripe’s processing may involve Australia and other countries, as described in Stripe’s Privacy Policy.
Fraud prevention, identity verification and regulatory complianceStripe, for its own purposes, in connection with both functions above.The Stripe entity providing the relevant payment service.Stripe determines its own purposes for these functions under its terms and the financial-services laws that apply to it; not an Academyship Subprocessor function.Information Stripe collects or receives to verify the identity of account holders and their representatives, to screen transactions for fraud and to meet its legal obligations, such as identity, device and transaction information.As described in Stripe’s Privacy Policy.

Academyship uses Stripe for subscription payments. For Academyship’s subscription checkout, payment-card details are entered on Stripe’s hosted checkout rather than on Academyship’s website.

If Academyship engages Stripe to process Customer Data on Academyship’s behalf for any other function, Academyship will assess whether Stripe is a Subprocessor for that function and, if it is, list it in Section 3 and give any notice required by the DPA before that processing begins.

AI providers that are not approved

Amazon Bedrock, listed in Section 3, is Academyship’s approved AI provider for Customer Data. Academyship’s software also contains support for other model providers, including a fallback path that can operate where configured. Those providers are not approved to process Customer Data, are not listed as Active, and must not receive Customer Data unless they are added to Section 3 and any notice required by the DPA has been given. Where model software runs on infrastructure operated by a third party, the register lists the legal entity that operates that infrastructure, not the name of the software.

Speech recognition for Razi voice typing

Razi voice typing uses the speech-recognition service supplied by the User’s browser, operating system or device. Recognition cannot be assumed to take place on the device: depending on the browser or device, speech may be sent to that provider’s servers, which may be outside Australia. The provider processes speech under its own terms and configuration. It is not appointed by Academyship and is not an Academyship Subprocessor. Academyship does not receive or store raw audio through Razi; it receives only the text a User inserts into an Academyship field. An Institution can control whether Razi is available to its Users where the relevant configuration exists.

Calendar links chosen by Users

Booking and event features can offer links that add an appointment or event to Google Calendar, Outlook or Office 365, or Yahoo Calendar, and a downloadable calendar file (ICS). When a User chooses one, the selected details, such as the title, time, location or meeting link and description, go to the provider the User chose, under that User’s own arrangement with the provider. These links are not an OAuth connection or an Academyship integration, and the calendar provider is not an Academyship Subprocessor. Copies in an external calendar are outside Academyship’s control and are not removed when the record is deleted in Academyship.

Payroll reporting providers

Payroll features can prepare information used for Single Touch Payroll reporting. No provider that lodges Single Touch Payroll reports with the Australian Taxation Office is listed in this register, because lodgement through the platform is not yet available. Academyship has engaged Single Touch Pty Ltd, which stores report data in Australia, to provide that lodgement when it becomes available. Before Single Touch Pty Ltd or any other provider receives Customer Data for that purpose, Academyship will list it in Section 3 and give the notice required by the DPA.

#05Customer-selected integrations

Institutions can choose to connect their own third-party providers ("Integrations") to their tenant. Those providers are selected and controlled by the Institution, not appointed by Academyship, and the resulting data flows are the Institution's responsibility under its own arrangements with those providers. They are not Academyship Subprocessors and are not listed in Section 3. For how these are handled, see the DPA and Privacy Policy.

#06Provider assessment and contracting

Before appointing a Subprocessor that will process Customer Data, Academyship carries out due diligence proportionate to the risk, and puts in place data-processing terms consistent with the DPA. Our assessment considers matters such as security and privacy practices, data minimisation, processing location and region, confidentiality, incident-notification obligations, and exit or transition arrangements. We do not publish the internal checklist or scoring we use for this assessment.

Before listing a provider that Academyship is evaluating, or whose support exists in Academyship's software, as Active, Academyship will complete an internal activation record covering the contract, the provider's role, the data it would receive, its processing and support locations, its onward recipients, retention and production readiness. The provider is listed here only once that record is complete and any notice required by the DPA has been given.

#07New and replacement providers

When Academyship appoints a new or replacement Subprocessor that will process Customer Data, it gives Customers written notice at least 30 days before the Subprocessor begins processing Customer Data, as set out in section 18 of the DPA. The notice identifies the provider's legal entity, the service, the purpose, the categories of data and data subjects, the processing locations and the proposed effective date. A Customer may object in writing on reasonable data-protection grounds within 30 days after the notice, and the DPA sets out how objections are resolved.

Where an urgent replacement is necessary (for example, to maintain security or continuity of the Services, or for legal reasons), Academyship may appoint a replacement limited to the affected service and provide notice as soon as reasonably practicable. The objection period then runs from that notice. New entries are added to the register with their effective date, and each change is recorded in the change log in Section 9.

#08How to receive change notices

Customers. Customers do not need to subscribe. Academyship sends the notices due under the DPA by email to each Customer's account contacts, or to a privacy or security contact the Customer nominates. To nominate a contact, email legal@academyship.com.au.

Others. Anyone else, such as a prospective customer or an additional contact at a Customer, can ask to be told of register updates by contacting legal@academyship.com.au. Academyship manages these notifications manually on request. To provide notifications, Academyship retains the requester's contact details and notification preferences and uses them only for that purpose, consistent with the Privacy Policy. These updates are in addition to, and do not replace, the notices due to Customers under the DPA.

This register is also updated when a change takes effect, so it can be checked at any time.

#09Change log

Change log for the subprocessor register.
DateProviderActionEffective dateSummaryNotice dateDocument version
9 October 2026All entries; Stripe (not a Subprocessor)Register revision; no change to Active Subprocessors9 October 2026No Subprocessor was added, removed or replaced. Classified Stripe by payment function; explained that AI providers other than Amazon Bedrock are not approved; explained browser and device speech recognition, user-initiated calendar links and payroll-reporting providers; and aligned notice and objection wording with DPA version 3.0.Not applicable; no new or replacement Subprocessor2.0
12 September 2026Amazon Web Services Australia Pty LtdInitial production register12 September 2026Published AWS core infrastructure, Amazon SES, AWS End User Messaging and Amazon Bedrock as the active Academyship subprocessors for production operation in Sydney, Australia.12 September 20261.0

#10Questions and related documents

For questions about this register or subprocessor changes, contact legal@academyship.com.au.

#11Document governance

This register is the operational source of truth for Academyship's active Subprocessors. Academyship will update it whenever a provider or material data flow changes, check it for currency each quarter, and review it formally with legal each year in June. The DPA Annex III snapshot and the Privacy Policy summary are updated through Academyship's controlled document-update process. Annex III of DPA version 3.0 lists the same Active Subprocessors as this version of the register.

Academyship keeps each version of this register. Earlier versions are available on request from legal@academyship.com.au.

Version history for this Subprocessor Register.
VersionDateSummary of changes
2.09 October 2026No change to the Active Subprocessors. Replaced the single Stripe entry with a classification of each Stripe payment function; explained that AI providers other than Amazon Bedrock are not approved and that Academyship’s software contains support for other model providers; added explanations of browser and device speech recognition, user-initiated calendar links and payroll-reporting providers; explained the meaning of Active status and support access; aligned the notice and objection process with DPA version 3.0, including written notice to Customers at least 30 days in advance without needing to subscribe; and restated the register’s review schedule as a commitment. Recorded that Academyship has engaged Single Touch Pty Ltd to lodge Single Touch Payroll reports once that feature is available; it is not listed as an active Subprocessor until then.
1.012 September 2026Published the Subprocessor Register for Academyship’s production launch, including the active AWS services and their Sydney processing locations.