← Back to Privacy

Sub-processors

Last updated: 31 August 2026

Document control

Version: 1.8

Date: 31 August 2026

This page is kept aligned with the Data Processing Agreement v1.6 (24 August 2026) and the Data Protection Impact Assessment v1.5 (24 August 2026).

Version history

VersionDateStatusNotes
1.831 August 2026CurrentRemoved Zoho Bookings after meeting scheduling was withdrawn; school enquiries continue through Zoho CRM
1.730 August 2026SupersededDisclosed Zoho CRM controller-side processing for teacher access applications and added Zoho Bookings controller-side entry for school demo bookings in controller operations and Article 30 extract
1.624 August 2026SupersededAligned with DPA v1.6 and DPIA v1.5; sub-processor notice window aligned to thirty (30) days; account/service email split from school-related email in the Article 30 extract
1.524 August 2026SupersededMicrosoft entry split into per-service entries; Resend transfer safeguards and split-key exclusion clarified; Article 30 extract and EU AI Act position added
Earlier versions2026SupersededPrevious editions of this page were published without a version number; their content is consolidated into v1.5

Sign-off

ItemDetail
Document ownerSENScribe Limited
Data protection contacthello@senscribe.ie
StatusUpdated for publication review on 31 August 2026
Review cycleReviewed whenever a sub-processor is added or replaced, and otherwise at least annually alongside the parent DPIA review cycle

Introduction

SENScribe Limited ("SENScribe", "we", "us") acts as a data processor on behalf of schools and educational bodies, including Education and Training Boards ("controllers"), when providing the SENScribe service. Under Article 28(2) GDPR, we maintain this list of sub-processors engaged to assist in delivering the service.

SENScribe also processes limited personal data for its own purposes as an independent controller. Those operations are listed separately below and are summarised in our Article 30 record extract. For Student Support Files and other Customer Data processed under a school licence, the school or ETB remains the controller and SENScribe acts only as processor; nothing on this page changes that allocation.

Relationship with the Data Processing Agreement

The school-service sub-processors listed below are approved under Clause 10 and listed in Annex 3 of the Data Processing Agreement. Where this page is updated following advance notice under Clause 10(4), SENScribe will update Annex 3 in the next version of that agreement. This page is informative only; the executed Data Processing Agreement governs.

Current school-service sub-processors

Microsoft Ireland Operations Limited

Microsoft provides several distinct services to SENScribe. They are recorded separately here so that schools can see what each service involves.

Azure Cosmos DB and Azure Blob Storage (encrypted customer storage)

  • Services and purpose: hosting of encrypted student-support records and related service data in EU/EEA cloud storage
  • Data involved: encrypted customer content; account, request and limited diagnostic metadata
  • Location and safeguards: customer storage is hosted in an EU/EEA Azure region under the Microsoft Products and Services DPA

Azure OpenAI (supported AI processing)

  • Services and purpose: processing of browser-redacted and generalised AI drafting and rewrite requests within an EU data zone deployment
  • Data involved: browser-redacted and generalised AI inputs and outputs; automated detection reduces risk but cannot guarantee recognition of every identifier in free text
  • Location and safeguards: EU data zone deployment under the Microsoft Products and Services DPA. Prompts flagged under Microsoft's abuse monitoring may be stored by Microsoft for human review under the applicable Azure terms. See our Privacy Policy (Section 8) for what Microsoft states about that review, including that authorised human reviewers for European deployments are based in the EEA and that prompts are not used to train foundation models without customer permission or instruction. SENScribe has given neither permission nor instruction.

Azure Communication Services (primary transactional email)

  • Services and purpose: primary delivery of transactional and service email, including secure-review invitations
  • Data involved: recipient address, subject, HTML and plain-text message content, optional reply-to address, and delivery metadata; for secure review invitations only, the email-link half of the split decryption key
  • Location and safeguards: Europe region under the Microsoft Products and Services DPA

Azure Monitor and Log Analytics (security and operational diagnostics)

  • Services and purpose: security monitoring, service protection and operational diagnostics
  • Data involved: limited operational and security logging, which may include user identifiers and technical error information
  • Location and safeguards: West Europe; covered diagnostic logs have a documented thirty-day retention

Plus Five Five, Inc. (Resend)

  • Services and purpose: fallback transactional email delivery if the primary email path (Azure Communication Services) is temporarily unavailable
  • Data involved: recipient address, subject, HTML and plain-text message content, optional reply-to address and delivery metadata; student-support record content is not intentionally included
  • Exclusion: Resend is not used for split-key secure-review invitation flows. Those emails are sent only through the primary email path described above.
  • Location and safeguards: United States. Resend participates in the EU-US Data Privacy Framework and EU Standard Contractual Clauses are incorporated into Resend's DPA; the Standard Contractual Clauses provide a continuing fallback transfer mechanism where Data Privacy Framework coverage ceases or is suspended. Our assessment of this transfer is set out in Section 11 of the DPIA.

SENScribe's own operations as independent controller

The providers below support purposes determined by SENScribe as an independent controller. They are not engaged to process Student Support Files on a school's behalf.

ProviderPurposeRoleData involvedRegion / safeguards
Google Analytics 4Optional, consent-gated website and application usage analyticsProcessor to SENScribe under Google's data processing termsPseudonymous browsing, URL, cookie and device data; no Student Support File content is intentionally sentUnited States; Google participates in the EU-US Data Privacy Framework, with Standard Contractual Clauses incorporated into Google's data processing terms as a fallback
RevolutPayment processing for subscriptionsIndependent provider of payment services under its own termsBilling contact and payment details; no Student Support File contentEU/EEA; governed by Revolut's own privacy terms
Zoho CRM (Zoho Corporation B.V.)Managing teacher access applications and prospective-school licence enquiriesProcessor to SENScribe under Zoho's data processing termsApplicant details (name, school or work email, role, school details, intended use) and school enquiry information; no pupil or student data is requestedEU data centre; Zoho publishes its privacy terms, DPA information, and sub-processor list
Zoho (Zoho Corporation B.V.)Invoicing for subscription paymentsProcessor to SENScribe under Zoho's data processing termsBilling contact details needed to issue invoices; no Student Support File contentEU data centre; Zoho publishes its privacy terms and DPA information

Note on terminology: this page describes analytics data as pseudonymous because identifiers are separated from browsing data at collection. Our Privacy Policy now uses the same "pseudonymous usage data" description; terminology is aligned across our published documents.

Article 30 extract: SENScribe-controlled operations

Article 30(1) GDPR requires controllers to maintain a record of processing activities. The table below is a public extract of the processing operations that SENScribe carries out as an independent controller, reflecting the disclosures in this page and our Privacy Policy. It is provided for transparency; it is not the complete internal record, and it does not cover processing carried out on behalf of school controllers under the Data Processing Agreement.

Processing activityData subjects and data categoriesPurposeLawful basisRecipients / transfersRetention (general terms)
Account administration and authenticationTeachers and SETs; name, email, hashed password, session tokens, usage counts, timestampsProviding, securing and administering the service; enforcing fair-use limitsContract, Art 6(1)(b); legitimate interests for security, Art 6(1)(f)Hosted in EU/EEA Azure regions described aboveEligible personal accounts deleted automatically after 12 months of inactivity; session tokens expire after 7 days of inactivity, with refresh while the user remains active
Provision of the encrypted school service (processor role)Students, parents or guardians, and school staff; Customer Data categories set out in Annex 1 of the DPAEncrypted storage, synchronisation, export and redacted AI drafting on documented school instructionsBasis determined by the school as controller; SENScribe processes on documented instructions, Art 28 GDPRSchool-service sub-processors listed above; storage and supported AI processing remain in EU/EEA regions or the EU data zoneDetermined by the controller; deletion and backup-expiry mechanics follow Clause 12 of the DPA
Account and service emailTeachers and other message recipients; recipient address, message content and delivery metadataAccount-related security messages, password reset and service notifications (SENScribe as controller)Contract, Art 6(1)(b)Azure Communication Services (primary, Europe); Plus Five Five, Inc. (Resend) as US fallback under the Data Privacy Framework and SCCsKept no longer than necessary for delivery and service operation
School-related email (secure review invitations)Recipient email address and review-link metadataSecure review invitations on documented school instructions (processor role)Basis determined by the school as controller; processed on documented instructions, Art 28 GDPRAzure Communication Services (primary, Europe); Resend US fallback outside split-key invitation flowsDeleted or returned under Clause 12 of the DPA; invitation key material is split so that neither service holds both halves
Teacher access applicationsApplicants; name, school or work email, role, school name/roll number, intended useManaging and reviewing teacher trial access applicationsSteps preparatory to a contract, Art 6(1)(b); legitimate interests for manual access review, Art 6(1)(f)Zoho CRM (EU data centre)Kept while needed to review and manage the application, then reviewed or deleted unless an approved account is created or a longer period is required by law
School licence enquiriesProspective-school contacts; enquiry information listed in Section 2.3 of the Privacy Policy; no pupil or student data is requestedManaging prospective-school licence enquiriesSteps preparatory to a contract, Art 6(1)(b); legitimate interests for proportionate business-to-business follow-up, Art 6(1)(f)Zoho CRM (EU data centre)Kept while needed to respond to and manage the prospective-school relationship, then reviewed or deleted unless a longer period is required for a customer relationship or by law
Subscription paymentsBilling contacts; billing contact and payment detailsProcessing subscription paymentsContract, Art 6(1)(b)Revolut (EU/EEA) as an independent provider under its own termsDuration of the subscription plus applicable accounting and tax retention periods
Website and application analytics (optional)Visitors who have consented; pseudonymous browsing, URL, cookie and device dataUnderstanding and improving use of the site and applicationConsent, Art 6(1)(a), read with the Irish ePrivacy RegulationsGoogle (United States; Data Privacy Framework participation, SCCs as fallback)In line with the analytics configuration; processing ceases when consent is withdrawn
Security monitoring and operational diagnosticsService users; limited diagnostic and security metadata, which may include user identifiers and technical error informationService security, incident investigation and abuse preventionLegitimate interests, Art 6(1)(f)Azure Monitor and Log Analytics (West Europe)Covered diagnostic logs retained for thirty days

Direct-marketing and lead re-engagement processing described in our draft marketing DPIA addendum remains a proposal that has not been approved and is not operational. It is therefore not included in this record until such time as it is approved and carried out.

EU AI Act readiness position

SENScribe's AI functionality is an optional drafting assistant. It generates draft educational documentation from browser-redacted and generalised inputs; teachers review, edit and remain responsible for final documents. It does not make automated decisions about students, and it is not designed or used for admission decisions, assessment of learning outcomes, or monitoring or proctoring during examinations, which are among the education-related use cases classified as high-risk under Annex III of the EU AI Act (Regulation (EU) 2024/1689).

The transparency obligations in Article 50 of the EU AI Act apply from 2 August 2026. Consistent with those obligations, the service presents AI assistance and generated drafts clearly to teacher users, and our Privacy Policy describes the AI drafting flow in plain language.

In respect of that functionality, SENScribe obtains AI model processing from Microsoft (Azure OpenAI) under enterprise terms, and its working position is that it acts in a deployer-type role rather than as a provider of a foundation model. A formal classification memorandum addressing high-risk timing under the Act and relevant Irish measures, including the proposed Regulation of AI Bill 2026, remains outstanding and will be completed with external counsel. This position is kept under review as the Act phases in.

How changes are notified

We maintain this page as the definitive published sub-processor list and display a "last updated" date at the top of the page. Before engaging any addition or replacement of a sub-processor that will process Customer Data, we notify controller customers directly, in writing, by email to the controller contact identified in the Data Processing Agreement. Notice is given no fewer than thirty (30) days in advance, providing the objection window stated in Clause 10 of the Data Processing Agreement. Updating this page alone does not constitute notice.

Objections

Schools, Data Protection Officers, or other authorised representatives of the controller may object in advance to a proposed new sub-processor by contacting us at hello@senscribe.ie, in accordance with Clause 10 of the Data Processing Agreement. We acknowledge objections and respond without undue delay. If an objection cannot be resolved, the controller may terminate the affected service before the change takes effect, and SENScribe will not engage the objected sub-processor for that controller's data (Clause 10(6)).