Sub-processors
Every third party that can process personal data on behalf of our customers, what reaches each one, and where it is processed.
- Last updated
- 11 August 2026
- Effective from
- 11 August 2026
Our commitment
The data processing agreement requires us to keep this list current and to give notice before we add to it. If a new provider is introduced into the service and it can touch personal data, it appears here — in the same change that introduces it.
- Notice before addition. We give at least 30 days’ notice before a new sub-processor starts processing customer data.
- A right to object. A customer that reasonably objects on data-protection grounds can raise it with us, and if we cannot resolve it, terminate the affected part of the service without penalty.
- Flow-down obligations. Each sub-processor is bound by written terms no less protective than those we owe our customers. We remain responsible to the customer for their performance.
This list was last reviewed on 11 August 2026.
In use today
Cloudflare, Inc.
| Purpose | Application hosting, database, object storage, CDN and DDoS protection |
|---|---|
| Data processed | All customer data stored in Classbell — pupil, guardian and staff records, attendance, assessment, finance and audit data, plus request logs |
| Location | Primary database region: Western Europe (WEUR). Uploaded files — pupil photographs and school logos — are held in object storage in the Eastern Europe region (EEUR). Edge compute runs in the Cloudflare location nearest the visitor. |
| Note | Classbell runs entirely on Cloudflare Workers, D1 and R2. This is the core infrastructure provider, not an add-on. |
Postmark (ActiveCampaign, LLC)
| Purpose | Transactional email delivery |
|---|---|
| Data processed | Recipient name and email address, and the content of invitation, password-reset and notification emails |
| Location | United States |
| Note | Used only for transactional mail — invitations, password resets and notices. Classbell sends no marketing email to school users. |
Google LLC (Google Analytics 4)
| Purpose | Usage analytics for this website and the Classbell application |
|---|---|
| Data processed | Pages visited, device, browser, approximate location derived from IP, and an analytics cookie identifier. Inside the application, the page address is rewritten before it is sent so that it never contains a pupil, guardian or staff identifier, never contains an invitation or password-reset link, and never contains your school's web address — your school is identified only by an opaque internal reference. |
| Location | United States |
| Note | Loaded only if you accept analytics cookies. Declining stops it entirely. |
Microsoft Corporation (Microsoft Clarity)
| Purpose | Session replay and heatmaps on this marketing website, to see which parts of it are confusing |
|---|---|
| Data processed | A recording of page layout and of your clicks and scrolling on classbell.app. It does NOT run inside a school's portal, so no pupil, guardian or staff data reaches it. |
| Location | United States |
| Note | This public website only, and only if you accept analytics cookies. It is not loaded in the Classbell application. |
Planned, not yet active
Stripe, Inc. — planned
| Purpose | Subscription billing and card payment processing |
|---|---|
| Data it would process | Billing contact name, email, billing address and payment-card details. Card details are collected by Stripe directly and are never transmitted to or stored by Classbell. |
| Location | United States and Ireland |
| Note | Handles the school's own subscription to Classbell. It does not process pupil, guardian or staff records. Not yet enabled on the current deployment. |
What is deliberately absent
It is as useful to know what is not on this list. Customer data is never sent to an advertising or marketing platform, a customer data platform, a data broker, or any third-party AI or machine-learning service — none of them are part of the product, and no pupil, guardian or staff record leaves the platform for one.
Getting notified of changes
To be told when this list changes, email classbell@axurs.com and ask to be added to sub-processor notifications. Notice goes to the administrative contact on each account by default.