ABCDEFGHIJ
1
TWINKL LTD – SUB-PROCESSOR REGISTER | Data Controller: Twinkl Ltd | Wards Exchange, 197 Ecclesall Road, Sheffield, S11 8HW | Document Owner: Data Protection Officer | Version: 2.1 | Last Reviewed: March 2026
2
Sub-Processor / Vendor NameService / FunctionCategories of Personal Data ProcessedData Subjects AffectedTransfer Country / RegionTransfer Mechanism / SafeguardDPA / Contract in Place?Technical & Organisational Security Measures (TOMs)Evidence / Certification LinksNotes / Gaps
3
AdyenPayment ProcessingPayment card data, transaction records, billing address, name, emailCustomers, paying subscribersNetherlands (EU)DPA / EU Adequacy (GDPR Art. 45)Yes – DPA in placePCI-DSS Level 1 compliant; end-to-end encryption of card data; tokenisation (no raw PAN storage); real-time fraud monitoring (RevenueProtect); AES-256 encryption at rest; TLS 1.2+ in transit; SOC 1 & SOC 2 Type II audited; RBAC; MFA for platform access; penetration testing; annual third-party auditsAdyen Security Overview
Adyen PCI Compliance
Adyen DPA
4
Amazon Web Services (AWS)Primary Data Hosting & Cloud InfrastructureAll categories of personal data hosted on platform; server logs; IP addressesAll data subjects (employees, customers, users)UK / EU DPA / UK IDTA / EU SCCsYes – AWS DPA & SCCsISO 27001 certified; SOC 1, SOC 2 Type II & SOC 3 audited; encryption at rest (AES-256) and in transit (TLS 1.2+); Virtual Private Cloud (VPC) isolation; Identity & Access Management (IAM); mandatory MFA; full audit logging (CloudTrail); regular penetration testing; physical security controls at data centres; 99.99% availability SLAAWS Compliance Programmes
AWS ISO 27001 Cert
AWS SOC Reports
AWS DPA
5
AWS Nova Lite (Amazon Bedrock)AI / Generative AI Model InferenceUser-submitted content; usage prompts; pseudonymised identifiersPlatform users, educators, pupilsUSDPA / SCCs / UK IDTAYes – AWS DPAEncryption in transit (TLS 1.2+) and at rest (AES-256); no training on customer data by default (opt-out enforced via Bedrock policy); full audit logging via CloudTrail; RBAC with least-privilege IAM policies; AWS Nitro System for hardware-level isolation; data residency controls; VPC endpoints to avoid public internet traversalAWS Bedrock Data Privacy
AWS AI Services Data Privacy
AWS DPA
Verify no-training opt-out is active in Bedrock console settings
6
Akamai TechnologiesCDN / Web Performance & SecurityIP addresses, device identifiers, HTTP request metadata, geolocation dataWebsite visitors, usersGlobal (US HQ)DPA / SCCs / UK IDTAYes – DPA in placeTLS 1.2+ / SSL enforcement; DDoS mitigation (Prolexic); Web Application Firewall (WAF); edge-node security with physical & logical access controls; data minimisation by design; ISO 27001 certified; SOC 2 Type II audited; log retention controls; RBAC for platform accessAkamai Compliance
Akamai ISO 27001
Akamai DPA
7
CloudinaryImage & Media Asset ManagementProfile images, user-uploaded media, metadataUsers, customersUSDPA / SCCs / UK IDTAYes – DPA & SCCsHTTPS/TLS in transit; cloud-based RBAC with least-privilege access; CDN delivery with signed URLs; AES-256 encrypted storage; SOC 2 Type II audited; automatic backup; access logging; CORS controls; IP allowlisting availableCloudinary Security
Cloudinary Privacy & Compliance
Cloudinary DPA
8
DPD (UK)Physical Delivery ServicesName, delivery address, phone number, emailCustomers (physical goods purchasers)UKDPAYes – DPA in placeSecure logistics data handling; encrypted parcel tracking portal (HTTPS/TLS); RBAC for driver and depot access systems; data minimisation (delivery data only retained as needed); physical security at depots; staff training on data handling; compliant with UK GDPR and Postal Services ActDPD UK Privacy PolicyRequest updated DPA and TOMs evidence at next contract review
9
Elastic / OpenSearch (Object Rocket)Search & Data AnalyticsUsage data, pseudonymised user identifiers, log dataPlatform usersUSDPA / SCCs / UK IDTAYes – DPA in placeData encryption at rest (AES-256) and in transit (TLS); RBAC with role-scoped API access; secure API endpoints (HTTPS only); SOC 2 Type II audited; audit logging; field-level security; IP allowlisting; index-level access controls; automated snapshots for backupElastic Security
Elastic Compliance
Elastic SOC 2
10
Fingerprint (OpenFPCDN)Device Fingerprinting / Fraud PreventionDevice identifiers, browser attributes, IP addresses, behavioural signalsWebsite visitors, usersUSDPA / SCCs / UK IDTAYes – DPA in placePseudonymisation of device identifiers; AES-256 encryption in transit (TLS 1.2+); strict data minimisation (only fraud-relevant signals collected); access controls with API key authentication; data retention limits configurable; SOC 2 Type II audited; GDPR-compliant consent integration; server-side processing to minimise client exposureFingerprint Security
Fingerprint Privacy
Fingerprint DPA
11
FireBoltData Warehouse & BI AnalyticsPseudonymised user IDs, usage data, analytics data, IP addresses, log dataPlatform usersUSDPA / SCCsYes – DPA & SCCsEncryption in transit (TLS) and at rest (AES-256); RBAC with least-privilege enforcement; VPC isolation; IP allowlisting; full audit logging; AWS KMS key management; IAM integration; SOC 2 Type II in progress (verify current status); automated backup and point-in-time recoveryFirebolt Security
Firebolt DPA
Confirm SOC 2 Type II certification status — was listed as 'in progress'
12
Flow (Book Distribution)Book & Physical Resource DistributionName, delivery address, order dataCustomers (book purchasers)UKDPAYes – DPA in placeSecure distribution data handling; HTTPS/TLS encrypted transactions; RBAC for staff access; data minimisation (order fulfilment data only); compliant with UK GDPR; physical security at warehouse/fulfilment sitesFlow PrivacyRequest formal TOMs documentation at next contract review
13
Gemini (Google DeepMind / Google Cloud AI)AI / Generative AI FeaturesUser-submitted text, prompts, pseudonymised identifiersPlatform users, educators, pupilsUS / EU (GCP regions)DPA / SCCs / UK IDTAYes – Google DPAEncryption in transit (TLS) and at rest (AES-256); no training on customer data without explicit consent (off by default for API use); full audit logging via Cloud Audit Logs; RBAC with least-privilege service accounts; Google Cloud security standards (ISO 27001, SOC 2/3); data residency configurable; VPC Service Controls; DLP integrations availableGoogle Cloud AI Data Privacy
Google Workspace DPA
Google Cloud Compliance
Confirm no-training setting is enforced via GCP console; review data residency region selection
14
GetSite ControlOn-site Pop-ups & Live Chat WidgetName, email, behavioural data, IP addressWebsite visitors, usersEUDPAYes – DPA in placeData encryption in transit (HTTPS/TLS); access controls with password-protected admin; GDPR-compliant data handling; data minimisation by configuration; server-side encryption at rest; consent-based data captureGetSiteControl Privacy
GetSiteControl DPA
Verify current DPA version covers UK GDPR
15
Google Analytics (GA4)Website Traffic & User Behaviour AnalyticsIP addresses (anonymised), device/browser data, page views, session dataWebsite visitorsUSDPA / SCCs / UK IDTAYes – Google DPA & SCCsIP anonymisation enabled (last octet masked); data encryption at rest and in transit; RBAC with restricted admin access; configurable data retention (set to minimum required); no cross-site tracking; consent mode integration; Google Signals disabled where not required; SOC 2 Type II; ISO 27001Google Analytics DPA
GA4 Data Privacy
Google Cloud Compliance
Ensure GA4 consent mode is correctly configured with UK cookie consent
16
Google Cloud Platform (GCP) – Cloud & EmailCloud Infrastructure, Gmail, Google WorkspaceEmails, calendar data, documents, personal data within WorkspaceEmployees, contractorsUS / EUDPA / SCCs / UK IDTAYes – Google Workspace DPAISO 27001 certified; SOC 2 Type II & SOC 3 audited; AES-256 encryption at rest; TLS in transit; MFA enforced (Google 2-Step Verification); RBAC via Google Admin console; full audit logging; eDiscovery and data loss prevention (DLP) tools; endpoint management; Google Workspace data residency option; physical security at Google data centresGoogle Workspace DPA
Google Workspace Compliance
Google ISO 27001
17
HubSpotCRM & Business ManagementName, email, company details, marketing preferences, contact historyCustomers, leads, contactsUSDPA / SCCs / UK IDTAYes – HubSpot DPAAES-256 encryption at rest; TLS 1.2+ in transit; MFA enforced; SOC 2 Type II audited; RBAC with granular permissions; data residency options (EU available); audit logs; GDPR tools (consent management, right-to-erasure workflows); SSO/SAML support; intrusion detection; annual penetration testingHubSpot Security
HubSpot DPA
HubSpot SOC 2
18
Impact.comAffiliate / Ambassador Programme ManagementContact data, marketing data, tracking dataCustomers, partnersUSASCCs / UK IDTAYesHTTPS/TLS encryption in transit; AES-256 at rest; access controls with RBAC; SOC 2 Type II audited; contractual data handling controls; data minimisation for tracking; fraud detection controls; MFA for admin accessImpact.com Privacy
Impact.com Security
Obtain formal DPA document and add to contract file
19
Jira (Atlassian)Project Management & Issue TrackingEmployee names, email addresses, work tasks, project dataEmployees, contractorsUS / EU (Atlassian Cloud)DPA / SCCs / UK IDTAYes – Atlassian DPASOC 2 Type II audited; ISO 27001 certified; AES-256 encryption at rest; TLS in transit; RBAC with project-level and space-level permissions; audit logs; SSO/MFA (Atlassian Access); IP allowlisting; data residency available (EU); automated backup; GDPR admin controlsAtlassian Trust Centre
Atlassian DPA
Atlassian SOC 2
20
KickboxEmail VerificationEmail addressesCustomers, subscribersUSDPA / SCCs / UK IDTAYes – DPA in placeTLS encryption in transit; minimal data retention (email addresses not stored post-verification by default); secure REST API with API key authentication; HTTPS-only endpoints; SOC 2 Type II audited; data minimisation by designKickbox Privacy
Kickbox DPA
21
Legal Debt Recovery LtdDebt CollectionName, address, account details, financial dataCustomers (debtors)UKDPAYes – DPA in placeSecure access controls for debt recovery data; encrypted data transfer (HTTPS/TLS); confidentiality agreements with all staff; RBAC; ICO registered; compliant with FCA debt collection guidelines and UK GDPR; physical document security; staff training on data handlingICO RegisterVerify current ICO registration; request updated TOMs schedule
22
Mailchimp (Intuit)Email Marketing & DeliverabilityName, email address, marketing preferences, open/click dataCustomers, subscribersUSDPA / SCCs / UK IDTAYes – Mailchimp DPAAES-256 encryption at rest; TLS 1.2+ in transit; SOC 2 Type II audited; RBAC with audience-level permissions; anti-spam compliance (CAN-SPAM, CASL); DKIM/SPF/DMARC enforced; MFA for account access; unsubscribe management; data retention controls; GDPR contact management toolsMailchimp Privacy
Mailchimp DPA
Mailchimp Security
23
Microsoft ClarityUser Behaviour Analytics / Session RecordingIP addresses (masked), session recordings, heatmaps, device data, click dataWebsite visitorsUSDPA / SCCs / UK IDTAYes – Microsoft DPAAutomatic IP masking (last octet); data minimisation by design; HTTPS/TLS in transit; Microsoft Azure security infrastructure; SOC 2 Type II audited; ISO 27001 certified; masking of sensitive input fields by default; RBAC for dashboard access; data retention controls; consent integration supportedMicrosoft Clarity Privacy
Microsoft DPA
Microsoft Compliance
Confirm input masking is correctly configured to exclude payment/sensitive fields
24
New RelicApplication Performance MonitoringServer logs, IP addresses, error traces, pseudonymised user identifiers, performance metricsPlatform users (indirect), employeesUSDPA / SCCs / UK IDTAYes – New Relic DPAAES-256 encryption at rest; TLS 1.2+ in transit; SOC 2 Type II audited; RBAC with account-level access controls; configurable data retention periods; audit logging; data obfuscation rules (PII scrubbing); IP masking options; FedRAMP authorised (moderate); penetration testing; SSO/SAML supportNew Relic Security
New Relic DPA
New Relic Compliance
Verify PII obfuscation rules are active to scrub any personal data from logs
25
OpenAIAI / Generative AI FeaturesUser-submitted text, prompts, pseudonymised identifiersPlatform users, educators, pupilsUSDPA / SCCs / UK IDTAYes – OpenAI DPAEncryption in transit (TLS 1.2+) and at rest (AES-256); zero data retention option active via API (prompts/completions not stored); no training on API data by default (confirmed in DPA); SOC 2 Type II audited; RBAC with API key scoping; audit logging; GDPR data subject rights tooling; penetration testing; dedicated security teamOpenAI Security
OpenAI Privacy Policy
OpenAI DPA
OpenAI SOC 2
Confirm zero-data-retention is enabled in API account settings; review if pupils' data is involved and consider age-appropriate AI policy
26
SendGrid (Twilio)Transactional Email DeliveryName, email address, IP address, email metadataCustomers, usersUSDPA / SCCs / BCRs / UK IDTAYes – Twilio/SendGrid DPATLS/SSL in transit; SOC 2 Type II audited; ISO 27001 certified; encrypted communications; RBAC with API key scoping; anti-spam compliance; DKIM/SPF/DMARC authentication; dedicated IPs available; Twilio BCRs cover intra-group transfers; email suppression list management; abuse monitoringSendGrid Security
Twilio DPA
SendGrid Compliance
27
ShopifyMerchandise E-Commerce & DistributionName, address, payment data, order history, emailCustomers (merchandise purchasers)EU / USDPA / SCCs / UK IDTAYes – Shopify DPAPCI-DSS Level 1 compliant; AES-256 encryption at rest; TLS 1.2+ in transit; RBAC with staff account permissions; SOC 2 Type II audited; fraud analysis tools; 2FA enforced for merchant accounts; automated threat detection; HTTPS enforced on storefronts; GDPR data deletion and export tools; bug bounty programmeShopify Security
Shopify DPA
Shopify PCI
28
Tableau (Salesforce)Interactive Data VisualisationAggregated/pseudonymised analytics and business dataInternal teamsEU / USDPA / SCCs / UK IDTAYes – Salesforce/Tableau DPATLS 1.2+ in transit; RBAC with site-level and workbook-level permissions; Salesforce Shield encryption available; SOC 2 Type II audited; ISO 27001 certified; MFA enforced; audit logging; row-level security for data access control; Salesforce Trust site for real-time statusTableau/Salesforce DPA
Salesforce Trust
Tableau Security
29
TwilioBusiness Communications (SMS, Voice)Phone numbers, message content, IP addressesCustomers, usersUSDPA / SCCs / BCRs / UK IDTAYes – Twilio DPAEnd-to-end encryption for voice (SRTP) and messaging (TLS); SOC 2 Type II audited; ISO 27001 certified; RBAC with API key and subaccount management; strict access controls; BCRs for intra-group transfers; GDPR DPA in place; message logging controls; MFA for console access; data residency options; abuse monitoringTwilio DPA
Twilio Security
Twilio Trust Centre
30
UpfluenceInfluencer Marketing & TrackingInfluencer contact data, social media handles, email, campaign performance dataInfluencers, marketing partnersUS / EUDPA / SCCs / UK IDTAYes – DPA in placeHTTPS/TLS encryption in transit; AES-256 at rest; RBAC for campaign and contact data access; data minimisation (campaign-relevant data only); GDPR-compliant influencer consent management; encrypted API communications; SOC 2 in progress (verify); access loggingUpfluence Privacy
Upfluence Security
31
ZendeskCustomer Support – Live Chat & TelephonyName, email, account details, support conversation data, IP addressCustomers, usersUSDPA / SCCs / BCRs / UK IDTAYes – Zendesk DPAAES-256 encryption at rest; TLS 1.2+ in transit; Zendesk BCRs covering intra-group transfers; SOC 2 Type II audited; ISO 27001 certified; RBAC with ticket-level and brand-level permissions; audit logs; data deletion and export tools; SSO/MFA; HIPAA BAA available; network security monitoring; penetration testingZendesk DPA
Zendesk Trust Centre
Zendesk Compliance
32
SprigQualitative User Feedback / Session InsightsUsage data, feedback, behavioural dataCustomers / usersUSASCCs / UK IDTAYesData minimisation and anonymisation tools; HTTPS/TLS in transit; AES-256 at rest; SOC 2 Type II audited; RBAC for survey and session data access; consent-based data collection; configurable data retention; GDPR compliance toolsSprig Security
Sprig Privacy
33
YPOSchool Application ProcessingStudent data, parent data, application infoStudents, parentsUK / InternationalSCCs / UK IDTAYesSecure portals with HTTPS/TLS; restricted access with RBAC; encryption at rest; data minimisation; compliant with UK GDPR and Children's data requirements (ICO Age Appropriate Design Code where applicable); audit trails; staff trainingYPO PrivacyChildren's data — verify Age Appropriate Design Code compliance; obtain updated TOMs
34
RefTechEvent Badge Scanning / Lead CaptureContact data, event interaction dataEvent attendeesUK / EUSCCs (if applicable)YesEncrypted devices for badge scanning; HTTPS/TLS in transit; AES-256 at rest; RBAC for event staff access; data minimisation (event-relevant data only); audit logs; GDPR-compliant consent capture at registration; secure data deletion post-event per retention policyRefTech PrivacyConfirm SCCs in place if EU data involved; obtain DPA
35
ManyChatSocial Media AutomationContact data, interaction dataCustomers / prospectsCanadaAdequacy decision (Canada – PIPEDA)YesHTTPS/TLS in transit; AES-256 at rest; RBAC for bot and campaign management; SOC 2 Type II audited; GDPR/PIPEDA compliant; consent-based subscriber management; unsubscribe management; platform-level security (Meta API); MFA for account access; data minimisationManyChat Security
ManyChat Privacy
36
AnrokUS/CA Automated Sales TaxTransaction data, billing dataCustomersUSA / CanadaSCCs / UK IDTAYesFinancial data protection controls; HTTPS/TLS in transit; AES-256 at rest; SOC 2 Type II audited; RBAC for finance team access; data minimisation (transaction data only); PCI-DSS alignment for billing data; audit loggingAnrok Security
Anrok Privacy
37
Meta PlatformsDigital Advertising / Hashed AudiencesHashed email addresses, marketing dataCustomers / prospectsUSASCCs / UK IDTAYesPseudonymisation via one-way SHA-256 hashing of emails before upload; HTTPS/TLS in transit; platform-level security (ISO 27001, SOC 2); RBAC with Business Manager account controls; MFA enforced for ad account access; data minimisation (hashed identifiers only); Meta DPA covers EU/UK transfers; custom audiences encrypted in transitMeta Privacy Policy
Meta DPA
Meta Business Security
Confirm hashing is applied before any data leaves Twinkl systems; review Meta pixel consent configuration
38
ElevenLabsAI Voice / Subtitle GenerationAudio, transcriptsEmployees, customersUSASCCs / UK IDTAYesAI processing controls with no-training option for API use; HTTPS/TLS in transit; AES-256 at rest; RBAC for API access; data minimisation (audio processed and not retained post-generation by default); SOC 2 Type II in progress (verify current status); audit logging; content moderation controlsElevenLabs Privacy
ElevenLabs Security
Verify no-retention setting is active; confirm SOC 2 status; consider if voice data constitutes biometric data (Art. 9 UK GDPR)
39
DescriptVideo Subtitle GenerationAudio / video dataEmployees, customersUSASCCs / UK IDTAYesEncryption at rest (AES-256) and in transit (TLS); secure cloud-based processing; RBAC for project and workspace access; SOC 2 Type II audited; HTTPS-only access; data minimisation; configurable media retention; MFA for account accessDescript Privacy
Descript Security
Assess whether voice/audio data = biometric data requiring Art. 9 UK GDPR basis
40
StripePayment Processing / Subscription BillingPayment data, billing infoCustomersUSA / EUSCCs / UK IDTAYesPCI-DSS Level 1 compliant; AES-256 encryption at rest; TLS 1.2+ in transit; tokenisation (no raw card data stored by Twinkl); RBAC with dashboard access controls; SOC 2 Type II audited; ISO 27001 certified; fraud detection (Stripe Radar); MFA enforced for dashboard; GDPR data subject tooling; bug bounty programmeStripe Security
Stripe Privacy
Stripe PCI
Stripe DPA
41
SnowflakeBI / Analytics Data WarehouseAggregated data, business dataCustomers, employeesUSA / EUSCCs / UK IDTAYesAES-256 encryption at rest; TLS 1.2+ in transit; end-to-end encryption option (Tri-Secret Secure); data segregation with virtual warehouses; RBAC with fine-grained access control; SOC 1 & SOC 2 Type II audited; ISO 27001 certified; dynamic data masking; row-level access policies; audit logging; MFA; data residency in EU availableSnowflake Trust Centre
Snowflake Security
Snowflake DPA
42
EventbriteEvent ManagementContact data, event participation dataCustomers, prospectsUSASCCs / UK IDTAYesZoom: AES-256-GCM encryption for meetings; TLS in transit; SOC 2 Type II; ISO 27001; RBAC for admin/host roles; MFA enforced; waiting room and password controls; Eventbrite: HTTPS/TLS; SOC 2 Type II; RBAC; data minimisation for registrant data; GDPR-compliant data subject tooling; both platforms offer data retention controlsZoom Security
Zoom DPA
Eventbrite Privacy
Separate DPA entries may be needed for Zoom and Eventbrite as distinct controllers
43
Zoom Webinars and Event ManagementContact data, event participation dataCustomers, prospectsUSASCCs / UK IDTAYesZoom: AES-256-GCM encryption for meetings; TLS in transit; SOC 2 Type II; ISO 27001; RBAC for admin/host roles; MFA enforced; waiting room and password controls; Eventbrite: HTTPS/TLS; SOC 2 Type II; RBAC; data minimisation for registrant data; GDPR-compliant data subject tooling; both platforms offer data retention controlsZoom Security
Zoom DPA
Eventbrite Privacy
Separate DPA entries may be needed for Zoom and Eventbrite as distinct controllers
44
Google Cloud Identity PlatformUser AuthenticationLogin credentials, identifiersUsers / employeesUSA / EUSCCs / UK IDTAYesIdentity security with OAuth 2.0 / OpenID Connect; MFA/2FA enforced; AES-256 at rest; TLS in transit; RBAC; SOC 2 Type II; ISO 27001; audit logging via Cloud Audit Logs; brute-force and anomaly detection; phishing-resistant authentication options; data residency in EU availableGoogle Cloud Identity
Google Cloud Compliance
Google DPA