Version subprocessors@2026-08-30 · In force from 2026-08-30
In force, and prepared in-house.This document is binding on Firma Limited from the date shown above. It was written by Firma Limited from the source code of the product, and has not yet been reviewed by an independent lawyer — we say that plainly rather than imply a review that has not happened. When that review takes place, no commitment made to schools, families or students will be weakened without the notice process each document describes.
Terms of Service Privacy Policy For students Data Processing Agreement Subprocessors Security TrustTaonova is unusual among edtech products in that almost every third party on this list is optional and switched on by the school, not by Firma Limited. The software ships with the integrations available but inert: an organization administrator must both set a control flag and supply that provider's own API key or credentials before any data leaves the installation.
The accurate statement to a school is not "here is our subprocessor list, take it or leave it". It is: here is the menu; your organization's administrator decides which of these ever receives your data, and the list that applies to you is the subset your administrator has enabled.
Two consequences follow, and a school's procurement office should understand both:
On this page, "school-enabled" means an organization administrator must turn it on; "deployment" means whoever runs the installation (Firma Limited for the hosted service, the school or its IT contractor for a self-hosted installation) configures it once at install time.
| What | The Taonova application server and its MongoDB database. |
|---|---|
| Who | Hosted service: DigitalOcean, LLC (a US-incorporated company operating the datacentre named below). Self-hosted: the school's own provider. |
| Data | Everything in the product — see the data inventory in the Privacy Policy (§3). This is the component that holds the student records themselves; the file storage below holds only uploads. |
| Location | Hosted service: Singapore (SGP1). Self-hosted: the school chooses, and can therefore keep all primary data in its own jurisdiction. |
| Notes | A school's procurement office usually asks "where is our data" expecting one answer; for the hosted service there are two, and this row is the one that covers the database. Singapore has no GDPR adequacy decision, so the Chapter V basis is the Standard Contractual Clauses in the DPA plus the transfer impact assessment in the international-transfers analysis (available on request). Self-hosting remains the strongest data-residency answer this product can give, and schools with hard residency requirements should be pointed at it. |
| What | Files uploaded into the product: profile and group images, journal attachments, and collector-form attachments, which routinely carry medical conditions, medications, allergies, emergency contacts and signed parental consent forms. |
|---|---|
| Who | Hosted service: Amazon Web Services (S3). Self-hosted: an S3-compatible store chosen by the deployment, commonly MinIO on the school's own hardware. |
| Location | Hosted service: Asia Pacific (Seoul), ap-northeast-2. Self-hosted: wherever the deployment's store runs. Credentials, bucket and region are per-organization settings, which is what lets a school pin uploads to its own jurisdiction. |
| Notes | Objects are written private and served through an authenticated redirect that re-runs the owning document's own read check before issuing a short-lived signed URL. |
| What | Account invitations, password resets, report/journal notifications to families, conference bookings, billing notices. |
|---|---|
| Who | The relay is a per-deployment choice, not a code dependency — configured at deploy time, and named on that installation's published privacy page, so each deployment discloses its own relay rather than inheriting this document's. Hosted service, as of 2026-07-29: Twilio SendGrid. Self-hosted: whatever relay the school's operator configures — a mainland-China installation uses an in-country relay and this row simply does not apply to it. No email provider is hardcoded anywhere in the codebase, which is what makes self-hosting in another jurisdiction possible. |
| Data | Recipient email address, and the message body — which routinely contains a student's name and may contain report comments or journal content. |
| Location | Hosted service: United States (Twilio SendGrid). Self-hosted: wherever the school's chosen relay operates. This is a disclosure a school must be told about, because it is the one always-on path by which student names leave the installation. |
| Status | Live on the hosted service. The relay is configured with DKIM/SPF/DMARC. Transactional mail — including password resets and address-verification messages — goes through it. |
None of these is enabled by default. Every server-side call path requires both the organization's control flag and the organization's own API key. A Taonova installation with no AI configured makes no LLM calls at all. This is genuine privacy-by-default and is worth stating to schools as such.
The organization supplies its own API key and therefore its own account and contract with the provider. Keys are stored on the organization document and are visible only to an organization administrator viewing the settings page.
| Provider | Endpoint contacted | Corporate location | Adequacy for EU transfer |
|---|---|---|---|
| OpenAI | api.openai.com (chat, image generation, audio transcription) | United States | No adequacy decision. Requires Standard Contractual Clauses — normally via OpenAI's own DPA, which the school signs. |
| Anthropic | api.anthropic.com | United States | As above. |
| Google Gemini | generativelanguage.googleapis.com | United States | As above. |
| OpenRouter | openrouter.ai (chat, audio transcription, embeddings) | United States | OpenRouter is a router, pinned by this installation. Every request carries a provider-routing constraint that limits the upstream to a fixed set — on this installation: openai, anthropic, google-vertex, google-ai-studio, with re-routing disabled and upstreams that retain or train on the data refused. So the recipient set is closed and enumerable, but it is still one hop more than a direct provider. See section 5. |
| DeepSeek | api.deepseek.com | People's Republic of China | No adequacy decision, and the PRC is a jurisdiction where the standard transfer-impact analysis is materially harder to pass. See section 5. |
Each provider also exposes a separate image-generation flag, and the organization selects one active provider and model.
What is actually sent to these providers is described in the Privacy Policy (§6), and it is not uniform — there are three tiers, and conflating them would be the easiest way to mislead a school:
| Service | Purpose | What is sent | Enabled by |
|---|---|---|---|
| AWS S3 (or an S3-compatible store such as MinIO) | File uploads: project evidence, journal post attachments, activity files, form/collector attachments, rich-text editor uploads, user files | The uploaded file itself, plus a key path containing the organization id and document id. Form attachments can include medical, allergy, dietary, emergency-contact and signed-consent documents. | Per-organization credentials, bucket and region — so a school can choose an EU or NZ region. |
| Stripe | Subscription billing for the hosted service only | Organization name, the billing contact's email address, and the organization id as metadata. No student data. | Hosted service only; irrelevant to a self-hosted installation. |
| Microsoft Graph / OneDrive / Teams | Opening, storing and editing documents in the school's own Microsoft tenant; Teams links; sign-in with Microsoft, where the school enables it | Document content and metadata the user chooses to open or save; the Microsoft access token is supplied by the caller. For sign-in: the account identifier, name and email address Microsoft returns. | Per-organization; the school's own Microsoft tenant. |
| Google — sign-in, and (where configured) Google Drive | Sign in with Google, where the school enables it; and picking, copying and linking files in the school's own Google Workspace | For sign-in: the account identifier, name, email address and profile picture URL Google returns. For Drive: the metadata of the individual files a person picks, or that Taonova creates for them — Taonova holds per-file access only and can never read, list or search the rest of a Drive. The Google access token is obtained in the user's browser and is not held on the server. | Per-organization, and per-school credentials: the school creates its own Google Cloud project in its own Workspace, so its own Workspace agreement with Google governs. Sign-in with Google has been available per organization for as long as the product has had accounts; it is named here because it was not named before. |
| SIS roster sync — Clever, Wonde, PowerSchool, or a generic REST SIS | Importing class rosters, students and teachers | Requests carry the school's SIS credentials; responses return student and staff names and identifiers, which are then matched into Taonova. | Per-organization configuration; the school's own SIS contract. |
| Pixabay | Stock image search for curriculum and page content | The search query text only. No student data. | Per-organization API key. |
| Open Library | Looking up book metadata and covers for the resource library | ISBN / title / author search terms only. No student data. | Always available where the resource library is in use; no key required. |
These are not subprocessors in the Article 28 sense — Firma Limited sends them no data — but they are third-party recipients of the user's IP address, user agent and referring page, which is personal data under GDPR and personal information under the NZ Privacy Act. A school asking "does anything load from outside our network?" deserves a truthful yes.
Everything that could be self-hosted now is, served from the installation's own origin. What remains is two hosts that genuinely cannot be, and two never-reached fallbacks:
| Host | What it serves | When it loads | Status |
|---|---|---|---|
| js.live.net | Microsoft OneDrive file picker SDK | Only on the OneDrive picker / MSAL OAuth redirect pages, and only for a school that has enabled the OneDrive integration | Cannot be self-hosted. Microsoft serves the picker the OAuth popup itself requires. The main application no longer loads it — the SDK is vendored; these are the redirect pages only. |
| challenges.cloudflare.com | Cloudflare Turnstile — the bot check on the public self-serve sign-up page | Only on the sign-up page, and only on an installation that has configured a Turnstile site key; an installation without one makes no Cloudflare request at all | Cannot be self-hosted — the challenge is the service. Cloudflare receives the visitor's IP address and browser characteristics and runs bot-detection fingerprinting; the server additionally calls Cloudflare to validate the token, forwarding the visitor's IP. Never loads inside the product, only on the pre-login sign-up page. Disclosed on the installation's published privacy page automatically whenever the key is configured. |
| unpkg.com, cdn.jsdelivr.net | PDF annotation and chart libraries | Never, in a correctly deployed installation | Fallbacks behind the self-hosted copies, which are tried first. Reached only if the deployment's own assets did not ship. |
The maths equation editor, PDF viewer, chart libraries, room-booking calendar and OneDrive button icon are all served from the installation's own origin, pinned to specific versions — no third party sees the viewer's IP for any of these. A unit test fails the build if a new CDN reference appears in client code, and checks that the vendored assets are actually present.
Embedded third-party content — YouTube, Vimeo, Loom, Desmos, GeoGebra, Padlet, Quizlet, Scratch, Canva, Spotify, TED, CodePen, Google Docs/Drive — can also appear where a teacher chooses to embed it in curriculum or page content. Those embeds behave like any embedded content on any website: the third party sees the viewer's IP address. This is a school-controlled editorial decision, not a Firma Limited disclosure.
One viewer the product constructs itself, so it does not fall under that carve-out: the Microsoft Office Online viewer (view.officeapps.live.com) is used by the application — not by a teacher's embed — to preview Office documents in the locked-writing gradebook and the document-upload preview. When it loads, Microsoft receives the viewer's IP address and the (signed, short-lived) URL of the document being previewed. It only ever previews documents that are already stored in, or bound for, the school's Microsoft integration or its own storage, and only for schools using those features — but it is an application behaviour and is disclosed here as one.
And a second one, on the same footing: the Google Docs Viewer (docs.google.com/viewer). Where an uploaded Word, Excel or PowerPoint file has no Microsoft preview available, the application — again, not a teacher's embed — renders it through Google's anonymous document viewer. Google receives the viewer's IP address and the signed, short-lived URL of the school's own file, which that service then fetches in order to render it. No account is involved and Taonova sends Google nothing else. It is named here because the teacher-chosen-embed paragraph above does not cover a viewer the product constructs itself, and because the Microsoft equivalent has had its own paragraph since the first version of this list.
Deployment note. Self-hosting only helps if the vendored assets ship with the bundle. A self-hosted installation that copies the application but not its public assets will silently fall back to the CDNs for charts, and lose maths fonts and PDF rendering outright.
DeepSeek is hosted in the People's Republic of China. If an organization administrator enables it, prompts — which on some paths contain student names and student work — are transmitted to a PRC-hosted endpoint. Under the NZ Privacy Act IPP 12 and under GDPR Chapter V this is a cross-border disclosure that the school must decide it is comfortable with. Firma Limited's position: we make it available, we name it plainly, we do not enable it, and we advise EU and UK schools not to.
OpenRouter sub-routes are pinned. A request to OpenRouter is fulfilled by an upstream provider that OpenRouter selects. Every request Taonova sends carries a provider-routing constraint with three parts:
The practical consequence: the enumerable recipient list a school needs is the same list whether it uses OpenRouter or a first-party provider directly. Models that only a non-pinned upstream can serve — DeepSeek's own models, for instance — are not available through OpenRouter here; DeepSeek remains available as a directly selected provider, with the disclosure above.
Widening the list is a change to this page, not just a configuration change. A deployment can narrow it freely. Firma Limited will not add an upstream to the shipped list without first adding it here and giving the notice section 7 promises — and an operator who widens it on their own installation takes on that same disclosure duty to their schools, which is why this page names the actual set rather than the default.
Verified by search across the client, server and module code and the served HTML for: Google Analytics, Google Tag Manager, Segment, Mixpanel, Amplitude, Matomo, PostHog, Heap, Plausible, Sentry, Bugsnag, Rollbar, LogRocket, FullStory, Hotjar, DoubleClick, AdSense, Facebook pixel, Intercom, HubSpot, Drift. Zero hits.
Taonova contains:
For a product used by children this is a materially better result than most of the market. There is also no push-notification, SMS, geolocation or mapping provider in the codebase.
Under the DPA (clause 8.5), Firma Limited will give each customer at least thirty (30) days' notice before adding or replacing a subprocessor that Firma Limited itself engages, during which the customer may object.
Adding a school-enabled integration to the menu above is not, by itself, a change to any school's subprocessor list — nothing flows to a provider the school has not switched on. But new providers will still be announced, because a school that has delegated the decision to its administrator needs to know what that administrator can now switch on.
There is currently no in-product notification mechanism for subprocessor changes and no per-organization subprocessor-change contact field. Notice would today be sent by email to the billing contact, manually, and we would rather say so than let "notice" imply machinery that does not exist.
Taonova is a product of Firma Limited, a company incorporated in New Zealand. Governing law: New Zealand.
New Zealand Business Number 9429036053421. Registered office: 64 Ngatiawa St, One Tree Hill, Auckland 1061, New Zealand.
Privacy questions, data-subject requests, security reports and legal notices: info@taonova.com.
Terms of Service Privacy Policy For students Data Processing Agreement Subprocessors Security Trust