Skip to main content

Trust Center · Policies

Vendor Management Policy

Last updated: 2026-09-03 · Owner: Founder / CTO · Design Excellent Group SL

How we choose, contract with and review the providers that process customer data.

Purpose

Make sure every third party that handles customer or learner data protects it at least as well as we do.

Current sub-processors

The authoritative list, with purpose, region and safeguard, is published on the Trust Center. As of this version: Supabase (database, auth, storage — EU), Bunny.net (video — EU + edge), Cloudflare (DNS/CDN/WAF), Emailit (e-mail), Stripe (payments), OpenAI (speech-to-text for captions, no training on our data), Google (optional sign-in and consent-gated analytics) and our Coolify-managed EU hosting provider.

Before onboarding a vendor

  1. Need — the vendor must be necessary for a product function; data shared is limited to that function.
  2. Assessment — review of the vendor's security documentation (SOC 2 / ISO 27001 reports where available, DPA, sub-processor list, data location, breach-notification commitments).
  3. Contract — a GDPR Art. 28 data-processing agreement and, for transfers outside the EU/EEA, EU Standard Contractual Clauses.
  4. Access — credentials issued per integration, stored in the secrets vault, scoped to the minimum permissions.

During the relationship

  • Annual review of each vendor's security posture and of whether the data shared is still the minimum.
  • Vendor incidents that affect our customers are handled under the Incident Response Policy.
  • The public sub-processor list is updated before a new vendor processes personal data, giving customers the opportunity to object.

Offboarding

Access revoked, credentials rotated, data deletion confirmed with the vendor in writing, list updated.