#01What this list is
This page is Academyship's canonical, public register of Subprocessors — the third parties that ACADEMYSHIP PTY LTD (ACN 698 283 448, ABN 89 698 283 448) engages to process Customer Data on its behalf when providing the Services. It is informational, but it is directly connected to the contractual rights in our Data Processing Addendum (DPA).
A Subprocessor is a provider Academyship appoints that processes Customer Data under Academyship's instructions. This is different from:
- Customer-selected Integrations — providers an Institution chooses to connect to its own tenant (see Section 5). Academyship does not control these data flows;
- Independent controllers / service providers — a party that determines its own purposes for certain data rather than acting on Academyship's instructions; and
- Telecommunications carriers — networks that carry SMS or other messages to their destination.
Under the DPA, Academyship gives reasonable advance notice of a new Subprocessor that will process Customer Data, and Customers may object as set out in the DPA. See Sections 7 and 8 for notice and objection.
#02How to read the register
The register in Section 3 lists each active Subprocessor with the following information:
- Provider legal entity — the contracting company, not just a brand name;
- Service name — the trading or service name used;
- Website — the provider's public site;
- Role / classification — Subprocessor, and the nature of the processing;
- Service and purpose — what Academyship uses the provider for;
- Data categories — the types of Customer Data involved;
- Data subjects — the people the data is about;
- Processing / storage location — where the data is processed or stored;
- Transfer safeguards — where relevant to any cross-border processing;
- Public assurance information — where publicly available;
- Effective date, status and last reviewed.
We list specific legal entities rather than generic descriptions.
#03Active production subprocessors
The following are Academyship-appointed Subprocessors that currently process Customer Data in production. This table is Academyship's canonical current register.
| Provider legal entity | Service name | Website | Role / classification | Service and purpose | Data categories | Data subjects | Processing / storage location | Transfer safeguards | Provider privacy and security information | Effective date | Status | Last reviewed |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Amazon Web Services Australia Pty Ltd (ABN 63 605 345 891) | AWS core infrastructure | AWS Customer Agreement | Subprocessor (processor) | Application hosting, tenant RDS databases, S3 files, logs, snapshots and backups. | Customer Data hosted by the platform, including workspace records, files, logs and backup copies. | Students, parents/guardians, staff, administrators and other individuals whose data an Institution places in the platform. | Sydney, Australia (ap-southeast-2). | Core platform Customer Data remains in Sydney; see the processing position below. | AWS security information | 12 September 2026 | Active | 12 September 2026 |
| Amazon Web Services Australia Pty Ltd (ABN 63 605 345 891) | Amazon SES | Amazon SES | Subprocessor (processor) | Transactional and Institution-sent email. | Email recipient names and addresses, message content, delivery metadata and related service records. | Email recipients, including students, parents/guardians, staff and administrators. | Sydney, Australia (ap-southeast-2). | Core platform Customer Data remains in Sydney; see the processing position below. | Amazon SES service information | 12 September 2026 | Active | 12 September 2026 |
| Amazon Web Services Australia Pty Ltd (ABN 63 605 345 891) | AWS End User Messaging | AWS End User Messaging | Subprocessor (processor) | SMS processing through AWS. | Mobile numbers, message content, delivery metadata and related service records. | SMS recipients, including students, parents/guardians, staff and administrators. | Sydney, Australia (ap-southeast-2) for SMS processing. | Telecommunications carriers may route messages through the recipient’s carrier network. | AWS End User Messaging service information | 12 September 2026 | Active | 12 September 2026 |
| Amazon Web Services Australia Pty Ltd (ABN 63 605 345 891) | Amazon Bedrock | Amazon Bedrock | Subprocessor (processor) | Foundation-model processing for Academyship’s institutional AI assistant, permitted Tenant search, summarisation, drafting, report and document assistance, administrative recommendations and action previews. | Permitted AI inputs, authorised workspace context, outputs and related usage or audit events. | Authorised Institution staff and individuals whose permitted Customer Data is included in an AI task. | Sydney, Australia (ap-southeast-2); cross-region inference is disabled. | Customer Data is not used to train general-purpose models. Core platform Customer Data remains in Sydney. | Each Institution may enable, disable or restrict AI Features. AI usage, security and audit events follow the 30-day infrastructure and security-log retention position. | 12 September 2026 | Active | 12 September 2026 |
Academyship hosts its core production platform and Customer Data in Sydney, Australia (ap-southeast-2). Limited processing outside Australia may occur through disclosed telecommunications delivery, Stripe-hosted payment services, Customer-selected Integrations or authorised access, subject to applicable privacy, contractual and security safeguards.
For Academyship's Australian AWS account, the AWS Customer Agreement identifies Amazon Web Services Australia Pty Ltd (ABN 63 605 345 891) as the AWS contracting party. The public AI feature inventory, role controls and human-review requirements are in the Responsible AI Statement. SMS messages are handed to telecommunications carriers for delivery and may be routed through carrier networks in the recipient's country.
Academyship uses AWS End User Messaging SMS for SMS delivery. AWS may process recipient mobile numbers, message content and delivery metadata, while telecommunications carriers participate in delivery and may route messages through recipient-country networks. Institutions control message content, recipients, timing and any authorised sender identity, and are responsible for consent, other lawful authority, notices, opt-outs and communications-law compliance. Academyship does not guarantee carrier delivery or exact sender-ID display. An Institution’s sender identity does not change the parties’ privacy or data-processing roles, and is not an Academyship Subprocessor.
#04Other third-party service providers that are not subprocessors
Some third parties are not Academyship-appointed Subprocessors because they provide services under their own contractual and regulatory arrangements. Customer-selected Integrations are not listed here — they are addressed in Section 5.
Stripe payment provider
| Contracting entity | Official terms | Classification | Purpose | Information processed | Processing locations |
|---|---|---|---|---|---|
| Stripe Payments Australia Pty Ltd (A.C.N. 160 180 343) | Stripe Services Agreement | Independent payment-service provider; not an Academyship-appointed Subprocessor. Stripe’s own role for payment data is determined under its terms and applicable law. | Subscription-payment processing and hosted checkout. | Payer and billing contact details, payment-method details, transaction amount, date and status, subscription status, applicable tax, refund or chargeback information, and support interactions, as applicable. | Australia for Stripe Payments Australia Pty Ltd; Stripe’s international processing operations may also involve other countries, including the United States and India, as described in Stripe’s Privacy Policy. |
Academyship uses Stripe for subscription payments. Payment-card details are entered on Stripe’s hosted checkout rather than on Academyship’s website.
#05Customer-selected integrations
Institutions can choose to connect their own third-party providers ("Integrations") to their tenant. Those providers are selected and controlled by the Institution, not appointed by Academyship, and the resulting data flows are the Institution's responsibility under its own arrangements with those providers. They are not Academyship Subprocessors and are not listed in Section 3. For how these are handled, see the DPA and Privacy Policy.
#06Provider assessment and contracting
Before appointing a Subprocessor that will process Customer Data, Academyship carries out due diligence proportionate to the risk, and puts in place data-processing terms consistent with the DPA. Our assessment considers matters such as security and privacy practices, data minimisation, processing location and region, confidentiality, incident-notification obligations, and exit or transition arrangements. We do not publish the internal checklist or scoring we use for this assessment.
#07New and replacement providers
When Academyship appoints a new or replacement Subprocessor that will process Customer Data, it provides reasonable advance notice, and Customers may object as described in the DPA. Where an urgent replacement is necessary (for example, to maintain security or continuity of the Services), Academyship may appoint a replacement and provide notice as soon as reasonably practicable. New entries are added to the register with their effective date.
#08How to receive change notices
To request notification of subprocessor changes, contact legal@academyship.com.au. Academyship manages these notifications manually on request. To provide notifications, Academyship retains the requester's contact details and notification preferences and uses them only for that purpose, consistent with the Privacy Policy. This register is also updated when a change takes effect, so it can be checked at any time.
#09Change log
| Date | Provider | Action | Effective date | Summary | Notice date | Document version |
|---|---|---|---|---|---|---|
| 12 September 2026 | Amazon Web Services Australia Pty Ltd | Initial production register | 12 September 2026 | Published AWS core infrastructure, Amazon SES, AWS End User Messaging and Amazon Bedrock as the active Academyship subprocessors for production operation in Sydney, Australia. | 12 September 2026 | 1.0 |
#10Questions and related documents
For questions about this register or subprocessor changes, contact legal@academyship.com.au.
#11Document governance
This register is the operational source of truth for Academyship's active Subprocessors. It is updated whenever a provider or material data flow changes, checked for currency each quarter, and formally reviewed with legal each year in June. The DPA Annex III snapshot and the Privacy Policy summary are updated through Academyship's controlled document-update process.
| Version | Date | Summary of changes |
|---|---|---|
| 1.0 | 12 September 2026 | Published the Subprocessor Register for Academyship’s production launch, including the active AWS services and their Sydney processing locations. |