| Clerk, Inc. | User authentication, sign-in and session management | Email, name, sign-in events and session identifiers | International processing under provider contractual safeguards |
| Vercel, Inc. | Application delivery, serverless API runtime and deployment previews | Request metadata and application data processed in transit | Configured regions; international transfers under provider safeguards |
| Supabase, Inc. | Managed PostgreSQL database and object storage | Tenant application data and stored files | London, United Kingdom (eu-west-2) |
| Stripe Payments Europe Ltd. | Subscription billing and payment processing where enabled | Billing contact, plan and payment metadata; Journey does not store card numbers | Ireland / EEA |
| Resend, Inc. | Transactional email, including invitations and notifications | Recipient address, message content and delivery events | International processing under provider contractual safeguards |
| Anthropic, PBC | Historical legacy compatibility processor; not an active governed-OTJ AI sub-processor | No current governed-OTJ AI processing. This historical entry remains while retirement of legacy routes is independently verified. | United States; international transfers under provider safeguards |
| OpenAI, L.L.C. | Journey Advanced programme-bound governed OTJ/evidence assistance through Vercel AI Gateway, after named data-protection, security and release approval | Minimised authorised persisted workflow content for learner draft, tutor/assessor feedback draft or closed K/S suggestion. Pattern-based redaction reduces but cannot guarantee removal of personal data; credentials, payment data, raw signatures and document bytes are excluded. Requests use store:false; default abuse-monitoring retention may be up to 30 days unless OpenAI approves another arrangement. | Provider-configured processing under the applicable provider terms and contractual safeguards |
| Functional Software, Inc. (Sentry) | Operational application error, performance and replay diagnostics | Authenticated account, tenant, role, workflow, release, request/session and bounded replay context; credentials, tokens, payment-card data, raw signatures and document bytes are excluded | Provider-configured processing under contractual safeguards |
| PostHog, Inc. | Consent-based product analytics and session diagnostics | After consent: authenticated account, tenant, role, workflow, release, request/session, interaction and bounded replay context; credentials, tokens, payment-card data, raw signatures and document bytes are excluded | European Union cloud endpoint |
| Google LLC | Consent-based analytics and optional Google sign-in | Analytics events after consent; identity data when Google sign-in is chosen | International processing under provider contractual safeguards |
| Cloudflare, Inc. | DNS, domain security and edge protection | Network and request metadata | Global network under provider contractual safeguards |