- 10 Jul 2023
- 5 Minutes to read
- Contributors
- Print
- DarkLight
- PDF
List of Sub-Processors
- Updated on 10 Jul 2023
- 5 Minutes to read
- Contributors
- Print
- DarkLight
- PDF
Sub-Processor definition
In support of our Data Protection Agreement we maintain a list of "Sub-Processors" - defined as other Data Processors contracted by Cirrus to process "Personal Data" to support servicing you as a Customer (Data Controller).
- If a partner contracted by Cirrus does NOT process "Personal Data", better known as "Personal Identifiable Information" or PII, they are NOT a Data Processor under the GDPR and therefore not a Sub-Processor under our Data Protection Agreement.
- If a Partner is contracted directly by the Customer, they are NOT (a Sub-Processor) in scope of the Cirrus Data Protection Agreement.
For completeness sake we have also listed those partners and marked them "(Out-of-Scope)".
To optimally facilitate you we strive to provide up-to-date direct links to our partners Compliance information ("Compliance Info").
For some Sub-Processors Cirrus merely links to another website without sending any (user)data, these are marked "IP address only". Note that an IP address must be considered as PII, see EU - What is personal data?.
List of Platform URLs
For the list of URLs used by the Cirrus Platform we kindly refer you to our Cirrus Platform URLs article in our developers portal
Cirrus End-Users
In this section we list Sub-Processors processing data for our end-users; users of the Cirrus Platform.
Core Sub-Processors
Sub-Processors that are core to the Cirrus Platform.
Sub-Processor | Purpose | Country/Location | Compliance Info | Status Page | Remarks |
---|---|---|---|---|---|
Amazon AWS | Facilitate Assessment Process - Hosting Customer Data | EU: Ireland/Dublin (and Stockholm/Sweden), AU: Australia/Sydney, CA: Montreal/Canada, SG: Singapore/Singapore | AWS Compliance, Useful links: AWS ISO/IEC 27001, AWS ISO/IEC 27017, AWS ISO/IEC 27018, AWS SOC, AWS GDPR DPA | AWS Health | The most important sub processor as it hosts the Cirrus Platform including its Customer Data. NOTE: For your convenience we have added useful links to the AWS pages containing their ISO certificates (e.g. "AWS ISO/IEC 27001:2013 Certification"), SOC 3 report ("AWS SOC 3 Security, Availability & Confidentiality Report") and AWS GDPR DPA (Data Processing Agreement). EU Stockholm is a backup location for EU Premium. |
Optional Sub-Processors
Customers (Data-Controllers), in particular Customer' System Adminstrators in Cirrus may enable optional Sub-Processors.
Sub-Processor | Purpose | Country/Location | Compliance Info | Status Page | Remarks |
---|---|---|---|---|---|
Document360 | Facilitate Assessment Management - Provides Help Widget - Help Centre / Knowledge Base | Global, incl. India, see Azure global infrastructure plus Global CDNs (Stackpath (OpenJSF), JSDeliver, Google Fonts, CloudFlare (FontAwesome) locations) | Document360 GDPR plus CDNs (OpenJSF, JSDeliver, Google Fonts, FontAwesome privacy policies) | status.document360.com | IP Address only - NOTE: Author/admin can activate this by clicking (?) or seeking help |
ImgIX | Facilitate Assessment Process - Process images | AWS Region, USA | Privacy Policy | status.imgix.com | IP Address only. NOTE: Author can upload images that need to be resized. All (image) data is stored in the AWS Region of the Cirrus Platform, see Amazon AWS above. |
webspellchecker.net | Facilitate Assessment Process - Provide Spell-checking service alternative for Browser build-in | US (Virginia) | webspellchecker Compliance. | status.webspellchecker.com | NOTE: Author can enable this spell-checking for Essay questions. |
Add-On Sub-Processors
Customers (Data-Controllers) may subscribe to use additional "Add-On" Sub-Processors.
Sub-Processor | Purpose | Country/Location | Compliance Info | Status Page | Remarks |
---|---|---|---|---|---|
Proctorio | Facilitate Exams - Remote proctoring | US: US, EU: EU, see Proctorio Privacy and AWS global infrastructure / Azure global infrastructure | Proctorio Compliance / Release Notes | uptime.proctorio.com | If and only if contracted through Cirrus is Proctorio a Sub-Processor. |
Sub-Contractors (Out-of-Scope)
If a Sub-Contractor does NOT process "Personal Data", better known as Personal Identifiable Information or PII, they are by definition not a "Data Processor" under the GDPR and not a Sub-Processor under our Data Privacy Agreement.
Sub-Contractor | Purpose | Country/Location | Compliance Info | Status Page | Remarks |
---|---|---|---|---|---|
Sowiso | Facilitate Exams and Marking - Process Math answers | Netherlands | Information Security Policy / Privacy Policy / Release Notes | ? | No PII. (No IP address in Server-to-Server) |
Customer Sub-Contractors (Out-of-Scope)
If a Partner is contracted directly by the Customer they are not in scope of the Cirrus Data Protection Agreement.
Partners | Purpose | Country/Location | Compliance Info | Status Page | Remarks |
---|---|---|---|---|---|
Ecobit | Facilitate Marking - Scanning printed answers (Print & Scan) | Netherlands | Ecobit DPA | Candidate name and signature | |
Proctorio | Facilitate Exams - Remote proctoring | US: US, EU: EU, see Proctorio Privacy and AWS global infrastructure / Azure global infrastructure | Proctorio Compliance / Release Notes | uptime.proctorio.com | If contracted directly by Customer. |
ProctorU | Facilitate Exams - Remote proctoring | ProctorU C ompliance | Contracted directly by Customer. | ||
Readspeaker | Facilitate Exams - Reading Cirrus/Exam texts out loud | Netherlands | Privacy Policy / Release Notes | ? | IP address only |
TurnItIn | Facilitate Marking - Plagarism Detection | US, EU, APAC | TurnItIn Privacy and Security | TurnItIn Status | Contracted directly by Customer |
Cirrus Service Management
For completeness we also include our Cirrus Service Management tooling used by Cirrus to collaborate with Customer's Super Users and other contacts.
Service Management Sub-Processors
Sub-Processor | Purpose | Country/Location | Compliance Info | Status Page | Remarks |
---|---|---|---|---|---|
Airtable | Facilitate Service Management - Store Service information | Virginia, US (AWS) | Airtable Security Airtable Privacy | Email and names of service contacts. | |
Atlassian | Facilitate Service Management - Notify subscribers of Status Page updates | Ireland/Dublin, Germany/Frankfurt, USA/N. California | Atlassian Compliance, Atlassian GDPR | metastatuspage.com | Only email of email notification subscribers. |
Atlassian | Facilitate Service Management - Customer Portal, report and track requests | Ireland/Dublin, Germany/Frankfurt, USA/N. California | Atlassian Compliance, Atlassian GDPR | jira-service-management.status.atlassian.com | Email and optionally name of request participants. |
Document360 | See Document360 under Optional Sub-Processors | Provides Help Centre / Knowledge Base (and Help Widget) | See Document360 | See Document360 under Optional Sub-Processors | See Document360 under Optional Sub-Processors |
Google Workspace | Facilitate Service Management and Project Collaboration - Provide Mail, Document and Videoconferencing | Global, see Google data center locations | Google Cloud Compliance EU | Workspace Dashboard | |
Mailchimp | Facilitate Service Management - Mail Service and Product update information | US | Mailchimp GDPR & Compliance | Only for recipients; Email and consent, optionally first name of newsletter recipients. | |
Pipedrive | Facilitate Service Management - Store Service and Product update information | US and EU, see Rackspace Data Centres | Pipedrive Privacy & Security | Email and consent, optionally name of newsletter recipients. | |
Slack | Facilitate Service Management and Project Collaboration - Provide Instant Messaging | United States, Australia, Canada, France, Germany, India, Japan, South Korea, United Kingdom, See Slack Subprocessors | Slack Compliance | status.slack.com | Optional. |
WeFact | Invoicing | EU | WeFact Veiligheid | Invoice contact name and email |