The short version. The full policy below is what applies.
Personal data and backups are stored in the UK; a small number of providers process data in the US under UK transfer safeguards.
Every sub-processor is bound by a written contract with UK GDPR Article 28 terms.
AI providers receive only the content of the request and may not train on it.
Organisations get 30 days' notice of any new sub-processor and may object.
Tutorio uses a small number of trusted third parties to host and run the Service. This page lists them, where they process data and what they do for us. It forms part of our Privacy Policy and our Schools & Organisations Agreement. Organisations that have registered for notifications receive at least 30 days' notice before a new sub-processor is added.
Infrastructure and hosting
Provider
Purpose
Location
Transfer safeguard
Amazon Web Services
Application hosting, serverless functions, object storage, scheduled jobs
United Kingdom (London)
Data stays in the UK; AWS DPA
MongoDB Atlas
Primary database and its backups
United Kingdom
Data stays in the UK; MongoDB DPA
Cloudflare
Content delivery, DDoS protection, storage of the app's own static assets, widget rendering
Global edge network; static app assets in EU (no customer data stored)
UK IDTA / Addendum; Cloudflare DPA
Kubernetes-hosted services (UK data centre)
Websocket and real-time live lesson services, geocoding
Class invitation and reminder text messages where a phone number is provided
United Kingdom
UK provider
Google Firebase Cloud Messaging
Push notifications to Android and web devices
United States / global
UK IDTA Addendum; Google Cloud DPA
Apple Push Notification service
Push notifications and Live Activities on iOS
United States / global
Apple developer terms; token-only data
Identity and payments
Provider
Purpose
Location
Transfer safeguard
Apple (Sign in with Apple, App Store)
Optional sign-in; app distribution and in-app purchases
United States / global
Apple terms; UK adequacy framework where applicable
Google (Sign in with Google, Google Play)
Optional sign-in; app distribution and in-app purchases
United States / global
Google DPA; UK IDTA Addendum
Payment processor (web checkout)
Card payments for web purchases; we never hold full card numbers
EU / United States
PCI DSS Level 1; UK IDTA Addendum
AI providers
Provider
Purpose
Location
Transfer safeguard
Anthropic
Course drafting, marking against mark schemes, feedback and Rio conversations
United States (EU/UK routing where available)
Commercial terms with zero data retention option; no training on customer data; UK IDTA Addendum
Google (Gemini API)
Generating course cover images and icons from a tutor's text prompt; no learner data is sent
United States / global
Google Cloud DPA; no training on API content; UK IDTA Addendum
Only the content needed for the request is sent (for example, a written answer plus the mark scheme). Learner names and contact details are not included unless the learner types them. Organisations may ask for AI features to be disabled. See the AI Transparency Statement.
Operations and support
Provider
Purpose
Location
Transfer safeguard
GitHub
Source control and CI; no production personal data
United States
GitHub DPA
Error and performance monitoring
Crash and performance diagnostics, with personal data scrubbed
EU
Provider DPA
Email helpdesk
Support correspondence
EU / United Kingdom
Provider DPA
Google AdSense
Advertising on public marketing pages only, subject to cookie consent
United States / global
Google Ads DPA; UK IDTA Addendum
Our commitments
Every sub-processor is bound by a written contract containing the obligations required by Article 28 of the UK GDPR.
We assess each provider's security before onboarding and review it periodically.
Where data leaves the UK we rely on adequacy regulations or the UK International Data Transfer Agreement or Addendum, supplemented by encryption and data minimisation.
We remain responsible to you and to organisations for our sub-processors' performance.
Change notifications
Organisations can subscribe to sub-processor change notices by emailing [email protected]. Changes are also recorded in the version history below.
Version history
Every published version of this document, newest first. Material changes are announced before they take effect.
Version 1Current
Initial publication.
Effective from 27 September 2026
Questions about this policy?
Email [email protected] and a person will reply. For anything urgent about a child's safety, contact [email protected] or the emergency services.