← Home

Subprocessors and external services

This deployment-aware register names the service categories Petrios can use. Whether a provider is legally a processor, independent controller, or merely disabled depends on the operator’s contract and configuration.

Last updated: 18 July 2026

Current service register

Petrios subprocessors and external services
ServicePurposePotential dataDeployment status
SupabasePostgres database, authentication, and private session-document storageAccount, organisation, teaching/document, attendance, feedback, certificate, portfolio, delivery, communication, and audit dataCore service; operator chooses project and region
RenderRuns the Petrios web applicationRequests, IP/network metadata, session cookies, and server logs; application data in transitConfigured application host
ResendSends authentication and operational emailRecipient, sender, subject/body, delivery metadata, and attachments where applicableConfigured
OpenAI APIOptional LLM, private learning-document processing, and provider-hosted authoritative web researchPurpose-limited session metadata, assistant messages, processed feedback, private PDF/DOCX/PPTX contents sent on moderator recap generation, document-derived search queries, public result URLs/titles, and generated recap scriptsEnabled
OpenAI APIOptional text-to-speech for moderator-reviewed Audio RecapsThe current draft recap script and speech-generation request metadata; the speech step does not receive uploaded document files or research queriesEnabled
Jitsi Meet (meet.jit.si)Optional live video roomsParticipant-provided meeting identity and audio/video exchanged directly with the Jitsi serviceAvailable when a user opens a video room

Primary data/backup region: Not declared by this deployment: region(s) for database, app host, and backups. International-transfer safeguards: Not declared by this deployment: provider-specific transfer safeguards.

Operator obligations

Before production use, the operator must reconcile this runtime-derived list with signed contracts, provider dashboards, support and monitoring tools, DNS/CDN services, backup destinations, and any organisation-added integrations. It must record legal entity, service location, processing purpose, data categories, retention, security measures, transfer mechanism, DPA link, and effective date for each recipient.

Changes and objections

This open-source application cannot notify people when an independent operator changes infrastructure. Each operator must define its own advance-notice channel and objection process in its executed data-processing agreement. Repository changes that introduce a new built-in external data flow must update this register, the privacy notice, environment contract, and relevant subsystem specification in the same change.