Subprocessors and external services
This deployment-aware register names the service categories Petrios can use. Whether a provider is legally a processor, independent controller, or merely disabled depends on the operator’s contract and configuration.
Last updated: 18 July 2026
Current service register
| Service | Purpose | Potential data | Deployment status |
|---|---|---|---|
| Supabase | Postgres database, authentication, and private session-document storage | Account, organisation, teaching/document, attendance, feedback, certificate, portfolio, delivery, communication, and audit data | Core service; operator chooses project and region |
| Render | Runs the Petrios web application | Requests, IP/network metadata, session cookies, and server logs; application data in transit | Configured application host |
| Resend | Sends authentication and operational email | Recipient, sender, subject/body, delivery metadata, and attachments where applicable | Configured |
| OpenAI API | Optional LLM, private learning-document processing, and provider-hosted authoritative web research | Purpose-limited session metadata, assistant messages, processed feedback, private PDF/DOCX/PPTX contents sent on moderator recap generation, document-derived search queries, public result URLs/titles, and generated recap scripts | Enabled |
| OpenAI API | Optional text-to-speech for moderator-reviewed Audio Recaps | The current draft recap script and speech-generation request metadata; the speech step does not receive uploaded document files or research queries | Enabled |
| Jitsi Meet (meet.jit.si) | Optional live video rooms | Participant-provided meeting identity and audio/video exchanged directly with the Jitsi service | Available when a user opens a video room |
Primary data/backup region: Not declared by this deployment: region(s) for database, app host, and backups. International-transfer safeguards: Not declared by this deployment: provider-specific transfer safeguards.
Operator obligations
Before production use, the operator must reconcile this runtime-derived list with signed contracts, provider dashboards, support and monitoring tools, DNS/CDN services, backup destinations, and any organisation-added integrations. It must record legal entity, service location, processing purpose, data categories, retention, security measures, transfer mechanism, DPA link, and effective date for each recipient.
Changes and objections
This open-source application cannot notify people when an independent operator changes infrastructure. Each operator must define its own advance-notice channel and objection process in its executed data-processing agreement. Repository changes that introduce a new built-in external data flow must update this register, the privacy notice, environment contract, and relevant subsystem specification in the same change.