Every third party that processes customer or candidate data on our behalf — with what they handle, where they sit, and how to be notified of changes.
We publish the full list as required by GDPR Article 28(2), and notify customers within 30 days of any addition or replacement.
All primary infrastructure and AI processing is hosted in the EU. No customer or candidate data is transferred outside the European Economic Area by default.
For workloads that require zero third-party sub-processors, we offer an EU-only single-tenant deployment. Contact us for details.
ProctorSafe ("we", "us", "the Company") engages the third parties below to deliver the service. Each one is bound by a written data-processing agreement that satisfies GDPR Article 28, and where transfers outside the EEA are unavoidable, we rely on the EU Standard Contractual Clauses (SCCs) plus any supplementary measures required by an updated transfer impact assessment.
If you need the underlying list as a CSV or JSON for your own vendor register, write to [email protected].
| Sub-processor | What they process | Hosting location | Notes |
|---|---|---|---|
| Primary cloud provider | Tenant and session data, captures (if recording on), backup snapshots | EU (Frankfurt, primary; Dublin, failover) | Object storage, PostgreSQL, container runtime. EU-only by default. |
| Object storage (S3-compatible) | Temporary session-capture storage, AI analysis payloads | EU | Buckets are tenant-scoped, encryption at rest with KMS-managed keys. |
| DNS provider | Domain resolution for `proctorsafe.eu` | Global anycast, EU resolvers available | No customer data flows through DNS. |
| Sub-processor | What they process | Hosting location | Notes |
|---|---|---|---|
| Primary AI provider (EU tier) | Compressed event timeline (codes + timestamps + severity) | EU | Used for session-level recommendations (`APPROVE` / `SPOT_CHECK` / `INVESTIGATE` / `VOID`). Disabled by default per section. |
| Secondary AI provider (US tier) | Same | US | Used only when a tenant explicitly opts in. Customer-supplied API key in this mode; no per-tenant data crosses our backend. |
| Sub-processor | What they process | Hosting location | Notes |
|---|---|---|---|
| Transactional email | Outbound email to tenant admins and reviewers (magic links, alerts, breach notifications) | EU | Used only for service emails. We do not send candidate-facing email from this system. |
| Sub-processor | What they process | Hosting location | Notes |
|---|---|---|---|
| Application performance | Anonymised request traces, error counts, slow queries | EU | No candidate PII, no session payloads, no event codes. Tenant id present. |
| Log aggregation | Server logs, anonymised | EU | 30-day retention. Candidate id is the opaque session id, not PII. |
| Uptime monitoring | Endpoint reachability | EU | No customer data leaves our network. |
| Sub-processor | What they process | Hosting location | Notes |
|---|---|---|---|
| Support inbox | Inbound email from customers, support tickets | EU | Used only for tickets that customers send to support addresses. |
| Internal wiki | Internal runbooks | EU | Not customer-facing. |
| Sub-processor | What they process | Hosting location | Notes |
|---|---|---|---|
| Payment processor | Card details, billing address, invoice history | EU | Used only for customer billing. Candidate data never touches this processor. |
[email protected] with subject subscribe to sub-processor changes).
If a sub-processor change is unacceptable for your deployment, you may terminate the relevant order form within the 30-day notice window and we will refund any pre-paid, unused fees on a pro-rata basis. If you require a sub-processor-free deployment, ask us about the EU-only single-tenant option.
For audit-trail purposes, the following sub-processors were previously listed and have since been retired:
For questions about a specific sub-processor, a sub-processor change, or to subscribe to change notifications:
[email protected]Last updated: 2026-09-22 Next scheduled review: 2026-12-22 (quarterly)
Dive deeper with guides from our articles library.
A practical breakdown of which GDPR articles apply to online exam proctoring, what they require, and how ProctorSafe's architecture addresses each requirement by design — not by policy.
Read articleRegulatory & complianceHow GDPR Article 25 changes remote assessment design: data minimization, default settings, and what “state of the art” means for proctoring.
Read articleRegulatory & complianceA DPIA blueprint for remote proctoring: necessity, proportionality, student risk assessment, and privacy-first mitigations.
Read articleStart a free trial and run real sessions against your own application, try the interactive demo in your browser, or contact us for a walkthrough tailored to your program.