Back to the Information Governance Pack

Data protection

Sub-processor Register

v1.19
Updated Sep 2026 · Reviewed Jun 2026 · Next review May 2027

Owner: Andrew James (CEO)

This register lists all third-party organisations (sub-processors) that process personal data on behalf of Halved Limited in connection with the Halved platform. It is maintained in accordance with Article 28 of UK GDPR and is reviewed annually or when sub-processors change.

Halved will provide schools with notice of any new or replacement sub-processor in accordance with the data processing agreement (‘DPA’) agreed between Halved and the school and allow any objection rights set out in that DPA before the sub-processor processes live student data.

Any planned or conditional sub-processor must not process live student data until the relevant DPA terms are in place and the school has been notified where required.

Conditional providers must be marked active only if the relevant service is enabled in a way that processes platform personal data.

Sub-processor Register

Sub-processorParent entityServices usedPurposeData categories processedLocationDPAStatus
Microsoft AzureMicrosoft CorporationApp Service, PostgreSQL Flexible Server, Cache for Redis, Blob Storage, Key Vault, Log Analytics WorkspaceApplication hosting, primary data storage, secrets management, audit loggingUnique student identifiers, staff names, email addresses, assignment work, chat history (may include a student’s first name), AI learning profiles, student-uploaded content, student free-text notes, session data, API credentialsUK South (London)Microsoft DPAActive
Azure OpenAI Service (Sweden Central resource)Microsoft CorporationAzure OpenAI, regional Standard deploymentAI learning support chat inference: generating responses to the messages a student sends, the opening line a student is greeted with, and the replies given to school staffChat message text, the student’s first name where the school has Halved hold one, lesson and page context including the text a student has typed on the page, recent conversation history, learning profile summary. For a member of staff: their own name and observed-behaviour context about the students they ask aboutSweden Central (Sweden, EU; covered by UK adequacy regulations), subject to Microsoft’s abuse monitoring (see Notes)Microsoft DPAActive from 24 September 2026
Azure OpenAI Service (UK South resource)Microsoft CorporationAzure OpenAI, regional Standard deploymentReading a document uploaded to the platform and deriving its aims, checkpoints and tasks; estimating the topic a piece of material covers; writing the one-line instruction a student sees for a piece of work, from the material and notes their teacher provided; rewriting a student’s learning profile in the background from their conversation, and reading their messages for interests they mention; reformatting a teacher’s lesson notes; describing the page a student is working on when the student asks about itUploaded document content; a student’s conversation, where the learning profile is rewritten or interests are read; teacher lesson-note content and the material a to-do line is written from; page images including a student’s unsubmitted working ink. Page images are held for the duration of the call and are not stored.UK South (London), subject to Microsoft’s abuse monitoring (see Notes)Microsoft DPAActive
Azure Speech ServiceMicrosoft CorporationSpeech-to-text, Text-to-speech (en-GB-AdaMultilingualNeural)Converting student voice input to text; converting AI text responses to audioStudent voice audio recordings, AI-generated text contentUK South (London)Microsoft DPAActive
Azure Communication ServicesMicrosoft CorporationEmail send (ACS)Transactional emails (account creation, password reset, sign-in reminders); safeguarding escalation emails to school leadsUser email addresses, staff names, student first names where used, account setup links, password reset tokens; safeguarding alert content and flagged message excerptsUnited KingdomMicrosoft DPAActive
Azure Container Instances (Gotenberg)Microsoft CorporationAzure Container Instances running Gotenberg:8 document converterConverting PPTX and DOCX into page images for in-platform display, both teacher-uploaded lesson materials and documents a student uploads; converting a DOCX to PDF so that its text can be read, which for a student’s upload is what allows that text to be screened before the document reaches a teacher. A PDF is not sent to this converter: Halved renders PDF pages itselfLesson material content (teacher-uploaded educational files); student-uploaded documents (PowerPoint and Word)UK South (London)Microsoft DPAActive
Azure AI VisionMicrosoft CorporationAzure AI Vision (Read OCR)Converting a student’s handwriting into text; reading text from images of a student’s work, being photographed work and submitted inkThe image only, for the duration of the call. Azure AI Vision retains nothing.UK South (London)Microsoft DPAActive
Azure AI Content SafetyMicrosoft CorporationContent Safety APIAutomated moderation of student chat messages and AI responses for safeguarding categories, including the repeat check Halved makes on text whose first check could not be completed; text screening of a student’s answer-sheet writing on draft save and again at submission, and of text extracted from documents a student uploads; image moderation of profile photographs, of photographed work and submitted ink, and of the page a student is working on before the tutor’s vision call describes itChat message text, answer-sheet text, text extracted from uploaded documents, and images: profile photographs, photographed work, submitted ink, and page images including a student’s unsubmitted working inkUK South (London)Microsoft DPAActive
Microsoft Defender for StorageMicrosoft CorporationDefender for Storage (Standard tier), on-upload malware scanningOn-upload malware scanning of files written to Halved’s Blob storage. A student’s upload is gated on the verdict; a staff-authored annotation image is scanned but is not gated on itUploaded file content, covering student documents, photographs, and annotation images authored by a student or by a member of staff. Microsoft states that scanned files are not stored by the service, and that scanning is performed in the same Azure region as the storage account. Microsoft further states that in limited cases the scanning engine may share file metadata, including metadata Microsoft classifies as customer data such as a SHA-256 hash, with Microsoft Defender for Endpoint, and that this sharing may go outside the scanning region. Microsoft does not describe those cases, or the metadata shared, more precisely than that. File content is not shared on that path. Halved treats such metadata as personal data for the purposes of this register.UK South (London)Microsoft DPAActive
Azure Logic AppsMicrosoft CorporationLogic Apps workflowOrchestrating safeguarding escalation flow triggered by high-severity flagsSafeguarding flag metadata, email contentUK South (London)Microsoft DPAActive
MongoDB AtlasMongoDB, Inc.Atlas M10 cluster (halved-prod-mongodb)Primary document store for student accounts, lessons, assignments, and chat historyUnique student identifiers, staff names, email addresses, assignment work, chat conversation history (may include a student’s first name), AI learning profiles, student-uploaded content, student free-text notesAzure UK South (London)MongoDB DPAActive

DPA References

Microsoft Products and Services Data Protection Addendum: microsoft.com/licensing/docs (covers all Azure services listed above under a single Microsoft DPA)

MongoDB Data Processing Agreement: mongodb.com/legal/data-processing-agreement

Notes

Azure AI Content Safety and Azure Logic Apps support the live safeguarding pipeline and are active sub-processors.

Azure AI Vision retaining nothing is a statement about that sub-processor, not about Halved. Halved stores, in its own Blob storage (UK South), the images it retains as part of a student’s work: submitted annotations (marked-up lesson slides), submitted jotter pages (a student’s working out), teacher annotations, and photographed work. Two image types in this table are not stored by Halved: handwriting-input images, and the page image the tutor’s vision call describes. Neither means a student’s working goes unrecorded. The strokes that page image is composited from are held in the platform database as the student’s annotation draft, and the page image made when the work is submitted is stored in Blob storage with the assignment. What is not kept is the composite made for that one call.

All sub-processors process student personal data within the United Kingdom, except that AI inference for the chat function is performed by the Azure OpenAI Service from Halved’s production resource in Microsoft Azure Sweden Central, on Microsoft’s regional Standard deployment type, under which prompts and completions are processed only in Sweden. Sweden is a European Union member state covered by UK adequacy regulations, so no further transfer safeguard is required. Data held at rest by that service for that resource, including any content retained under Microsoft’s abuse monitoring, is stored in Sweden. Halved will move AI inference to another region in the United Kingdom or the European Economic Area only on 30 days’ prior notice to schools under the Data Processing Agreement, with a right to object, and to no other region without a school’s prior written authorisation.

The Location column states the region of each sub-processor. Location is not the whole of the position for two of them, and both are reconciled here rather than left to a reader.

Microsoft Defender for Storage scans within the storage account’s own region, and Microsoft states that in limited cases it may share file metadata outside that region with Microsoft Defender for Endpoint. What may leave the region is metadata derived from a file rather than file content, and it is set out in the Defender for Storage row above.

Microsoft’s service-level abuse monitoring applies to both Azure OpenAI production resources and is at Microsoft’s default on each: content flagged by Microsoft’s automated abuse detection may be retained for up to 30 days for review by authorised Microsoft staff, located in the European Economic Area for the Sweden Central resource and in a location Microsoft does not publish for the UK South resource. Halved has applied to Microsoft’s modified abuse monitoring programme; the application has not been approved and the storage remains enabled. The evidence and the status of the application are set out in section 3 of the Data Flow and Data Handling Summary.

This register records sub-processors. Halved’s own administrative access to production is not a sub-processor and is not recorded here. That access is exercised by named officers of Halved Limited from the United Arab Emirates and is set out in sections 3 and 4 of the Data Flow and Data Handling Summary.

This register covers the production environment, in Azure UK South and, for the Sweden Central Azure OpenAI resource, Azure Sweden Central. Production’s UK South Azure OpenAI account is halved-prod-oai. The development and demonstration environments each have a UK South account of their own and do not use production’s; they process no real student data. The development and demonstration environments, including the Sweden Central evaluation resource, are not listed here.

Halved does not use any sub-processor for analytics. Google Analytics and Microsoft Clarity have been removed from the platform.

Cloudflare provides DNS, CDN and security for the Halved marketing website (halved.io) only. It does not sit in front of the student-facing platform (my.halved.io) and processes no student or school personal data, so it is not a platform sub-processor. Confirmed June 2026 by response-header inspection (cf-ray present on halved.io, absent on my.halved.io).

Review date: May 2027 (or earlier if sub-processors change) | dataprivacy@halved.io