School documents · Pack 2026-08-29
Sub-processor register
Organisations that may process school data to run Five Wells.
- Who it is for
- DPOs
- How to access it
- Public. Check this page before renewal; it is the change-notice channel for the standard DPA.
This pack describes how Five Wells Education designs and operates the platform so schools can complete their own due diligence. It is not legal advice. The school remains the data controller for pupil and staff data it places in the product. A solicitor or DPO should review processing before go-live.
Always used to run the service
- Supabase — authentication, PostgreSQL database, and file storage for the application.
- Vercel — application hosting. Anonymous visitor analytics may run on public marketing pages only, not on staff/pupil app routes.
Used when the school triggers that feature
- Resend — transactional email (for example staff invites). Recipient addresses are those the school entered.
- Wonde — MIS roster sync, only if the school’s tenant has Wonde enabled and connected.
- Google (Gemini API) — optional AI lesson planner and SEND Tracker drafting when staff run generate actions; optional pupil Well helper when the school has turned that setting on.
- Upstash — rate limiting for login and some staff credential APIs, when configured in production. Stores technical request metadata (for example IP) for throttling, not pupil education records.
Not sub-processors for pupil education records
- Schools’ own devices and MIS remain the school’s responsibility.
- Printing certificates or downloading CSVs moves a copy onto school-controlled systems.
Changes
Material additions to this list will be reflected on this page with an updated pack version date. Schools that cannot accept a new sub-processor for an optional module should keep that module switched off and contact Five Wells before renewal.
Related: All school documents · Roster field inventory
